Topic

What is crypto phishing?

Last reviewed:

The short lesson

Phishing is a message that pretends to be someone you trust, so you will click, log in or hand over a secret. In crypto, the prize is your exchange login, your 2FA code, your seed phrase or a wallet approval.

Common forms:

  • “Your account is locked.” An email or text that looks like your exchange, with a link to a fake login page.
  • Fake support. A reply to your public post, or a pop-up chat, offering help and asking for your seed phrase.
  • Search ads and look-alike sites. A site that copies a real wallet or exchange, one letter off in the address.
  • Fake airdrops and mints. “Claim your tokens” pages that ask you to connect and approve.

Habits that beat phishing:

  • Go to the site yourself. Use a bookmark or type the address. Do not use links in messages.
  • Never type your seed phrase into any website. Real services do not ask.
  • Read what you sign. If a wallet asks for an approval you did not expect, reject it.

Paste a suspicious message into our Scam message decoder to see its red flags.

A candle, an old key-shaped magnifier and a map on a dark table

Related terms

Common questions

How do I know if an email from an exchange is real?

Do not use the link. Open the app or type the site address yourself and check your messages there.

What if I clicked a phishing link?

If you entered a password, change it now and turn on stronger 2FA. If you entered a seed phrase, move what is left to a new wallet right away.

Can phishing show up in search results?

Yes. Fake ads can copy real names. Use bookmarks for sites you use often.

Where do I report phishing?

In the US, at ReportFraud.ftc.gov. Also tell the real company being copied.

Start here

Start here. Learn first. The sample lessons, topic pages, glossary and tools are open, with no card and no sign-up.

Start with Lesson 1