Crypto

How crypto phishing attacks actually work

How crypto phishing attacks work: the tricks that steal wallets, the wallet-drainer signature scam, and the simple habits that stop them before you sign.

How crypto phishing attacks actually work

Quick answer

Crypto phishing tricks you into revealing a secret or signing a transaction instead of breaking any cryptography. Attackers use lookalike sites, fake support, and fake airdrops to capture your seed phrase, exchange login, or a wallet approval. Because on-chain transfers are final, the defence is to slow down and read every signature before confirming.

Key points

  • Phishing attacks people, not cryptography
  • No legitimate service ever needs your seed phrase
  • Connecting a wallet is low-risk; signing is where theft happens
  • Watch for unexpected approve, Permit or setApprovalForAll prompts
  • Bookmark real sites and never reach wallets through ads

Crypto phishing is a form of theft where an attacker tricks you into revealing a secret or signing a transaction, rather than breaking any cryptography. The maths behind Bitcoin or Ethereum is not the weak point; you are. Almost every large loss that gets blamed on “hacking” actually starts with a convincing message, a lookalike website, or a wallet pop-up that the victim approved themselves.

Understanding the mechanics matters because self-custody has no fraud department. When a bank transfer is stolen, a human can sometimes reverse it. On a public blockchain, a confirmed transaction is final. That finality is a feature for legitimate payments and a trap once an attacker has your signature.

What phishers are actually after

There are only a few things an attacker needs, and each maps to a different attack style:

  • Your seed phrase or private key. This is the master secret to a self-custody wallet. Anyone who has it controls every asset in that wallet, forever. See our explainer on what seed phrases are and how people lose them.
  • Your exchange login and 2FA code. For funds held on a centralised exchange, the account credentials are the target. This is closer to traditional account-takeover fraud.
  • A transaction signature. Increasingly, attackers do not need your key at all. They just need you to sign something in your own wallet — often a token approval that lets their contract move your funds later.

Recognising which secret is being targeted tells you what a request should never ask for. No legitimate service, ever, needs your seed phrase.

The common delivery methods

Phishing is a delivery problem before it is a technical one. The recurring channels are worth naming so you recognise them under pressure:

  • Lookalike websites. A domain one character off from the real one, often promoted through paid search ads that sit above the genuine result. The page is a pixel-perfect clone whose only job is to capture what you type or connect your wallet.
  • Fake support. You post a problem in a public channel and a “support agent” direct-messages you within minutes. Real support almost never DMs first, and never asks for your recovery phrase.
  • Airdrop and “claim” lures. A message says you are owed free tokens. The claim page asks you to connect your wallet and sign a transaction that quietly grants spending permission.
  • Compromised accounts. A project’s own social media or Discord gets taken over and a malicious “mint” or “migration” link is posted. Because it comes from a trusted handle, defences drop.
  • Clipboard and malware attacks. Malware silently swaps a copied wallet address for the attacker’s, so you paste the wrong destination without noticing.

Wallet-drainer phishing, step by step

The most damaging modern variant deserves a closer look, described here purely so you can spot it. A “drainer” is a pre-built kit that turns a signature into a theft. The flow is consistent:

  • You land on a lookalike or lure page and click Connect Wallet. Connecting alone is low-risk — it only shares your public address.
  • The site then prompts a signature. This is the decisive moment. It may be a token approve or setApprovalForAll, a gasless Permit signature, or a request to interact with a malicious contract.
  • If you approve, the attacker’s contract now has permission to move specific tokens or NFTs from your wallet, sometimes with no further interaction from you.
  • The drain executes, often within seconds, and the transaction confirms on-chain with your valid signature attached.

The uncomfortable truth is that the blockchain worked exactly as designed. There was no bug. You authorised the transfer. That is why prevention lives entirely in the moment before you sign.

