Phishing links and fake crypto sites
How lookalike domains, fake claim pages, DMs and search adverts lead to theft, and the checks to do before you connect a wallet or sign anything.
Updated 15 Sept 2026 · Beginner · 4 min read
In short
- Most phishing does not hack your wallet. It gets you onto the wrong site, then asks you to connect, sign or type something that gives the attacker control.
- Lookalike domains, punycode names, fake airdrop pages, links in DMs and paid search adverts are the main ways victims arrive there.
- Check the address bar, the domain’s age and the exact wallet request before you connect. A padlock only means the connection is encrypted, not that the site is genuine. If you are unsure, leave and type the site address yourself.
What a fake site is trying to make you do
A fake site can only take money if it gets an action from you. Usually that action is one of four things: connecting your wallet so the site can target the right chain and tokens, signing a message that is really a permit or delegation, approving a token or NFT operator, or typing a seed phrase into a recovery form. The page may look almost perfect because the attacker copied the real site’s HTML, images and wording.
The story used to bring you there changes with fashion. In one cycle it is a “wallet sync” page, in another a “claim your airdrop” page, a governance vote, a refund, a staking migration or an urgent security notice. The goal is the same: get one signature or one secret before you slow down.
Lookalike domains and punycode
The safest sign on a website is the address bar, not the logo. Attackers register names that differ by one letter, swap l for I, add or remove a hyphen, or use a different ending such as .net instead of .com. Internationalised domain names add another trick: letters from another alphabet that look identical on screen. Browsers store these as punycode, the xn-- form you sometimes see when they decide a name is suspicious.
- Read the whole domain, from right to left: in app.example.com, the actual domain is example.com.
- Be wary of extra words such as claim-, app-, rewards- or support- added before a familiar brand.
- If a link opens a page that looks right but the URL is not the one you already know, leave.
- Use the link checker on a copied URL when you want a second opinion about lookalikes, hosting and age.
Where the bad links arrive from
- DMs and group chats. Fake moderators and “helpers” send links to forms, mirror sites and wallet recovery pages. Real support teams do not move you to a private chat to solve an account problem.
- Search adverts. Paid results can sit above the real site. The visible title may be correct while the actual destination is not.
- Compromised social accounts. A real project account can post a bad link after being taken over.
- Calendar invites, QR codes and PDFs. A QR code on a screen or in a slide deck hides the destination until you scan it.
Fake airdrops and “claim now” pages are especially effective because they promise free money and a short deadline. The page often asks only for a signature, which feels harmless. In practice it can be a token allowance, an NFT setApprovalForAll or an EIP-7702 authorisation. That is why a “claim” button belongs in the same mental category as a payment form.
Checks to do before you connect a wallet
- Type the known site address yourself, use a bookmark you created earlier, or follow the link from the project’s own documentation. Do not trust a DM, a reply, a comment or a search advert.
- Check whether the page asks for something that matches your task. A portfolio tracker needs a public address, not a wallet signature. A support page never needs your seed phraseThe 12 or 24 words (BIP 39) from which a wallet derives all its keys..
- Paste the link into the link checker and look for a very recent registration, suspicious hosting or a lookalike brand.
- If the site asks you to sign, stop and decode the request. Our signature decoder helps you tell a plain message from typed data and spot hidden approvals.
- If the page wants you to revoke or clean something, use a trusted route you already know, such as token approvals or a wallet’s own settings, not the button on the page.
If you already connected or signed
Treat the next ten minutes as damage control. If you only connected and signed nothing, close the site and disconnect it in your wallet or wallet settings. If you signed a message, an approval or a transaction, assume it may have granted some authority.
- Check live approvals with the token approvals tool. Revoke anything you did not mean to grant.
- Run the address through wallet health, which flags suspicious delegation and approval exposure on supported chains.
- Move remaining high-value assets to another wallet you control if you suspect a drainer is active.
- Keep the URL, signature request, transaction hashes and any chat messages. They help when you report it to the platform, wallet maker or exchange.