What is Phishing?
Tricking you into revealing secrets or approving malicious actions by impersonating a trusted brand, person, or website.
Phishing is social manipulation dressed up as legitimacy. Attackers send emails, messages, ads, or build websites that imitate a wallet, exchange, or project, aiming to make you enter a seed phrase, log in on a fake site, or sign a malicious transaction. It is the entry point for a huge share of crypto theft.
This matters because phishing targets people, not code. No amount of blockchain security helps if you willingly type your secret into a convincing fake or approve a drainer because a message felt urgent and official.
Example: you get an email that looks like it is from your exchange warning of “suspicious activity” and linking to a login page; the page is a pixel-perfect fake that captures your password and two-factor code.
Safety note: slow down when a message creates urgency or fear. Type official URLs yourself rather than clicking links, verify sender details, never enter your seed phrase anywhere, and confirm requests through a second channel. Bookmark the real sites you use. Related terms include look-alike domain, wallet-drainer, impersonation scam, and social engineering.
Related terms
Keep learning: read the guides · scam alerts · free tools · full glossary.