GLOSSARY · CYBERSECURITY

Phishing

Phishing is a type of fraud where attackers create fake websites, emails or messages that impersonate legitimate services. The goal is to trick victims into entering their seed phrase, private key or account credentials. In crypto, phishing is one of the leading causes of fund loss — victims lost over $494 million to phishing attacks in 2024 alone.

How Crypto Phishing Works

Crypto phishing differs fundamentally from traditional banking phishing. There is no need to hack a server or intercept SMS codes. Convincing the user to voluntarily enter a seed phrase — or sign a malicious transaction — gives the attacker irreversible control over the wallet. No two-factor authentication, no chargeback, no undo.

This is what makes crypto phishing so effective and so devastating: blockchain transactions are final. A bank can reverse an unauthorized transfer; a confirmed blockchain transaction cannot be undone. The attacker moves funds in seconds once they have the key material.

The Main Types of Crypto Phishing

Fake websites — the most common method. Attackers register domains that are visually identical to MetaMask, Ledger, or Binance. The difference may be a single character, a digit substituted for a letter (0 instead of o), or a different TLD (.app instead of .io). The site asks you to enter your seed phrase "for verification" or "to restore access."

Google Ads phishing. Attackers purchase search ads for queries like "MetaMask download", "Ledger Live", or "Binance login." The ad link looks legitimate but leads to a spoofed site. In 2024, this became one of the most widespread attack vectors, catching victims who searched for wallet software.

Email phishing. A message apparently from an exchange warns of "suspicious activity" and asks you to verify your account via a link. The link leads to a fake login page. The tell: always check the sender's exact email address and the URL of the destination page — not the display text of the link, but the actual URL.

Social Phishing and Fake Support

Attackers create Telegram groups and Discord servers impersonating official support for MetaMask, Binance, or Ledger. A victim posting about a problem is contacted by a "support agent" who offers help in exchange for a seed phrase or remote desktop access.

Romance scams — a longer game: sustained trust-building through dating apps or social networks, followed by a proposal to invest in a "guaranteed" crypto opportunity or to transfer funds through the attacker's "platform." The FBI reported that Americans lost over $5.6 billion to crypto fraud in 2023, with romance scams accounting for a significant share.

Technical Phishing Attacks

Address Poisoning — the attacker sends a tiny transaction from an address whose first and last characters match yours (or match a frequent recipient in your history). The victim copies the "familiar" address from their transaction history and sends a large sum to the attacker instead.

Clipboard Hijacking — malware or a malicious extension monitors the clipboard in real time and replaces any crypto address you copy with the attacker's address. You copied the right address; what appears in the input field is the attacker's. Defence: always visually verify the first and last several characters after pasting.

Malicious transaction signatures. The attacker leads the victim to a DeFi site and asks them to sign a transaction with an innocent-sounding description. In reality, it is an approve transaction granting a smart contract unlimited permission to transfer all tokens from the address. Tools like Revoke.cash allow you to revoke such approvals.

How to Recognise Phishing

Three hallmarks of phishing: urgency ("your account will be locked in 24 hours"), a request for sensitive data (seed phrase, private key), and URL mismatch. Legitimate services never ask for a seed phrase and never create artificial time pressure.

Always check the URL in the browser address bar — not in the email, not in a banner, but in the actual address bar after the page loads. For critical services, use bookmarks: MetaMask, Ledger, Binance — and always navigate through them.

What to Do If You Fall Victim to Phishing

If you entered your seed phrase: immediately create a new wallet on a different device and transfer all funds. Do not use the compromised device until it has been fully scanned. If funds are already gone, record the outgoing TxIDs and contact KarCrypto within hours.

If you signed a suspicious transaction: go to Revoke.cash or Etherscan Token Approvals and revoke all unknown token permissions from your address. This blocks further withdrawals via the already-granted approval, even if the attacker still holds the permission key.

Frequently Asked Questions

How do I tell a real MetaMask site from a fake one?

Always check the URL in your browser address bar: metamask.io (no hyphens, digits, or extra words). Use bookmarks for important sites and never click links from emails or messages.

What should I do if I entered my seed phrase on a suspicious site?

Immediately create a new wallet on a clean device and transfer all funds. If funds are already stolen, record the TxID and contact KarCrypto within the first hours.

Can antivirus software protect against crypto phishing?

Partially. Antivirus blocks known phishing domains, but new sites often are not yet in databases. More reliable: manually check URLs and use a hardware wallet.

What is Address Poisoning?

An attack where the attacker sends a transaction from an address whose first and last characters match yours. The victim copies the "familiar" address from their history and sends funds to the attacker. Always verify the full address.

How do I revoke suspicious token approvals?

Visit Revoke.cash, connect your wallet and revoke any unknown approvals. You can also use Etherscan Token Approvals for Ethereum. Regular approval audits are an important DeFi security practice.

Related Terms

Useful Resources