Phishing
In simple terms
Phishing is when a fake message or website pretends to be a service you already use, so that you enter your password or seed phrase and hand it straight to an attacker.
Definition
Tricking someone into surrendering credentials or a seed phrase by impersonating something they trust.
In depth
Crypto phishing combines classic credential capture with signature-level attacks specific to smart contract wallets. Delivery is typically a lookalike or homograph domain promoted through paid search, a direct message, or a compromised project announcement channel. Beyond seed-phrase capture, wallet drainers solicit an approval or an off-chain signature — a token allowance, or a permit — that grants transfer rights the attacker exercises later, so the theft need not coincide with the interaction. Granted allowances persist until explicitly revoked.
How does Phishing work?
An attacker builds something resembling a service you already use — a wallet, an exchange, an airdrop page — and routes you to it through a sponsored search result, a direct message, or a hijacked announcement channel. One of two things is then asked. Either you enter a seed phrase or password into the page, handing over the account outright. Or you approve a transaction that looks routine but grants permission to move tokens out of your wallet whenever the attacker chooses, which is why the theft sometimes arrives days later.
An example
Someone searches for their wallet's website and clicks the first result, which is a paid advertisement for a domain one character different from the real one. The page invites them to restore their wallet by entering their twelve words. The funds are gone within seconds, because those words are the wallet, and anyone holding them can rebuild it on their own device.
Figures are illustrative only.
What beginners get wrong
- Arriving at a site through a search advertisement rather than a bookmark is how most of these begin. Bookmark the real address once and use only that.
- A signature request is not automatically harmless. Approving one can grant open-ended permission to move your tokens, so read what is being requested rather than the button label.
- Approvals persist until revoked. A wallet compromised this way stays drainable long after you stop visiting the site.
Related terms
Educational only — not financial advice.
