Fri, 28 August 2026
Security10 May 2026

Phishing in crypto: how to recognize the most common traps

In 2026, phishing remains the biggest cause of lost crypto among private individuals. A practical guide to recognizing the well-known tricks before you experience them.

Article image for: Phishing in crypto: how to recognize the most common traps

Why crypto phishing is so effective

In the traditional world you can often still reverse a fraudulent withdrawal. With crypto, a transaction is final once it is confirmed. Phishers know this, which is why they increasingly target wallet signatures instead of passwords.

The five most common forms

1. Fake emails from your exchange

An email that looks like your exchange, with a button to ‘check unusual activity’. The link leads to a copy of the site that captures your login details and 2FA code.

2. Fake support on Discord and Telegram

You ask a question in an official channel and within seconds receive a private message from ‘support’. Real support never sends the first DM.

3. Wallet drainers via a signature

You are led to a page that asks you to sign something innocent (for example, to claim an airdrop). In reality you grant an unlimited approval that lets your tokens be drained.

4. Fake airdrop tokens in your wallet

You see an unknown token in your wallet with a high ‘value’. Anyone who tries to sell it ends up on a phishing site.

5. Copycat extensions in the browser store

An extension with the same name and logo as your real wallet, but with reviews only a few hours old. After installation it sends your seed phrase straight on.

Five habits that protect you

  1. Always type your exchange's URL yourself, or use a bookmark.
  2. With every wallet signature, read which permissions you are granting. Unlimited approvals are a red flag.
  3. Regularly revoke old approvals using tools like Revoke.cash.
  4. Keep your seed phrase offline, never in a notes app or the cloud.
  5. Be extra alert to urgency. Phishers work with time pressure because it switches off reason.

What to do after a phishing attempt

  • Stop clicking anything on the suspicious page.
  • Open your wallet and revoke all outstanding approvals.
  • Move any remaining funds to a new wallet with a new seed phrase if you have doubts.
  • Report the incident to your exchange and to the relevant fraud helpdesk.

Closing

The technology behind crypto is strong, but the weakest link is usually between keyboard and chair. A few habits make the difference between an instructive scare and a painful loss.

#security#phishing#wallet#tips