How Crypto Phishing Scams Work
Understanding the mechanics of crypto phishing is the first step to avoiding it. Here are the five most common attack types — with exactly how each works and how to defend against it.

Ashir Khan writes about cryptocurrency security, self-custody, macro market analysis, and regulatory policy at CryptoBeacon.
Crypto phishing is uniquely dangerous because transactions are irreversible. Unlike bank fraud, there is no chargeback mechanism and no customer support line that can recover stolen funds.
The five attack types
Seed Phrase Phishing
Fake wallet websites or apps prompt you to enter your seed phrase to 'restore' or 'verify' your wallet. Once entered, your funds are immediately drained. These sites are often promoted through paid search ads.
Your seed phrase is never needed by any online service. Never enter it anywhere except on your hardware wallet device itself during initial setup.
Approval Phishing
You are asked to sign a transaction that appears routine (claiming a reward, minting an NFT) but is actually an ERC-20 approval granting an attacker's contract unlimited spending rights for a token you hold.
Read every transaction detail before signing. If a site asks you to approve spending of tokens when you just wanted to claim something free, that is a red flag.
DNS Hijacking
Attackers compromise the DNS records of legitimate DeFi protocols. Users who navigate to the correct URL are served the attacker's clone site. The URL looks legitimate but the site is controlled by attackers.
Bookmark trusted DeFi sites rather than searching or following links. Check social media for warnings before interacting with a protocol during market volatility when attacks often occur.
Spear Phishing
Targeted attacks against specific individuals — developers, influencers, or large holders. Attackers impersonate colleagues, investors, or journalists and send tailored messages with malicious links or attachments.
Verify unexpected contact through a secondary channel. Never open unsolicited attachments. Use a separate air-gapped machine for signing large transactions.
Browser Extension Attacks
Malicious browser extensions can intercept wallet connection requests, modify transaction data on-the-fly, or read clipboard content to replace addresses. Extensions with broad permissions are dangerous.
Minimise browser extensions on any browser used for crypto. Use a separate browser profile or dedicated browser solely for Web3 interactions.
Universal anti-phishing habits
- Never click crypto-related links from email, Discord, Telegram, or Twitter DMs
- Bookmark all sites you use regularly — never search for them
- Verify the exact URL character-by-character, including TLD (.com vs .io vs .net)
- Read every transaction on your hardware wallet screen before confirming
- Never share your seed phrase or private key with anyone or anything
