Candleread
Crypto and DeFi · Custody and Security

Phishing patterns crypto traders fall for

Name and pattern-recognize the most common phishing attacks against crypto users so they can be spotted in real time.

3 min read+25 XPLesson 67 of 79
Start reading

Lesson path

Crypto and DeFi

Custody and Security

Lesson 67 of 7985%
Lesson 67 of 79Crypto and DeFiCustody and Security

Today's tiny win: make one idea click.

Name and pattern-recognize the most common phishing attacks against crypto users so they can be spotted in real time.

Learn itSpot itPass the check

Pattern recognition beats vigilance

You can't be alert forever. Vigilance is a finite resource and attackers know it. The defense is pattern recognition — once you can name the common phishing setups, you can spot them quickly even when you're tired, distracted, or moving fast. Here are the five patterns crypto users get caught by, in roughly the order they come at you.

Two cards: a green card says open the exchange site yourself, a coral card says click the link in the email, teaching the defense against fake exchange emails.Do thisOpen the exchangesite yourselfNot thisClick the link inthe email
Wick saysNever click links in exchange emails; type the site yourself and check from there.

Pattern one: fake exchange email. An email arrives that looks like it's from your exchange. It might warn you about 'suspicious activity' or offer a withdrawal you didn't request. The link goes to a lookalike domain — one character off, or a different top-level domain. You log in. Now the attacker has your credentials. Defense: never click links in exchange emails. Open the exchange manually in your browser and check from there.

Pattern two: fake support in Telegram or Discord. You post a question in a project's chat. Within minutes someone with a near-identical username messages you privately, claiming to be support. They walk you toward 'verifying your wallet' on a fake site, or ask you to share your seed phrase to 'sync.' Real support never DMs first. Real support never asks for a seed phrase. If you remember nothing else, remember those two sentences.

Pattern three: the malicious approval. A site asks you to 'connect wallet' and then to sign a transaction. The transaction isn't a swap — it's an approval that gives the site's contract permission to move a specific token (or all tokens) out of your wallet later. You sign, you forget about it, weeks later the wallet drains. Defense: read the approval. Modern wallets show the contract address and the token; check that both match what you think you're doing. When in doubt, reject.

Wick thinks in a focused cloud that real support never DMs first or asks for a seed, teaching how to spot fake support in Telegram or Discord.Real support neverDMs first or asks formy seed.?
Wick saysReal support never messages you first and never asks for your seed phrase.

Pattern four: the fake giveaway. A celebrity or project account (often a compromised real one, or a near-duplicate) announces a 'double your crypto' event. Send X, get 2X back. Nobody ever sends crypto back. This pattern is older than crypto itself and it keeps working. If a giveaway requires you to send anything first, it isn't a giveaway. It's an opening.

Pattern five: the malicious browser extension. You install a 'wallet helper' or a 'gas tracker' or a 'portfolio sync.' The extension reads what you type, watches what you copy, and replaces wallet addresses on the fly so your transactions go to the attacker's address. Defense: minimal extensions on a browser you use for crypto. When in doubt, use a separate browser profile (or a separate browser entirely) just for crypto, with nothing installed in it.

Wick points at a chalkboard: send 0.1 ETH first, get 0.2 back, nobody sends it back, naming the fake giveaway pattern so you can spot it fast.Fake giveawaySend 0.1 ETH firstGet 0.2 back?Nobody sends it back
Wick saysIf a giveaway asks you to send crypto first, it isn't a giveaway, it's a trap.

Recap: five patterns — fake email, fake support DM, malicious approval, fake giveaway, malicious extension. Name them and you can spot them even when you're tired.

Knowledge check

Answer before moving on.

0 / 3 answered

1. You post a question in a project's Discord. Two minutes later, an account with the same username as a moderator DMs you offering to help. What's the right response?

2. A famous account you follow on social media announces: 'Send 0.1 ETH to this address and we'll send 0.2 ETH back as a community giveaway.' What's the right read?

3. What's the cleanest defense against malicious browser extensions on a wallet you actually use?

Lesson handoff

Pass the check before saving.

Use the knowledge check first. After you pass it, this card turns into the save-and-continue handoff.