Glossary

What is crypto phishing?

In one sentence

Phishing is tricking you into handing over keys, seed phrases or approvals by impersonating something you trust. It is the most common way crypto is stolen.

Most crypto losses are not sophisticated blockchain attacks. They are people being persuaded to give access away.

Common forms: a fake wallet or exchange site reached through a search advertisement or a link, capturing your seed phrase. A “support agent” appearing in a Discord or Telegram after you post a problem publicly — real support never messages first. Fake airdrop or claim pages that ask you to connect a wallet and sign a transaction granting unlimited spending approval. Cloned browser extensions. And clipboard malware that silently substitutes the destination address when you paste.

Defences that work. Never enter a seed phrase anywhere except your own wallet during a deliberate restore. Bookmark the sites you use rather than searching for them. Read what you are signing — an approval is not a login. Check the first and last characters of a pasted address. Treat anyone who contacts you first as hostile. And be sceptical of urgency, which exists to stop you checking.

For example

A signature request is not always a login — it can be an unlimited approval to spend your tokens.

← Back to the glossary