Phishing
Share post
In Brief
Phishing is a scam in which attackers impersonate trusted entities — through fake websites, emails, or messages — to trick you into revealing sensitive information like your recovery phrase or private keys, or into signing malicious transactions.

What Is Phishing?
Phishing is a social-engineering attack in which scammers impersonate a trusted person, company, or service to trick you into handing over sensitive information or access. In crypto, phishing typically aims to steal your recovery phrase, private keys, or passwords — or to trick you into signing a transaction that drains your wallet.
Because crypto transactions are irreversible and self-custody means there's no bank to reverse fraud, phishing is one of the most damaging threats to crypto users.
How Does Crypto Phishing Work?
An attacker sends a message or creates a site impersonating a wallet, exchange, or project.
It creates urgency or temptation ("verify your wallet," "claim your airdrop").
You're directed to a fake site or pop-up that looks legitimate.
You enter your recovery phrase, or connect your wallet and sign a malicious request.
The attacker uses the stolen information or approval to drain your funds.
Common Phishing Tactics
| Tactic | Example |
|---|---|
| Fake websites | Lookalike domains of real wallets/exchanges |
| Fake support | "Support agents" in DMs asking for your phrase |
| Malicious airdrops | Tokens linking to wallet-draining sites |
| Fake apps | Counterfeit wallet apps in app stores |
| Approval phishing | Tricking you into signing a token approval |
How to Protect Yourself
Never share your recovery phrase or private keys — no legitimate service will ever ask.
Check URLs carefully — bookmark official sites; watch for misspellings.
Don't click suspicious links in emails, DMs, or comments.
Verify before signing — read what a transaction actually does.
Download apps only from official sources and verify the publisher.
The Golden Rule
If anyone — including someone claiming to be "support" — asks for your recovery phrase, it's a scam, every time. Your recovery phrase should never be typed into a website or shared with a person. Genuine self-custody means only you ever see it.
Phishing and Trust Wallet
Trust Wallet will never ask for your secret recovery phrase, and no legitimate Trust Wallet support channel ever will. As a non-custodial wallet, only you hold your keys — so protecting them from phishing is the most important thing you can do. Always download Trust Wallet from official sources, double-check website URLs, and carefully review any transaction before signing it.