Common scam patterns
Common scam patterns is a distinct part of understanding Phishing & Scams. Scams often create urgency, promise rewards or impersonate support to convince users to reveal recovery material, install remote-access software or sign malicious requests. Any request for a private key, seed phrase or verification code should be rejected. Self-custody means the user controls both access and safekeeping. Seed phrases and private keys should not be entered into web forms, chats or services claiming they need to “verify” a wallet. Official staff will not ask for recovery phrases, private keys or verification codes.
In practice, do not rely on interface color, icons or labels alone. Cross-check verifiable details such as the active network, public address, transaction hash, contract address and approval target. Before any action that changes onchain state, read the request and confirm the amount, network and destination.
If something looks wrong, stop signing or resubmitting transactions until the situation is understood. Keep non-sensitive details such as the transaction hash, network name and public address for troubleshooting, but never share a seed phrase, private key or verification code. Onchain transactions are generally not reversible by a wallet provider, so preventive checks matter more than recovery promises.
Domain checks
Domain checks is a distinct part of understanding Phishing & Scams. Scams often create urgency, promise rewards or impersonate support to convince users to reveal recovery material, install remote-access software or sign malicious requests. Any request for a private key, seed phrase or verification code should be rejected. Self-custody means the user controls both access and safekeeping. Seed phrases and private keys should not be entered into web forms, chats or services claiming they need to “verify” a wallet. Official staff will not ask for recovery phrases, private keys or verification codes.
In practice, do not rely on interface color, icons or labels alone. Cross-check verifiable details such as the active network, public address, transaction hash, contract address and approval target. Before any action that changes onchain state, read the request and confirm the amount, network and destination.
If something looks wrong, stop signing or resubmitting transactions until the situation is understood. Keep non-sensitive details such as the transaction hash, network name and public address for troubleshooting, but never share a seed phrase, private key or verification code. Onchain transactions are generally not reversible by a wallet provider, so preventive checks matter more than recovery promises.
- Confirm the active network before sending or approving.
- Compare the full destination or contract details.
- Keep recovery material offline and private.
Fake support & airdrops
Fake support & airdrops is a distinct part of understanding Phishing & Scams. Scams often create urgency, promise rewards or impersonate support to convince users to reveal recovery material, install remote-access software or sign malicious requests. Any request for a private key, seed phrase or verification code should be rejected. Self-custody means the user controls both access and safekeeping. Seed phrases and private keys should not be entered into web forms, chats or services claiming they need to “verify” a wallet. Official staff will not ask for recovery phrases, private keys or verification codes.
In practice, do not rely on interface color, icons or labels alone. Cross-check verifiable details such as the active network, public address, transaction hash, contract address and approval target. Before any action that changes onchain state, read the request and confirm the amount, network and destination.
If something looks wrong, stop signing or resubmitting transactions until the situation is understood. Keep non-sensitive details such as the transaction hash, network name and public address for troubleshooting, but never share a seed phrase, private key or verification code. Onchain transactions are generally not reversible by a wallet provider, so preventive checks matter more than recovery promises.
What to do next
What to do next is a distinct part of understanding Phishing & Scams. Scams often create urgency, promise rewards or impersonate support to convince users to reveal recovery material, install remote-access software or sign malicious requests. Any request for a private key, seed phrase or verification code should be rejected. Self-custody means the user controls both access and safekeeping. Seed phrases and private keys should not be entered into web forms, chats or services claiming they need to “verify” a wallet. Official staff will not ask for recovery phrases, private keys or verification codes.
In practice, do not rely on interface color, icons or labels alone. Cross-check verifiable details such as the active network, public address, transaction hash, contract address and approval target. Before any action that changes onchain state, read the request and confirm the amount, network and destination.
If something looks wrong, stop signing or resubmitting transactions until the situation is understood. Keep non-sensitive details such as the transaction hash, network name and public address for troubleshooting, but never share a seed phrase, private key or verification code. Onchain transactions are generally not reversible by a wallet provider, so preventive checks matter more than recovery promises.
Security and risk reminder
Blockchain transactions are generally irreversible by a wallet provider. Third-party DApps and smart contracts can contain technical or business risks. Review every signature and approval independently, and consider revoking permissions you no longer use.
