Glossary

Phishing

Phishing is the practice of impersonating a trusted party, such as an exchange, wallet provider, or well-known project, to trick you into revealing credentials or authorizing transactions that steal your funds. It is the single most common way cryptocurrency is stolen from individuals, because it attacks the person rather than the technology.

Crypto phishing takes several recognizable forms. A classic example is an email that appears to come from your exchange, warning of suspicious activity and linking to a near-perfect copy of the login page that captures your password and two-factor code. Wallet-focused variants include fake airdrop sites that ask you to connect your wallet and sign a malicious approval, sponsored search ads pointing to lookalike wallet downloads, and pop-ups or direct messages asking for your seed phrase to verify or sync your wallet. No legitimate service ever asks for a seed phrase, so that request alone identifies a scam.

Defenses are behavioral: type important URLs yourself or use bookmarks instead of clicking links, treat urgency as a red flag, verify unexpected messages through official channels, and read what a wallet asks you to sign before approving. A common misconception is that phishing only fools careless people; well-crafted campaigns have caught experienced users, which is why hardware wallets with on-device verification add a valuable last line of defense.