Wallets & security
What Is Phishing in Crypto and How Do You Spot It?
Short answer
Phishing is a scam where attackers impersonate a service you trust — an exchange, wallet, or support team — to trick you into handing over access. In crypto it takes three main forms: fake login pages that capture your credentials, fake support agents who ask for your seed phrase, and malicious websites that request a wallet approval signature that drains your funds. Crypto phishing is irreversible: stolen funds are usually gone within minutes.
Key takeaways
- Fake sites clone real ones perfectly — the only reliable check is the URL, typed yourself or from a bookmark.
- No legitimate support team ever asks for your seed phrase, password, or 2FA code.
- Wallet 'signature requests' can grant contracts permission to spend your tokens — read what you're approving or decline.
- Urgency is the tell: 'account locked', 'verify now', 'one chance to claim'. Real services don't work like that.
What does crypto phishing look like?
The classic move: something creates urgency — an email about a login from
abroad, a DM about an airdrop you qualified for, a search-ad “Binance” that’s
actually binnance-secure.com — and then a pixel-perfect copy of the real
site. You enter your password and 2FA code into the fake; the attacker’s
automation relays them to the real site within seconds and logs in as you.
Modern phishing kits defeat every “check the design” instinct, because the
design is real. The URL is the only fingerprint that can’t be faked, which
is why navigation discipline beats vigilance: don’t evaluate links, refuse
to click them.
The more advanced variant skips passwords entirely: a DeFi site asks your wallet to sign an “approval” that grants a contract unlimited rights to a token, and the drain happens later while you sleep — sometimes weeks later, when you’ve forgotten you ever signed. Both run on the same engine: a moment of diverted attention.
The pattern library, condensed
Every phishing play in crypto is one of a handful of shapes:
| Pretext | What they want | The give-away |
|---|---|---|
| “Verify your wallet” airdrop/claim | A signature or approval | You never entered anything |
| “Wallet compromised — secure it here” | Your seed phrase | Real wallets don’t ask |
| “Support” in Telegram/Discord DMs | Credentials, phrase, screen share | Real support never DMs first |
| Exchange “security alert” email | Login on a fake page | Arrived by link, urgency tone |
| Too-good APY / giveaway | A deposit | Guaranteed returns don’t exist |
Notice the common thread: every row requires you to act on their timeline. Slowness — typing the URL yourself, waiting a day before claiming anything, asking “why does support need this?” — dissolves nearly all of it.
Which defenses actually work?
Three, layered. Navigation discipline: never click into a financial site from email, DM, or search ads — type the address or use your own bookmark, every time. Phrase hygiene: the moment anyone, in any channel, asks for your seed phrase, the conversation is over; the answer is always no. Signature awareness: when a wallet pops a confirmation, read the actual permission being requested, not just the branding around it — unlimited token approvals are a red flag most wallets now warn about, and periodic approval revocation is cheap insurance.
You clicked. Now what?
Speed matters because attackers automate the cash-out. For an exchange account: change the password immediately, revoke active sessions and API keys, and contact the exchange’s real support — freezes sometimes work if you’re fast. For a wallet signature: move remaining funds to a fresh wallet (new keys, new phrase), then revoke old approvals using a token-allowance tool. And accept the loss honestly if funds are gone — “recovery services” that DM you afterward are the second scorpion of the phishing scam, and they will ask for a fee and your seed phrase.
Approval hygiene: auditing what you’ve already signed
Phishing defense usually focuses on the next click, but the dangerous clicks you already made can linger for months. Token approvals — permissions granted to contracts to move your tokens — don’t expire, and unlimited approvals are common enough that many users carry a dozen standing invitations without knowing it.
The quarterly routine:
- Open an allowance checker (revoke.cash, or your wallet’s built-in approvals view) and connect the wallet — read-only, signing nothing.
- Read the list. Every row is a contract allowed to spend a token. Recognition test: anything you don’t remember approving gets revoked.
- Revoke by default. Revoking costs a small fee and nothing else; you can always re-approve when you actually need the protocol again.
- Prioritize unlimited approvals on tokens with real value — those are the standing balances attackers monetize when any spender contract turns out to be malicious later.
This habit closes the “weeks later” drain: the exploit that gets published for a protocol you used in March can’t hurt the November you if November-you revoked the March approval. It’s ten minutes a quarter, and it’s the only defense that operates on past mistakes instead of future ones.
Frequently asked questions
How do I check if a crypto website is fake?
Can a wallet signature request really empty my wallet?
I entered my password on a fake exchange site. What now?
Are crypto 'recovery services' legit?
Related terms
Editor-in-Chief & Lead Researcher
Editor of MyCryptoStart. Independent researcher of cryptocurrency exchanges, focused on fees, security, KYC, and onboarding — publishes step-by-step guides in plain English for beginners.
View author page →Some links on this page are affiliate links: we may earn a commission at no extra cost to you. This content is educational and is not financial, investment, or legal advice. Affiliate disclosure · Disclaimer.
Learn more about phishing
Our full guides that cover this term in depth.
What Is a Private Key? (And Why It's Secret)
A private key is the secret code that proves you own your crypto and lets you spend it. Learn how it works and how to keep it safe.
How to Create a Binance Account (2026 Guide)
Create a Binance account in about five minutes: sign up with email or phone, verify KYC, and turn on 2FA. Step-by-step guide for beginners.
What Is Cryptocurrency? A Beginner's Guide
Cryptocurrency is digital money secured by cryptography and recorded on a public ledger called a blockchain. Learn how it works and how to start safely.