Skip to content
MyCryptoStart

Wallets & security

What Is Phishing in Crypto and How Do You Spot It?

Short answer

Phishing is a scam where attackers impersonate a service you trust — an exchange, wallet, or support team — to trick you into handing over access. In crypto it takes three main forms: fake login pages that capture your credentials, fake support agents who ask for your seed phrase, and malicious websites that request a wallet approval signature that drains your funds. Crypto phishing is irreversible: stolen funds are usually gone within minutes.

Key takeaways

  • Fake sites clone real ones perfectly — the only reliable check is the URL, typed yourself or from a bookmark.
  • No legitimate support team ever asks for your seed phrase, password, or 2FA code.
  • Wallet 'signature requests' can grant contracts permission to spend your tokens — read what you're approving or decline.
  • Urgency is the tell: 'account locked', 'verify now', 'one chance to claim'. Real services don't work like that.

What does crypto phishing look like?

The classic move: something creates urgency — an email about a login from abroad, a DM about an airdrop you qualified for, a search-ad “Binance” that’s actually binnance-secure.com — and then a pixel-perfect copy of the real site. You enter your password and 2FA code into the fake; the attacker’s automation relays them to the real site within seconds and logs in as you. Modern phishing kits defeat every “check the design” instinct, because the design is real. The URL is the only fingerprint that can’t be faked, which is why navigation discipline beats vigilance: don’t evaluate links, refuse to click them.

The more advanced variant skips passwords entirely: a DeFi site asks your wallet to sign an “approval” that grants a contract unlimited rights to a token, and the drain happens later while you sleep — sometimes weeks later, when you’ve forgotten you ever signed. Both run on the same engine: a moment of diverted attention.

The pattern library, condensed

Every phishing play in crypto is one of a handful of shapes:

PretextWhat they wantThe give-away
“Verify your wallet” airdrop/claimA signature or approvalYou never entered anything
“Wallet compromised — secure it here”Your seed phraseReal wallets don’t ask
“Support” in Telegram/Discord DMsCredentials, phrase, screen shareReal support never DMs first
Exchange “security alert” emailLogin on a fake pageArrived by link, urgency tone
Too-good APY / giveawayA depositGuaranteed returns don’t exist

Notice the common thread: every row requires you to act on their timeline. Slowness — typing the URL yourself, waiting a day before claiming anything, asking “why does support need this?” — dissolves nearly all of it.

Which defenses actually work?

Three, layered. Navigation discipline: never click into a financial site from email, DM, or search ads — type the address or use your own bookmark, every time. Phrase hygiene: the moment anyone, in any channel, asks for your seed phrase, the conversation is over; the answer is always no. Signature awareness: when a wallet pops a confirmation, read the actual permission being requested, not just the branding around it — unlimited token approvals are a red flag most wallets now warn about, and periodic approval revocation is cheap insurance.

You clicked. Now what?

Speed matters because attackers automate the cash-out. For an exchange account: change the password immediately, revoke active sessions and API keys, and contact the exchange’s real support — freezes sometimes work if you’re fast. For a wallet signature: move remaining funds to a fresh wallet (new keys, new phrase), then revoke old approvals using a token-allowance tool. And accept the loss honestly if funds are gone — “recovery services” that DM you afterward are the second scorpion of the phishing scam, and they will ask for a fee and your seed phrase.

Approval hygiene: auditing what you’ve already signed

Phishing defense usually focuses on the next click, but the dangerous clicks you already made can linger for months. Token approvals — permissions granted to contracts to move your tokens — don’t expire, and unlimited approvals are common enough that many users carry a dozen standing invitations without knowing it.

The quarterly routine:

  1. Open an allowance checker (revoke.cash, or your wallet’s built-in approvals view) and connect the wallet — read-only, signing nothing.
  2. Read the list. Every row is a contract allowed to spend a token. Recognition test: anything you don’t remember approving gets revoked.
  3. Revoke by default. Revoking costs a small fee and nothing else; you can always re-approve when you actually need the protocol again.
  4. Prioritize unlimited approvals on tokens with real value — those are the standing balances attackers monetize when any spender contract turns out to be malicious later.

This habit closes the “weeks later” drain: the exploit that gets published for a protocol you used in March can’t hurt the November you if November-you revoked the March approval. It’s ten minutes a quarter, and it’s the only defense that operates on past mistakes instead of future ones.

Frequently asked questions

How do I check if a crypto website is fake?
Ignore the design — clones are pixel-perfect — and read the URL character by character: swapped letters (rn for m), added hyphens, wrong endings (.co for .com), and lookalike Unicode characters are the standard tricks. The reliable method is to never arrive by link at all: type the address or use your own bookmark, every time, and let browser password managers help — they refuse to autofill on lookalike domains.
Can a wallet signature request really empty my wallet?
Yes — two different mechanics. An approval (token allowance) grants a contract standing permission to move a specific token whenever it wants, and unlimited approvals are common in DeFi defaults. A direct signature can trigger an immediate transfer of whatever the message covers. Both are granted by one click on the wrong site, which is why every unexpected signature request deserves a full read before you touch confirm.
I entered my password on a fake exchange site. What now?
Within minutes: change the password on the real site, revoke all active sessions and API keys, enable or tighten [2FA](/glossary/two-factor-authentication/), and contact the exchange's real support — fast freezes sometimes work. If you also entered a 2FA code or used the same password elsewhere, treat every other account sharing that password as compromised too.
Are crypto 'recovery services' legit?
Almost always a second scam stacked on the first. Real on-chain recovery is rare, specialist work; the DMs that find you after a theft promising guaranteed recovery for an upfront fee — and eventually your seed phrase — are the same operation monetizing you twice. Law enforcement and the exchange's own support are the only channels with any real recovery power.

Editor-in-Chief & Lead Researcher

Lucas Almeida

Editor of MyCryptoStart. Independent researcher of cryptocurrency exchanges, focused on fees, security, KYC, and onboarding — publishes step-by-step guides in plain English for beginners.

View author page →

Some links on this page are affiliate links: we may earn a commission at no extra cost to you. This content is educational and is not financial, investment, or legal advice. Affiliate disclosure · Disclaimer.

Learn more about phishing

Our full guides that cover this term in depth.