Phishing is one of the oldest and yet still most effective scam techniques in the cryptocurrency world. Criminals rarely break the technical defenses of wallets. It is far easier to break a person's vigilance: impersonate a trusted brand and get you to hand over access to your funds yourself. In crypto the stakes are exceptionally high, because blockchain transactions are irreversible and there is no hotline that can undo a mistaken transfer.
How the attack works
Classic phishing starts with a message or an ad that leads to a website deceptively similar to the real one. The fake site copies the look of an exchange or a wallet but hides behind a slightly altered address: a typo, an extra hyphen or a different domain ending. When you enter your login details there, or worse, your recovery phrase, they go straight to the scammer.
Impersonation on social media is also increasingly common, as is so called address poisoning. In this method the attacker sends a tiny transaction from a wallet whose address closely resembles the address of your counterparty, hoping you will copy the wrong address from your history.
There are also fake mobile apps, deceptively similar to the official ones, which sometimes even make it into app stores, as well as impersonation of technical support, for example in an email posing as a security alert. The goal is always the same: to get you to click and enter your details before you have time to think.
Warning signs
A few things should immediately set off alarm bells:
- a request for your recovery phrase or private key (no legitimate service will ever ask for it),
- time pressure and threats, for example "verify your wallet within 10 minutes or you will lose your funds",
- a website address that differs from the original by a single character,
- a link received in a private message, email or ad instead of one typed in manually.
The rule is simple: no honest party will ever ask for your recovery phrase, and every such request is an attempted theft.
How to defend yourself
The foundation is slowing down and verifying. Access exchanges and wallets only through an address typed in manually or saved in your bookmarks, never through a link from a message. Enable two-factor authentication, preferably with an app rather than SMS. Before signing any transaction, check the address and what exactly you are agreeing to. Keep your devices and browsers up to date, because security patches genuinely make attacks harder. It also helps to verify social media profiles before you trust anyone claiming to represent a project or be its administrator.
Phishing works because it plays on haste and trust. Once you learn to pause at every request for data or a signature, you take away the scammers' most important tool.
This article is educational content, not investment advice.