Stealing access directly.
WHAT PHISHING TARGETS
Recovery phrases Wallet connections Exchange credentials
WHAT FAKE WALLET SITES DO
Reproduce a legitimate wallet's appearance, and capture the phrase entered.
HOW THEY ARE REACHED
Search advertisements Messages Similar domain names
WHAT TO DO
Reach wallets and exchanges only through saved bookmarks.
WHY NOT SEARCH
Advertisements above results have repeatedly been fraudulent.
WHAT FAKE SUPPORT IS
Someone contacting you claiming to help, after you post a problem publicly.
WHAT THEY ASK FOR
Your phrase, or for you to connect your wallet somewhere.
WHAT TO UNDERSTAND
Real support never contacts you first, and never asks for a phrase.
WHAT MALICIOUS APPROVALS DO
Obtain permission to move your tokens, exercised later.
HOW THEY ARE OBTAINED
A transaction or signature presented as something harmless.
WHAT TO DO
Read what you are signing, and use wallet simulation.
WHAT DRAINER SOFTWARE IS
Code on fraudulent sites that empties a connected wallet in one approval.
WHAT IT IS DISTRIBUTED THROUGH
Fake airdrops, fake mints, compromised interfaces.
WHAT TO DO ABOUT UNSOLICITED OPPORTUNITIES
Ignore them entirely.
WHAT TO DO IF YOU CONNECTED SOMEWHERE SUSPICIOUS
Revoke approvals immediately, and move assets.