Phishing patterns crypto traders fall for
Name and pattern-recognize the most common phishing attacks against crypto users so they can be spotted in real time.
Lesson path
Crypto and DeFi
Custody and Security
Pass the check before saving this lesson.
Pass the check to unlock nextOpen track mapChange starting pointToday's tiny win: make one idea click.
Name and pattern-recognize the most common phishing attacks against crypto users so they can be spotted in real time.
Pattern recognition beats vigilance
You can't be alert forever. Vigilance is a finite resource and attackers know it. The defense is pattern recognition — once you can name the common phishing setups, you can spot them quickly even when you're tired, distracted, or moving fast. Here are the five patterns crypto users get caught by, in roughly the order they come at you.
Pattern one: fake exchange email. An email arrives that looks like it's from your exchange. It might warn you about 'suspicious activity' or offer a withdrawal you didn't request. The link goes to a lookalike domain — one character off, or a different top-level domain. You log in. Now the attacker has your credentials. Defense: never click links in exchange emails. Open the exchange manually in your browser and check from there.
Pattern two: fake support in Telegram or Discord. You post a question in a project's chat. Within minutes someone with a near-identical username messages you privately, claiming to be support. They walk you toward 'verifying your wallet' on a fake site, or ask you to share your seed phrase to 'sync.' Real support never DMs first. Real support never asks for a seed phrase. If you remember nothing else, remember those two sentences.
Pattern three: the malicious approval. A site asks you to 'connect wallet' and then to sign a transaction. The transaction isn't a swap — it's an approval that gives the site's contract permission to move a specific token (or all tokens) out of your wallet later. You sign, you forget about it, weeks later the wallet drains. Defense: read the approval. Modern wallets show the contract address and the token; check that both match what you think you're doing. When in doubt, reject.
Pattern four: the fake giveaway. A celebrity or project account (often a compromised real one, or a near-duplicate) announces a 'double your crypto' event. Send X, get 2X back. Nobody ever sends crypto back. This pattern is older than crypto itself and it keeps working. If a giveaway requires you to send anything first, it isn't a giveaway. It's an opening.
Pattern five: the malicious browser extension. You install a 'wallet helper' or a 'gas tracker' or a 'portfolio sync.' The extension reads what you type, watches what you copy, and replaces wallet addresses on the fly so your transactions go to the attacker's address. Defense: minimal extensions on a browser you use for crypto. When in doubt, use a separate browser profile (or a separate browser entirely) just for crypto, with nothing installed in it.
Recap: five patterns — fake email, fake support DM, malicious approval, fake giveaway, malicious extension. Name them and you can spot them even when you're tired.
Knowledge check
Answer before moving on.
1. You post a question in a project's Discord. Two minutes later, an account with the same username as a moderator DMs you offering to help. What's the right response?
2. A famous account you follow on social media announces: 'Send 0.1 ETH to this address and we'll send 0.2 ETH back as a community giveaway.' What's the right read?
3. What's the cleanest defense against malicious browser extensions on a wallet you actually use?
Pass the check before saving.
Use the knowledge check first. After you pass it, this card turns into the save-and-continue handoff.