Security
Five phishing patterns worth recognising before you trade
Editorial desk · 1 min read ·
Fake support agents, address-poisoning, and signature requests that quietly drain a wallet — with the tells for each.
Almost every loss we read about starts with a message rather than a technical exploit. These five patterns cover the majority of them.
1. Support that contacts you first
No exchange or wallet team opens a direct message asking for a recovery phrase or a screen share. Treat any unsolicited support contact as fake by default.
2. Address poisoning
Attackers send a tiny transaction from an address that matches the first and last characters of one you use, hoping you copy it out of your history. Verify the middle of the address, not just the ends.
3. Blind signature requests
A site asks you to sign something your wallet cannot decode. If your wallet cannot describe what a signature does, do not approve it.
4. Urgency and deadlines
Migration deadlines, expiring airdrops and 'account suspension in 24 hours' all exist to stop you checking. Genuine deadlines survive a five-minute pause.
5. Search-ad impersonation
Paid results sometimes sit above the real site. Bookmark the wallet and exchange sites you use and open them from the bookmark.
⚠ RISK WARNING Cryptocurrency is a volatile, high-risk asset. You may lose your entire investment. Nothing here is financial advice.