Back to Glossary

Phishing Attack

Phishing Attack Definition: A phishing attack is a targeted deception in which an attacker impersonates a trusted party, such as an exchange, a wallet provider or a colleague, to make a victim reveal credentials or approve a transaction. In crypto, the attack usually ends in one of two moves: typing a seed phrase or password into a fake page, or signing a token approval that lets the attacker’s contract withdraw funds.

What Is a Phishing Attack?

Every phishing attack is a short play in three acts: a lure, a fake stage and a capture. The lure is a message that creates a reason to act now, such as a security alert, an airdrop, a margin warning or a job offer. The fake stage is a website, app or chat that looks like the real thing. The capture is the moment you hand over something valuable.

Attackers do not need to break any system for this to work. They borrow the trust you already place in a brand or a person. In July 2020, attackers phoned Twitter employees posing as internal IT staff, collected their login details and used an internal tool to post bitcoin scam messages from the accounts of Barack Obama, Elon Musk and Apple, collecting more than $100,000 before the posts came down.

That case shows the core pattern. A convincing story beats strong technology, because the attack targets the person who has the access, not the lock itself.

How Does a Phishing Attack Work?

Modern crypto phishing runs on drainer kits, ready-made packages that criminals rent out for a share of the takings. The kit clones a real project page, connects to your wallet and scans your balances. It then asks you to sign whichever request would move the most value, and the operator splits the proceeds with whoever brought you to the page.

Consider a hypothetical victim who holds 20,000 USDC. A reply under a real project’s post promises a limited airdrop and links to a near-identical domain. The site asks the victim to connect a wallet and “verify eligibility” by signing a message.

That message is a permit, an off-chain signature supported by many ERC-20 tokens. It grants a spender the right to move a set amount of the token without any further approval, and signing it costs no gas and shows no transfer, so it looks harmless. Minutes later the attacker’s smart contract submits the permit and pulls the full 20,000 USDC.

Nothing in that sequence required the victim’s seed phrase. The victim’s own valid signature did all the work, which is why reading what you sign matters more than guarding a password.

Types of Phishing Attacks

Credential phishing copies an exchange login page to capture your email, password and 2FA code, then logs in on the real site in real time. Seed phrase phishing uses fake wallet “sync” or “validation” pages that ask for your recovery words, which no legitimate service ever needs.

Approval phishing tricks you into signing token allowances or permits, as in the example above. Spear phishing targets one person with research behind it, such as a fake recruiter sending a trading desk employee a file that installs malware.

Search and ad phishing buys paid search results that sit above the real site for wallet or exchange names. Impersonation in chats sends direct messages from fake support staff in Telegram or Discord groups, usually right after you post a question in public.

Phishing Attack vs. Address Poisoning

Both rely on deception, but they fail at different moments. A phishing attack needs you to act on a fake page: type a secret or sign a request. Address poisoning needs no page at all. The attacker plants a look-alike address in your transaction history and waits for you to copy it by mistake.

The defences differ as well. Bookmarking official sites and refusing unexpected signatures stops most phishing. Checking the full destination address before each transfer stops poisoning.

Why Is a Phishing Attack Important for Traders?

Traders are exposed more often than most users because they connect wallets to new sites, chase airdrops and react to alerts under time pressure. Urgency is the attacker’s main tool. A message saying your account will be frozen in 30 minutes is designed to make you skip the checks you would normally run.

Technical defences cover part of the risk. App-based 2FA stops a leaked password from being enough on its own, and a hardware wallet shows the real transaction on its own screen. Hardware security keys go further, because they refuse to sign in on a domain that does not match the one they were registered to.

The limitation is that none of these tools can judge intent. A wallet will sign a malicious permit if you approve it, and a real-time proxy can relay a six-digit code before it expires. Keeping a separate wallet with small balances for new sites limits how much any single mistake can cost.

Key Takeaways

  • A phishing attack impersonates a trusted party to make you reveal credentials or approve a transaction, rather than breaking any system directly.
  • Every attack follows the same path: an urgent lure, a convincing fake page or chat, and a capture of secrets or signatures.
  • In crypto, signing a token approval or permit on a fake site can drain a wallet without the attacker ever learning your seed phrase.
  • No legitimate exchange, wallet or support agent will ask for a seed phrase, and an unexpected request for one is proof of an attack.
  • Hardware security keys, bookmarked sites and a separate low-balance wallet for new projects reduce the damage, but no tool can refuse a signature you approve yourself.
FAQ section

Can I get my crypto back after a phishing attack?

Rarely. A confirmed transaction cannot be reversed, so recovery depends on the stolen funds reaching an exchange or issuer that agrees to freeze them, and you should report the addresses to exchanges and the police quickly.

Does a hardware wallet protect against phishing?

It protects the private key but not your judgement. If you approve a malicious permit or transfer on the device, it signs exactly what you told it to.

How do I remove a token approval I signed on a phishing site?

Use a token approval checker from a block explorer or your wallet to find the spender and submit a revoke transaction that sets the allowance to zero. An off-chain permit that has not yet been used can often be cancelled the same way, but a permit the attacker already submitted cannot.

Is 2FA enough to stop phishing?

No. A real-time phishing proxy can capture a six-digit code and use it within seconds. Hardware security keys resist this because they check the website's real domain before signing in.

Private Key Security
Private Key Security Definition: Private key security is the...
Ransomware
Ransomware Definition: Ransomware is a type of malware that ...
Regulatory Sandbox
Regulatory Sandbox Definition: A regulatory sandbox is a fra...
Security Token Offering (STO)
Security Token Offering (STO) Definition: A security token o...

Live Chat

Contact our support team via live chat.

Help Center

Questions about our services?
Check out our Help Center.

Risk Warning:
Trading in leveraged products carries a high level of risk and may not be suitable for all investors.