Spear Phishing
Spear phishing is phishing aimed at a specific person or organization, using researched personal details to make the deception convincing. Where ordinary phishing sends the same fake exchange email to millions of addresses, a spear phishing attack is written for one target, referencing their real colleagues, projects, holdings, or recent activity.
In crypto, high-value targets include exchange employees, DeFi protocol developers, DAO treasury signers, and individuals known to hold large amounts. A representative example: an attacker studies a protocol developer on LinkedIn and GitHub, then poses as a recruiter from a real firm and sends a job offer with a technical assessment attached; the file installs malware that later captures the developer's keys or session tokens. Several major bridge and exchange hacks began exactly this way, with a single employee opening a tailored document. Attackers also impersonate colleagues on messaging apps during time pressure, asking a treasury signer to quickly approve a transaction.
Because the message quality is high, spotting spear phishing by tone or spelling rarely works. Defenses focus on process: verifying unusual requests through a second, independent channel, separating the devices used for signing from those used for email and browsing, and treating unsolicited files and job offers with suspicion. A common misconception is that only executives are targeted; anyone whose access touches funds or code is worth a tailored attack.