ThePathMark
Nº 23 Field notes

I thought phishing was just sketchy emails.

How a fake airdrop page, a support DM, and one almost-clicked approval taught me that crypto scams live inside normal-looking DeFi buttons.

The short version
  • Crypto phishing is social engineering aimed at your wallet — tricking you into typing a seed phrase, signing a bad transaction, or approving a malicious contract.
  • Most drains do not need your seed phrase. A fake swap site plus one unlimited token approval can empty USDC in seconds.
  • Attackers copy real interfaces — same layout, one wrong letter in the URL, or a link in a DM pretending to be support or an airdrop.
  • Your wallet cannot tell a scam site from a real one. It only shows what you are about to sign. Read every popup like a bank transfer.
  • Defense is boring and free: bookmark official URLs, never type seed phrases into websites, revoke old approvals, and test with tiny amounts first.

I grew up ignoring obvious spam — princes, inheritances, passwords in all caps. Crypto felt different because the scams dressed like the real apps I was already using. Wrong assumption: I thought phishing meant a clumsy email, not a pixel-perfect swap page that only needed one Approve click. Right version: most wallet drains are signatures I almost gave myself — on a site I reached through a link I did not verify.

01

The airdrop that wanted my seed phrase

A friend forwarded a Discord message: early token, connect wallet, claim before midnight. The site looked polished — dark theme, logo, countdown timer. Connect wallet was normal. Then a second screen: Enter your recovery phrase to verify wallet ownership.

I had just learned what a seed phrase was from What is a crypto wallet?. The timing felt almost educational — like the app was walking me through security.

It was not. Real claims never need twelve words in a browser box. I closed the tab and felt silly for how close I came. The page had not stolen anything yet. It was waiting for me to hand over the master key.

The scam did not break my wallet. It asked me to.

02

Support that slid into my DMs

Weeks later, after a failed swap that reverted and still cost gas, I posted a screenshot on X — half complaint, half joke about gas fees. Within minutes, two “support” accounts replied with links to “clear the stuck transaction.”

Same avatar colours as the real protocol. Different handles — extra underscores, one wrong letter. Both wanted me to connect and sign a “recovery” transaction.

I did not click. But I understood why people do. When you are embarrassed and out nine dollars in gas, a helpful stranger feels like rescue. That is the whole business model.

03

The swap site that was one letter off

The near-miss that still makes my stomach drop was the laziest mistake. I searched the name of a DEX instead of using my bookmark. Top result looked right. I connected. Selected USDC → ETH. The flow matched every tutorial.

Then the approval popup: unlimited USDC to a contract I did not recognise. On my real swaps I had started choosing exact amounts after reading Token approvals. This default was max — and the spender address did not match the docs when I pasted it into a block explorer.

I rejected. Switched to my bookmark. Same trade, different contract, exact approval. Saved nothing dramatic — maybe forty dollars of USDC at the time. Saved the habit of treating search results like recommendations.

04

The risk that actually keeps me up

Seed phrase theft is total and instant — I know that now. But the scarier day-to-day risk is quieter: malicious approvals on sites that look fine. No malware required. No hacked exchange. Just me, tired, clicking Confirm on a permission that outlives the tab.

I revoking old permissions on quiet Sundays now. Costs a little gas. Cheaper than assuming I will never visit a wrong URL again.

05

How I think about it now

Phishing is not a separate internet from DeFi. It is the same buttons — Connect, Approve, Sign — with a hostile contract on the other end. My wallet is a notary, not a bodyguard. It records what I agree to.

I bookmark first. I read popups second. I treat urgency as a warning label, not a deadline. When I mess up, I want the mistake to be a failed ten-dollar test, not a recovered-phrase story with no recovery.

Prefer the straight checklist? Read What are crypto phishing scams? for the full attack table and habits without my near-misses.

⚑ One honest flag

The scariest phishing page I almost used did not look scammy. It looked like every other DeFi site I had already trusted on a good day. The tell was not the design — it was the unlimited approval to a stranger’s contract. I only caught it because I had trained myself to read that one line.

I still hate that the safe move is boring. No chrome extension hero story. Just bookmarks, slow reading, and the occasional revoke transaction that feels petty until it is not.

If this cleared something up, you can buy me a coffee — or say hi on X.

← All field notes