Skip to content
BeginnerTax and safety

Guarding against phishing

Author
CRYPTO PORT Editorial
Published
Updated
Reading time
6 min

In short

Phishing works by showing you a convincing screen and letting you do the damage yourself. Never type a seed phrase or private key into anything. Reaching official sites only through your own bookmarks prevents most of it.

Key points

  • Any screen asking for a seed phrase or private key is a scam, without exception
  • Fake sites buy search adverts — open official URLs from your own bookmarks
  • Do not reach anything holding your assets via a link in an email, DM or social post
  • For two-factor authentication, an authenticator app or security key beats SMS

Definition

Impersonating a real exchange, wallet or project to make the user themselves enter credentials or sign a transaction that hands over their assets.

Fake sites copy the logo, the colours and the wording. Spotting one by eye is not a workable defence. What you can rely on is the URL and how you arrived at it — and fake sites buying search adverts is a repeatedly reported pattern. Verify the real URL for each exchange and wallet once, bookmark it, and open it only that way from then on.

Websites are not the only entry point. Emails manufacturing urgency ('your account has been frozen', 'confirm this withdrawal'), social posts posing as a project's official account, airdrop win notifications — treat every link inside such messages as fake. If something really is wrong with your account, you can check by going in through your bookmark.

A growing variant never asks for a seed phrase at all: it asks only that you connect a wallet and sign. A 'free NFT' or 'claim your compensation' page produces a signature request, and the assets move the moment you approve it. The dangerous habit is approving without reading, so refuse any signature whose effect you cannot describe.

Turn on two-factor authentication everywhere. SMS is vulnerable to phone-number takeover (SIM swapping), so an authenticator app or a hardware security key is stronger. Using an email address reserved for crypto, itself protected by strong two-factor authentication, also helps stop one compromise from cascading.

Watch out for

  • · No legitimate service — this site included — will ever ask for your private key or seed phrase
  • · Anyone messaging you first while claiming to be 'support' is almost certainly a scammer
  • · If you realise you have been hit, moving what remains to a fresh wallet comes before anything else

Frequently asked questions

  • I connected to a fake site but did not sign anything. Am I safe?

    Connecting only reveals your address; it does not move funds. It does mean you may now receive targeted follow-up messages. Review your token approvals and revoke anything you do not recognise.

Read next

Crypto quizzes

Answer a few questions and get your result instantly.

Start