Security · Phishing

How Crypto Phishing Scams Work

Understanding the mechanics of crypto phishing is the first step to avoiding it. Here are the five most common attack types — with exactly how each works and how to defend against it.

Ashir Khan
By Ashir Khan3 min read

Ashir Khan writes about cryptocurrency security, self-custody, macro market analysis, and regulatory policy at CryptoBeacon.

Last updated:

Crypto phishing is uniquely dangerous because transactions are irreversible. Unlike bank fraud, there is no chargeback mechanism and no customer support line that can recover stolen funds.

The five attack types

01

Seed Phrase Phishing

How it works

Fake wallet websites or apps prompt you to enter your seed phrase to 'restore' or 'verify' your wallet. Once entered, your funds are immediately drained. These sites are often promoted through paid search ads.

Defence

Your seed phrase is never needed by any online service. Never enter it anywhere except on your hardware wallet device itself during initial setup.

02

Approval Phishing

How it works

You are asked to sign a transaction that appears routine (claiming a reward, minting an NFT) but is actually an ERC-20 approval granting an attacker's contract unlimited spending rights for a token you hold.

Defence

Read every transaction detail before signing. If a site asks you to approve spending of tokens when you just wanted to claim something free, that is a red flag.

03

DNS Hijacking

How it works

Attackers compromise the DNS records of legitimate DeFi protocols. Users who navigate to the correct URL are served the attacker's clone site. The URL looks legitimate but the site is controlled by attackers.

Defence

Bookmark trusted DeFi sites rather than searching or following links. Check social media for warnings before interacting with a protocol during market volatility when attacks often occur.

04

Spear Phishing

How it works

Targeted attacks against specific individuals — developers, influencers, or large holders. Attackers impersonate colleagues, investors, or journalists and send tailored messages with malicious links or attachments.

Defence

Verify unexpected contact through a secondary channel. Never open unsolicited attachments. Use a separate air-gapped machine for signing large transactions.

05

Browser Extension Attacks

How it works

Malicious browser extensions can intercept wallet connection requests, modify transaction data on-the-fly, or read clipboard content to replace addresses. Extensions with broad permissions are dangerous.

Defence

Minimise browser extensions on any browser used for crypto. Use a separate browser profile or dedicated browser solely for Web3 interactions.

Universal anti-phishing habits

  • Never click crypto-related links from email, Discord, Telegram, or Twitter DMs
  • Bookmark all sites you use regularly — never search for them
  • Verify the exact URL character-by-character, including TLD (.com vs .io vs .net)
  • Read every transaction on your hardware wallet screen before confirming
  • Never share your seed phrase or private key with anyone or anything