Newer variants worth knowing

Phishing evolves to defeat the last round of advice, so a few current twists are worth recognising:

  • Address poisoning. The attacker sends you a tiny or zero-value transaction from an address that looks almost identical to one you use often — matching first and last characters. Later, when you copy a “recent” address from your history, you paste theirs and send real funds to it. Always copy destination addresses from a trusted source, never from transaction history.
  • Fake browser extensions and wallet updates. A pop-up or ad urges you to “update” your wallet extension or install a plug-in that turns out to be a key-stealer. Update only from the official store listing you reached yourself.
  • Malicious QR codes. A code posted publicly or sent to you leads to a lookalike site or pre-fills a payment to the attacker. Treat scanned links with the same suspicion as typed ones.
  • Search-ad and sponsored-result spoofing. Attackers buy ads that appear above the genuine site for common wallet and exchange searches. The safest habit is to bookmark the real sites and never reach them through an ad.

The common thread is that each variant tries to insert a fraudulent destination or signature into a moment you think is routine. Slowing down at exactly those routine moments is what defeats them.

The tells: how to spot a phishing attempt

Phishing relies on speed and emotion, so slowing down is itself a defence. Concrete warning signs:

  • Urgency and scarcity. “Claim in the next 10 minutes,” “your wallet is at risk,” “limited slots.” Pressure is the point.
  • An unsolicited approach. You did not start the conversation, yet someone is offering help, money, or a rare opportunity.
  • A request for your seed phrase or private key. This is always fraud, with no exceptions. Wallet software never needs you to type your phrase into a website.
  • A signature request you cannot read. If the wallet shows an approve, Permit, or setApprovalForAll you did not intend, stop.
  • A URL that is almost right. Check the full domain character by character, not just the logo.

Defending yourself in practice

Defence is a set of habits, not a single product. The ones that matter most:

  • Type or bookmark URLs; never click ads for wallets or exchanges. Paid search results are a favourite phishing vector.
  • Treat every signature as if it moves money, because it can. Read what your wallet is asking. If it is an approval, confirm the spender and amount.
  • Use a hardware wallet for meaningful balances. It forces you to confirm details on a separate screen an attacker cannot fake. See hardware versus software wallets, honestly compared.
  • Keep a “clean” wallet for connecting to new sites and hold long-term assets in a separate address you never connect to random dApps.
  • Review and revoke stale approvals periodically using a reputable tool. Our guide to token approvals covers how.
  • Verify contracts before interacting. Our walkthrough on how to verify a contract address shows the checks.

What this means

Crypto phishing works because it targets the one part of the system that cannot be patched: human judgement under pressure. The cryptography is sound, which is precisely why attackers do not attack it — they ask you to hand over the keys or sign the transfer yourself. Your strongest defence is a slower reflex: assume unsolicited messages are hostile, never enter a seed phrase anywhere, and read every signature before approving it. If a stolen transaction confirms, there is no undo, so the entire game is won or lost in the seconds before you click Confirm. Treat that click with the seriousness it deserves and the vast majority of phishing simply fails.

Sources

  1. Ethereum.org — Security
  2. CISA — Recognize and Report Phishing

Frequently asked questions

Can a phishing site steal my crypto just because I connected my wallet?

Connecting alone only shares your public address, which is low-risk. The theft happens if you then approve a signature or token permission the site requests, so the danger is in what you sign, not the connection itself.

Would a real exchange or wallet ever ask for my seed phrase?

No. No legitimate service needs your recovery phrase or private key. Any message or website asking for it is fraudulent, without exception.

I think I signed a malicious approval. What should I do?

Move remaining assets to a fresh wallet you control, then revoke the malicious approval using a reputable approval-checker tool. Once a drain transaction has confirmed on-chain it cannot be reversed.

Last reviewed: 26 Aug 2026 Next review: 26 Feb 2027 Section: Crypto
Liam Chen
Protocol & security writer · Blockchain mechanics, wallet security, cryptography

Liam Chen writes about how crypto works at the protocol level — consensus, cryptography, wallets and security. He explains mechanisms plainly and cites primary sources.

More by Liam Chen

Related

Crypto

What is a Merkle tree?

A Merkle tree summarises many items into one hash. Learn what a Merkle tree is, how it is built from…

Liam Chen · Aug 26, 2026 · 5 min
Crypto

KYC and AML in crypto, explained

KYC and AML in crypto explained: what identity checks and anti-money-laundering rules mean, why exchanges verify you, and how the…

Liam Chen · Aug 26, 2026 · 6 min