How Crypto Phishing Works and How to Avoid It
Phishing causes more crypto losses than any technical exploit. The patterns are consistent, which makes them recognisable.
Why phishing dominates
Attacking cryptography is impractical. Persuading someone to sign a transaction, or to type a seed phrase into a convincing page, is cheap and works often enough. That asymmetry is why the overwhelming majority of individual crypto losses are social rather than technical.
The main patterns
Fake wallet and exchange sites
A page identical to the real one, reached through a search ad, a message link, or a domain differing by one character. It asks you to "verify" or "restore" your wallet, and the seed phrase you enter goes straight to the attacker.
Malicious signature requests
More sophisticated and harder to spot. You connect a wallet to a site and are asked to sign something. The signature is not a transfer — it is an approval granting the attacker permission to move your tokens, executed later. The wallet may show no outgoing amount at all.
Impersonated support
Someone contacts you claiming to be support, often shortly after you posted about a problem publicly. Real support never initiates contact and never asks for a seed phrase, a password, or remote access to your machine.
Address poisoning
An attacker sends a tiny transaction from an address visually similar to one you use. Later you copy the address from your transaction history and send to theirs.
What to check before signing anything
- The URL, character by character. Homoglyph domains are the norm, not the exception.
- What the signature actually authorises. If it is an approval, check what token and what amount. Unlimited approvals deserve scrutiny.
- The destination address in full, on the hardware wallet screen where possible.
- How you arrived. A link from a message or an ad is the highest-risk path.
Structural defences
- Bookmark every site you use and navigate only from bookmarks.
- Use a separate wallet for interacting with applications, holding little.
- Keep long-term holdings in a wallet that never connects to anything.
- Revoke approvals regularly.
- Disable direct messages on platforms where scammers operate, or treat all of them as hostile.
If you think you signed something malicious
- Move remaining assets to a fresh wallet immediately — a new seed, not a new address from the same seed.
- Revoke approvals from the compromised wallet, if you can do so before it is drained.
- Record transaction hashes and the site involved.
- Report through the National Cyber Crime Reporting Portal if you are in India.
- Be alert to recovery scams, which target recent victims specifically.
Speed matters more than anything else here. An approval is exploited when the attacker chooses, which may be days later — moving funds first and investigating afterwards is the correct order.
Reading a signature request properly
Modern wallets display what you are about to sign, and learning to read that display is the single most valuable skill here.
| Request type | What it does | When to worry |
|---|---|---|
| Transfer | Sends a specific amount | Check amount and destination |
| Approve | Lets a contract move your tokens | Check the token, the amount, and who is approved |
| setApprovalForAll | Grants control of an entire NFT collection | Almost never legitimate from an unfamiliar site |
| Permit / signature | Off-chain approval, no gas | Frequently used maliciously — no gas does not mean no risk |
| Blind signing | Wallet cannot decode it | Decline unless you are certain |
The last two matter most. A gasless signature feels harmless precisely because nothing appears to move, and that is what makes it effective — the transfer happens later, using the permission you granted.
Search ads and why bookmarks matter
Phishing sites buy search advertising against exchange and wallet names, so the top result for a genuine product can be a counterfeit. The domain is usually a near-match that survives a glance.
This is why "bookmark everything" appears in every serious security guide. It is unglamorous and it removes an entire attack category permanently.
Social engineering that does not look like phishing
- A job offer requiring you to install software or complete a test task — used to deploy wallet-draining malware.
- A collaboration request asking you to review a document or a repository.
- A friend's compromised account sending a link. The account is real; the person is not.
- A community moderator offering help in a direct message after you asked a question publicly.
The common thread is that contact is initiated by someone else and creates a reason to act quickly. That pattern alone is enough to justify slowing down and verifying independently.
Further reading
Educational content, not financial advice. Crypto is volatile and you can lose money.
Enjoyed this article? Put it into practice.
SmartViewAI gives you live portfolio analytics, AI-graded signals, and a built-in academy. All in one place.