Search
Phishing emails, fake login pages, malicious links, and account theft prevention.
Phishing is an attack where criminals pretend to be a trusted person, company, bank, exchange, delivery service, employer, or website so they can trick you into giving away information or taking an unsafe action.
Phishing in cryptocurrency communities is often much more sophisticated than a random fake email or badly designed login page.
Attackers frequently target people who already follow a token, project, exchange, wallet, or crypto community because those people are more likely to recognize the name being used in the scam. That familiarity gives the attacker an advantage.
Instead of approaching someone with a completely unrelated story, the scammer can build the message around something the victim already understands and may already be interested in.
A person who follows a token project on X, joins its Telegram group, participates in its Discord server, or holds the token may be approached with a message about an airdrop, migration, giveaway, staking opportunity, blocked transaction, withdrawal issue, wallet update, or supposed investment opportunity.
The story changes, but the objective is usually the same: persuade the victim to interact with a malicious link, connect a wallet, approve something dangerous, or reveal wallet credentials.
One of the most common tactics is impersonation.
Attackers may clone the profile of a project administrator, community manager, moderator, support representative, or official social media account.
The copied account may use the same:
The fake account can then begin contacting community members directly.
A victim might receive a message asking:
“Have you claimed your airdrop yet?â€
“Are you having problems with your withdrawal?â€
“Did your token migration complete successfully?â€
“Would you like to participate in the next investment round?â€
“Your transaction appears to be blocked. I can help you fix it.â€
These messages work because they sound connected to something that could realistically happen inside a crypto project.
If the community is discussing a migration, attackers may use migration as their story.
If users are waiting for an airdrop, the phishing campaign may focus on claiming the airdrop.
If the project recently experienced technical problems, fake support accounts may approach users who publicly mention those problems.
The scammer does not necessarily need to invent the entire situation. They can simply take advantage of a real event happening inside the community.
Crypto users regularly ask questions publicly.
Someone may write in a Telegram group:
“My withdrawal is still pending.â€
Another person may say:
“My transaction has been stuck for hours.â€
Someone else might ask:
“How do I migrate my old tokens?â€
An attacker watching the group now knows exactly what problem that person is experiencing.
The scammer can send a private message pretending to be support.
They may say they have noticed the issue and can help solve it.
The victim may assume the message is legitimate because the person appears to know exactly what they were discussing.
The attacker then provides a link to a supposed support page, migration portal, verification page, or wallet synchronization service.
The technical problem may be real.
The support representative is not.
On Telegram, attackers sometimes become even more aggressive.
A new member may receive a private message or even a voice call shortly after joining a crypto group.
The caller may claim to be:
In some cases, scammers may deliberately use a female voice or a female-presenting profile because they believe it can make the conversation seem more approachable or trustworthy.
The person on the call may sound friendly and knowledgeable.
They may know the project's name, token symbol, latest announcement, migration plans, or recent problems being discussed by community members.
The caller may even spend time answering ordinary questions before introducing the malicious link.
The objective is often to make the victim comfortable enough to connect a wallet.
Once trust has been established, the caller may say that the wallet needs to be verified, migrated, synchronized, upgraded, or connected to a special portal.
The human interaction can make the request feel more legitimate than a random phishing message.
But the conversation is still part of the social-engineering process.
Not every phishing campaign relies on manually messaging people one by one.
Attackers may attempt to collect large lists of potential targets connected to particular crypto projects.
Public follower lists, usernames, group memberships, profile information, and publicly visible contact details can help criminals identify people who are interested in a specific token or community.
They may use scraping tools or automated collection methods to build lists of potential victims.
Once they have a large target list, they can send phishing messages in bulk.
Email is one possible channel.
A person who follows a particular crypto project might receive an email claiming:
The message is more convincing because it appears related to something the recipient actually follows.
Attackers may also try to make bulk phishing emails look professional by using branded templates, polished writing, realistic sender names, and legitimate-looking email infrastructure.
Some may attempt to use reputable bulk-email or marketing services because they want their messages to look more legitimate and reduce the chance that they are immediately treated as obvious spam.
The important point is not which service delivers the email.
It is that phishing can be highly targeted.
The recipient may receive a message about a real project they genuinely follow, which makes the fraud much easier to believe.
Once the victim clicks the link, the phishing site may closely imitate the real project's website.
The attacker may copy:
The domain name may also resemble the legitimate site.
A victim who is concentrating on the airdrop, migration, or account problem may not notice a small difference in the address.
The page then moves the scam into its next stage.
One approach is simple.
The website asks the victim to enter their seed phrase or private key.
The page may claim that the information is required to:
This is not a normal wallet connection.
A seed phrase can provide control over the accounts associated with many self-custody wallets.
If the victim manually enters those recovery words into the fraudulent website, the attacker may be able to restore the wallet somewhere else.
At that point, the attacker does not need the victim to remain connected to the phishing site.
They may already possess the recovery information needed to control the wallet.
Not every crypto phishing site asks for a seed phrase.
Some rely on wallet connections and malicious transaction requests.
The victim may click “Connect Wallet†and see what appears to be a normal Web3 connection.
Connecting by itself does not normally mean every asset can immediately be stolen.
The dangerous step may come immediately afterwards.
