ThePathMark
Chapter 23 Security High risk

What are crypto phishing scams?

How fake sites, DMs, and wallet popups steal crypto — the common tricks, what they look like in real life, and habits that cost nothing but save your balance.

The short version
  • Crypto phishing is social engineering aimed at your wallet — tricking you into typing a seed phrase, signing a bad transaction, or approving a malicious contract.
  • Most drains do not need your seed phrase. A fake swap site plus one unlimited token approval can empty USDC in seconds.
  • Attackers copy real interfaces — same layout, one wrong letter in the URL, or a link in a DM pretending to be support or an airdrop.
  • Your wallet cannot tell a scam site from a real one. It only shows what you are about to sign. Read every popup like a bank transfer.
  • Defense is boring and free: bookmark official URLs, never type seed phrases into websites, revoke old approvals, and test with tiny amounts first.

Phishing (pronounced “fishing”) is a scam where someone impersonates a trusted person or site to steal from you. In crypto, the prize is usually your wallet balance — not your email password. The tricks look like normal DeFi: a swap page, a support message, an “exclusive airdrop,” a popup that says Approve.

If you have not read What is a crypto wallet? or Token approvals, start there. This guide connects both — most phishing drains use a fake site plus a permission you signed yourself.

01

What crypto phishing is — and what it is not

Classic email phishing sends you to a fake bank login. Crypto phishing targets the things only you can do with your private keys:

Attack typeWhat the scammer wantsWhat you lose
Seed phrase theftYour 12–24 word recovery phrase typed into a fake site or formEverything in every wallet that phrase controls — forever
Malicious approvalAn approval (on-chain permission) to a contract they controlTokens you approved — often all of that token if unlimited
Malicious transactionA signed send, swap, or transfer to their addressWhatever that transaction moves
Address poisoningYou copy-paste a “similar” address from your historyA send to the wrong recipient — no undo
Fake support / urgencyPanic clicks — “verify now,” “claim before midnight”Any of the above, faster

This is not a smart contract bug on a protocol you chose carefully. It is you, on a bad link, signing something harmful. The blockchain will execute your signature exactly as written. There is no fraud department.

02

How the common scams work

Fake swap or dApp sites. The page looks like Uniswap, a bridge, or a farm you know. The URL is off by one character, or it arrived in a Telegram DM. You connect your wallet — that part is harmless by itself. Then the site asks for an unlimited approval to USDC. You confirm. Their contract pulls your balance. See How to swap on a DEX for what a real swap flow looks like, so the fake one feels wrong.

“Connect wallet to claim” airdrops. A tweet or Discord post promises free tokens. The claim site asks for your seed phrase to “sync” or “verify eligibility.” No legitimate airdrop ever needs your seed phrase. Ever.

Fake wallet updates and extensions. Browser add-ons or “MetaMask security refresh” pages that ask you to import your recovery phrase. Real wallet apps do not ask for the full phrase on random websites — only during setup or restore inside the official app.

Support impersonators. Someone DMs you on X, Discord, or Telegram: “We noticed suspicious activity — click here.” Real exchanges and protocols do not fix account problems through unsolicited DMs. They will never ask for your seed phrase.

Address poisoning. Scammers send you a tiny amount from an address that looks almost like one you trust — same first and last few characters. You copy from transaction history later and paste the poisoned address. Always verify the full address before sending size.

03

Compared to familiar non-crypto things

Familiar scamCrypto phishing equivalent
Fake bank login pageFake swap site that asks for approvals
”IRS call — pay now” urgency”Your wallet will be frozen in 1 hour” DM
Skimmer on an ATMMalicious browser extension reading clipboard
Giving a contractor a house keyUnlimited token approval to an unknown contract
Handing someone your ID and PINTyping your seed phrase into any website
Wrong number on a wire transfer formAddress poisoning — one wrong character, money gone

The difference: in crypto, the “wire transfer” you approve is often irreversible in minutes, with no bank to call.

04

Why these scams work on beginners

Honest reasons — not insults:

  • Everything is new. Connect, approve, sign, gas — popups blur together. Scammers bet you will click Confirm without reading.
  • Real DeFi already feels risky. When a fake site adds urgency, it matches the anxiety you already have.
  • Interfaces are copy-pasteable. A dApp (decentralized app) is mostly a website. Cloning the look is easy. Cloning trust is not required.
  • Public wins, private losses. Screenshots of gains circulate; drain stories are quieter. The environment looks like everyone else clicks first and reads later.
  • Same vocabulary as real apps. “Approve,” “Claim,” “Verify wallet” — legitimate tools use the same words. The scam is in who receives the permission.
05

What it looks like when you are being targeted

Concrete red flags:

  • A link you did not type yourself — ad, reply, email, QR code, “helpful” stranger.
  • Seed phrase requested anywhere online — forms, PDFs, “sync” tools, support chat.
  • Unlimited approval for a site you visited once, for a token you barely use.
  • A transaction preview that sends your tokens to an address you do not recognise, while the UI still says “Claim reward.”
  • Time pressure — countdown timers, “last chance,” threatened closure.
  • A contract address that does not match official docs when you check a block explorer.
  • “Support” that reaches out to you first, especially asking you to share your screen or sign something.

If your wallet warns “this transaction may fail” or shows a suspicious contract, that warning is worth more than the pretty website behind it.

06

Risks beginners should know

  • One bad approval can drain one token completely — unlimited USDC approval means all your USDC, not “just what I tried to swap.”
  • Hardware wallets do not block bad signatures — a hardware wallet protects keys from malware; it still asks you to confirm what you chose to sign. Read the screen.
  • Revoking approvals costs gas — cheap compared to losing the balance. Tools like revoke.cash help audit open permissions (type the URL yourself).
  • Poisoned addresses survive in your history — the explorer shows Success even when you sent to a scammer. Green checkmark means the chain did what you signed, not that you signed wisely.
  • Same scam, new wrapper — “NFT mint,” “tax tool,” “wallet sync,” “validator registration.” The mechanism is still: get you to sign or reveal keys.
  • Search results and ads lie — sponsored links above official sites have fooled experienced users. Bookmarks beat search when money is involved.
07

A sensible way to start — checklist

  1. Bookmark the swap, bridge, and explorer URLs you actually use. Type them yourself or use those bookmarks — not DMs.
  2. Treat seed phrase like a bank vault combination — paper backup only; never enter it on a website, in Discord, or in a Google Form.
  3. Read wallet popups — which token, which amount, which contract address. If you cannot explain it in one sentence, reject it.
  4. Prefer exact approvals over unlimited when the app allows it. Revoke after experiments.
  5. Verify addresses on a block explorer before first deposits to a new app — compare to official docs, not just the ticker symbol.
  6. Test with a small amount on any new site — enough to feel a mistake, not enough to ruin a month.
  7. Pause on urgency — real protocols rarely need you to act in the next ten minutes because a stranger said so.

Phishing defense is not a product you buy. It is slow habits on a fast internet.

⚑ One honest flag

No legitimate crypto service needs your seed phrase after your wallet is set up. Anyone who asks for it — in a form, a chat, or a “verification” page — is not troubleshooting. They are fishing. Close the tab.

If this cleared something up, you can buy me a coffee — or say hi on X.

← All guides