What Is Phishing in Crypto?
Phishing is impersonation with a payment rail. Someone pretends to be a site, service, or person you trust, and walks you into surrendering access: a seed phrase, a malicious signature, or a transfer to the wrong address. In crypto the loot is irreversible, so the craft has become industrial.
The Variants Worth Knowing
- Clone sites. Pixel-perfect copies of wallets, exchanges, and marketplaces at lookalike domains, often promoted by paid ads above the real result.
- Fake support. You post a problem publicly; "support" arrives in DMs, sympathetic and fast, with a validation site or a seed-phrase form. Real support never DMs first and never needs your phrase.
- Fake airdrops and mints. Free tokens or urgent claim pages whose claim button is a drainer signature.
- Compromised communities. A hacked project Discord or X account posting an "official" surprise mint to thousands of followers at once.
- Targeted email and SMS. Exchange-branded security alerts herding you to log in on a clone, plus SIM-swap setups for the personal touch.
- On-chain lures. Mystery tokens and NFTs in your wallet whose websites are traps, and poisoned addresses seeded into your history.
The Checklist That Beats Nearly All of It
- Bookmark real URLs once; never navigate by ad, DM, or reply link.
- The seed phrase goes nowhere, ever. No exceptions survive contact with this rule.
- Unsolicited help is hostile until proven otherwise. Urgency is the tell: real services do not give you nine minutes to act.
- Read every signature request. Unsure what it does means the answer is no.
- Keep a no-approvals vault wallet so one mistake cannot take everything. Full habits: Wallet Security and Self-Custody.
When It Matters
Phishing is the top way regular people lose crypto, ahead of every exotic hack. Report incidents to the FTC and IC3; check suspicious addresses on Chainabuse.
Related Terms
Glossary · Learn · Resource Library · Return to Official Home Page
Copyright © 2026 Crypto Guidance Inc.