The website can ask the victim to sign a message, approve a token, authorize a smart contract, or confirm another transaction.
If the approval gives a malicious contract access to tokens, the attacker may be able to move assets within the limits of that permission.
This is one reason wallet prompts should not be treated as routine popups.
A person may believe they are simply claiming an airdrop while actually approving something very different.
Some malicious crypto sites are designed around wallet-draining infrastructure.
These operations attempt to identify assets available in a connected wallet and then persuade the user to authorize transactions that transfer valuable tokens or cryptocurrency.
From the victim's perspective, the site may appear to be processing a claim, migration, reward, or verification.
Behind the interface, the requested transaction may actually benefit the attacker.
It is important to distinguish this from the idea that merely opening a website automatically empties every wallet.
In most cases, some form of wallet interaction, approval, signature, credential compromise, or transaction authorization is still involved.
The scam succeeds because the victim believes they are authorizing one action while actually authorizing another.
Attackers may discover that a compromised wallet contains little or no cryptocurrency.
That does not necessarily mean they abandon the target.
If the attacker already has the seed phrase, private key, or a useful malicious approval, they may try to persuade the victim to place assets into that wallet later.
The scammer may say:
“Deposit some USDT to activate your account.â€
“Buy the token before completing the migration.â€
“You need a minimum balance to claim the reward.â€
“Transfer crypto into the wallet so the system can verify it.â€
“Fund the wallet before staking can begin.â€
The victim may believe they are completing a legitimate process.
If the attacker already has control of the wallet or has established malicious permissions, newly deposited assets can then be stolen.
This can make the scam particularly deceptive because the theft does not necessarily happen at the exact moment the original phishing link is opened.
The attacker may be willing to wait.
Not every fraudulent crypto operation begins by impersonating an existing project.
Some attackers create their own.
They may launch a real token, create Telegram and Discord communities, build an official-looking website, operate social media accounts, recruit promoters, and encourage people to join.
The token may genuinely exist on a blockchain.
People may genuinely trade it.
The community may have real members.
The operators themselves may even put money into the token or create early trading activity.
That activity can make the project appear more legitimate.
From the outside, it may look like a small but growing crypto community.
The fraud is not necessarily that the token does not exist.
The problem may be the intentions of the people controlling it.
A fraudulent project may need to look active before outsiders are willing to invest.
The people behind it may therefore create liquidity, buy their own token, generate early transactions, promote price increases, and make the market appear more established.
They may use social media to create excitement around the project.
Community members might see:
All of this can create the impression that the project is succeeding.
The operators may then encourage outside investors to buy more.
Their own early investment can become part of the deception.
Instead of proving that the project is trustworthy, it may simply be the cost of making the operation appear credible.
Once a fraudulent project has built a community, the attackers have something extremely valuable: a group of people who already trust the brand.
That community can later be targeted with additional schemes.
Members may receive messages about:
A fake migration link can now appear especially believable because it comes from a community the victim has been following for months.
The scammer does not need to impersonate someone else's project anymore.
They control the project themselves.
Once enough outside money has entered the project, the operators may extract value.
Depending on how the token and liquidity are structured, they may:
The token itself may continue to exist on-chain even after the people behind it are gone.
This is another reason the existence of a real token does not automatically make the project legitimate.
Blockchain existence proves that the token exists.
It does not prove that the people promoting it are honest.
Crypto scams often become convincing because they mix genuine elements with fraudulent intentions.
A real blockchain transaction may be involved.
A real token may exist.
Real people may be buying it.
A real Telegram group may contain thousands of members.
The project may have a working website.
The scammers may even spend real money developing and promoting it.
None of those facts guarantees that the operation is legitimate.
A fraud can contain many real components.
The deception may lie in why those components were created and what the operators ultimately intend to do with the community and the money entering it.
The popular image of phishing is simple:
A scammer sends a fake link, the victim clicks it, and money disappears.
Crypto phishing can be much more involved.
A campaign may begin with surveillance of a community.
The attacker identifies active members.
They study what problems people are discussing.
They clone an administrator.
They send a personalized message.
They make a phone call.
They build trust.
They provide a convincing website.
They persuade the victim to connect a wallet.
Then they ask for an approval, signature, seed phrase, or deposit.
Each step makes the next one easier.
The phishing page is only one part of the operation.
The real weapon is often the story surrounding it.
A completely random message saying “connect your wallet now†may be easy to ignore.
A message saying:
“We noticed you asked about yesterday's migration issue. Your old tokens have not been converted yet. Please use the migration portal before the deadline.â€
is much more dangerous if the project really is carrying out a migration.
The attacker has created context.
That context can come from:
The more the attacker knows, the less random the phishing attempt feels.
Crypto communities provide attackers with many different stories, but most wallet-focused phishing campaigns eventually move toward the same objective.
The attacker wants the victim to surrender control.
That may happen through:
The giveaway, migration, investment, support request, or airdrop is simply the explanation used to get there.
That is what makes crypto phishing so adaptable.
The attackers do not need one perfect scam.
They can watch what a community is doing, copy its language, impersonate its people, and build a fraudulent request around whatever members are most likely to believe.
This category teaches readers how phishing works, how to inspect suspicious messages, and what to do after clicking a suspicious link.
New articles for this category will appear below. If there are no articles yet, use this guide as the starting point.