0%
Level 4: Risk & Safety

Phishing Patterns

How attackers trick people into giving up their crypto.

7 min read
Phishing
Social engineering attacks that trick victims into revealing sensitive information (like seed phrases or passwords) or signing malicious transactions, typically by impersonating legitimate services.
Why Phishing Works

Phishing exploits trust and urgency. Attackers create convincing replicas of legitimate services and manufacture scenarios where victims feel they must act quickly. Even experienced users fall for sophisticated attacks.

Common Attack Patterns

Fake Websites

Clone sites that look identical to real exchanges/wallets but steal credentials.

Examples:
  • uniswapp.com instead of uniswap.org
  • metamask.io.com instead of metamask.io
  • Sites appearing in Google Ads before real results
Protection:

Bookmark official sites. Never click links from messages.

Phishing Emails

Emails claiming urgent action needed on your account.

Examples:
  • "Your account will be suspended"
  • "Verify your wallet to receive airdrop"
  • "Security alert: unauthorized login detected"
Protection:

Never click email links. Go directly to official site.

Social Media DMs

Fake support accounts reaching out after you post questions.

Examples:
  • "I'm a moderator, I can help with your issue"
  • "Connect wallet to this link to fix"
  • Accounts with similar names to official support
Protection:

Real support NEVER DMs first. Ignore all unsolicited messages.

Malicious Browser Extensions

Fake wallet extensions that capture your seed phrase.

Examples:
  • Extensions with names similar to popular wallets
  • Extensions asking to "import" existing wallet
  • Promoted extensions in app stores
Protection:

Only download from official websites. Verify extension IDs.

URL Red Flags

Always examine URLs carefully before entering any information:

metamask.io.comFAKE - extra domain
metamask.ioREAL - official domain
uniswap.org.financeFAKE - extra subdomain
un1swap.orgFAKE - number replacing letter

Anti-Phishing Checklist

Bookmark official sites and only access through bookmarks
Never click links in emails, DMs, or ads
Verify URL carefully before connecting wallet
Real support never contacts you first
Download wallet extensions only from official sites
Use hardware wallet for transaction signing
Enable 2FA on all exchange accounts
Be suspicious of urgency and "limited time" offers
What Beginners Should Remember
  • Slow down — urgency is a manipulation tactic
  • When in doubt, don't click. Go directly to official site.
  • No legitimate service will ever ask for your seed phrase
  • Bookmark and use only those bookmarks for crypto sites
  • Assume any unsolicited contact is a scam until proven otherwise