Crypto glossary

Phishing

Phishing is fraud that uses fake websites, apps, emails or messages that look genuine to trick you into a harmful action, such as entering your seed phrase, logging in on a copied page or signing a transaction that hands over your funds.

Auf Deutsch lesen

How crypto phishing works

The attacker imitates something you trust: a wallet, an exchange, a DeFi app, a support team or a well-known project. The goal is always the same, to get you to give away access. In traditional phishing that means a password. In crypto, it usually means your seed phrase or a signature that authorizes the attacker to move your tokens, and once that happens, the loss is final.

Common forms

Fake websites with lookalike addresses, often promoted through search ads, that ask you to connect your wallet or enter your recovery phrase. Fake apps and browser extensions in official stores. Emails or texts claiming your account is locked or a wallet update is required. Direct messages from fake support staff on Discord, Telegram or X. Airdrop or mint pages that ask you to sign a permit or approval, which lets a wallet drainer take your tokens.

Address poisoning is a newer variant: the attacker sends a tiny transaction from an address that looks like one you use, hoping you copy it from your history next time.

An example

Say you search for a popular DeFi app and click the first result, which is an ad. The page looks identical. You connect your wallet to claim a reward, and it asks you to sign a message. The message is actually a permission for another contract to spend all your USDC. Minutes later, your balance is gone. Nothing was hacked; you signed it.

How to protect yourself

Never type your seed phrase anywhere except when restoring a wallet on a device you control. Bookmark the sites you use and avoid search ads. Treat unsolicited messages, urgent deadlines and offers that sound too good as warning signs. Read what a wallet asks you to sign and reject anything you do not understand. Use a separate wallet with small funds for new apps, and review and revoke token approvals regularly.

Ask Coach about it

Coach is the AI on AtenaCrypto. It explains crypto with live market data, in plain words.

How do permit signatures used by wallet drainers work, and how can I recognize one in my wallet before signing?Ask Coach →

Frequently asked questions

Will a real support team ever ask for my seed phrase?

No. Legitimate wallets, exchanges and projects never need your seed phrase. Anyone asking for it is a scammer.

I signed something on a phishing site. What now?

Act fast: revoke the approvals you granted, move remaining funds to a new wallet with a new seed phrase if your phrase may be exposed, and report the site.

How can I check if a website is real?

Use bookmarks or links from the project's verified official channels, check the domain letter by letter, and be suspicious of pages reached through ads or messages.

Related terms

Social EngineeringWallet DrainerSeed PhraseBlind SigningToken AllowanceRevoke

Learn it step by step

AC Learning explains these ideas in interactive lessons — the first eight sections are free.

Open AC Learning → Create a free account

All glossary terms · Educational reference only — not investment, legal, tax or financial advice.