What is Phishing?
Impersonation attacks — fake exchange emails, support agents, wallet pop-ups — designed to capture your login, 2FA codes or seed phrase. The most common way crypto is actually stolen.
Phishing is impersonation: fake exchange emails, cloned websites, "support agents" in your DMs, counterfeit wallet pop-ups — all engineered to capture your login, 2FA codes or seed phrase. It is by a wide margin how crypto actually gets stolen: not by breaking the cryptography, but by asking politely while dressed as someone you trust.
Crypto sharpens the stakes because transactions don't reverse — there's no bank fraud team to claw a transfer back. The defensive habits are unglamorous and near-total in effect: bookmark your exchange and never follow emailed links; treat urgency itself as the red flag (real platforms don't give you 10 minutes to "verify"); use app-based 2FA; and remember that no legitimate service — none — will ever ask for your seed phrase. The scam playbook catalogues the current costumes.
See it in practice
Related terms: Seed phrase · Two-factor authentication (2FA) · Rug pull · full glossary
FAQ
I clicked a phishing link — what now, in order?
If you entered exchange credentials: change the password and 2FA immediately, from a clean device, and contact the platform. If you typed a seed phrase anywhere: that wallet is compromised — move funds to a fresh wallet with a new phrase now, not tomorrow.
How do I verify a "support agent" is real?
You can't in an inbound message — real exchange support doesn't initiate DMs, and never asks for passwords, codes or phrases. Go to the platform through your own bookmark and open a ticket yourself; anything else is theatre.
General information only, not financial advice. Definitions are maintained in our fact database and reviewed with the daily rebuild.