Skip to main content

Phishing

Phishing is a social engineering attack where malicious actors impersonate legitimate platforms, services, or individuals to deceive users into disclosing sensitive information, such as private keys, seed phrases, or login credentials. In the crypto sector, phishing is highly sophisticated; attackers often create fake websites, send fraudulent emails, or use social media bots to trick users into signing malicious transactions that drain their wallets.

Definition

Phishing is a social engineering attack where malicious actors impersonate legitimate platforms, services, or individuals to deceive users into disclosing sensitive information, such as private keys, seed phrases, or login credentials. In the crypto sector, phishing is highly sophisticated; attackers often create fake websites, send fraudulent emails, or use social media bots to trick users into signing malicious transactions that drain their wallets.

Simple explanation

Phishing is a ‘digital con job.’ A scammer pretends to be your bank or a famous project website, sending you an email or link that looks perfectly real. They want to trick you into typing in your secret recovery password so they can log in and take everything you have in your account.

Why it matters

Phishing remains the most common way individual users lose assets in crypto. It bypasses even the most secure technical protocols because it targets the weakest link: human error.

How it works

The attacker sets up a fake interface that mimics a real service. They lure victims through ads, phishing emails, or social engineering. Once a victim connects their wallet to the malicious site, they are asked to sign a transaction or reveal their seed phrase, which immediately transfers their assets to the attacker’s wallet.

Real-world example

Fake NFT minting sites often emerge during popular project launches, tricking users into signing ‘set approval for all’ transactions that grant the scammer access to their entire wallet.

Advantages

  • Highlights the necessity of wallet security
  • Demonstrates the importance of user verification
  • Encourages use of hardware wallets

Limitations

  • Highly effective against non-technical users
  • Irreversible once funds are moved
  • Constantly evolving and difficult to track

Common misconceptions

  • Many people believe they are safe because they don’t ‘give away’ their private key, not realizing that signing a malicious transaction is effectively the same.
  • Users assume that using a ‘verified’ Twitter account prevents them from being phished, ignoring that accounts can be hacked.

Canonical knowledge ID: glossary:phishing