Lookalike domains are common entry points
Phishing sites can copy a legitimate interface and use domains that differ by only a few characters. Verify the domain from a trusted saved entry point rather than relying on search ads or unsolicited messages. Treating lookalike domains are common entry points as its own decision point helps prevent rapid click-through mistakes across multiple accounts, networks or DApp steps.
Fake support asks for secrets
Anyone claiming to be support, an administrator or a technician who asks for a seed phrase, private key, verification code or remote access should be treated as suspicious. Legitimate support does not need those secrets to inspect public transaction data. The practical goal of fake support asks for secrets is to separate on-chain facts from interface presentation; if the two disagree, verify public blockchain state first.
Fake airdrops exploit urgency
Unknown tokens, NFTs, direct-message links or “limited-time claim” pages can be used to trigger malicious approvals. Receiving an asset on-chain does not make its sender trustworthy, and unknown rewards do not justify unexplained signatures. Because blockchain actions can create persistent or irreversible state, understanding fake airdrops exploit urgency should come before signing, approving or submitting.
Clipboard address replacement
Malware can replace an address during copy and paste. Recheck recognizable parts of the destination and its source before sending. A small test can reduce some operational risk for larger transfers, but it still must use the correct network. Reviewing clipboard address replacement never requires giving anyone a seed phrase or private key; public state can be checked with addresses, transaction hashes and contract information.
Remote control amplifies risk
Scammers often ask users to install remote-control software under the pretext of troubleshooting. Wallets, seed phrases and signing screens should not be handled while another person can control or view the device remotely. Before moving on, make sure the fields related to remote control amplifies risk match the intended task. If an important field cannot be explained, stop and verify the source.
Contain the account after an incident
After suspicious activity, stop signing and sending, disconnect questionable sessions, inspect approvals and recent transactions, and use a trusted device to decide whether assets should be moved to a new wallet. Do not disclose keys to a supposed “recovery team.” If the interface does not match expectations, record the network, address or transaction hash and troubleshoot contain the account after an incident one variable at a time.
Use this list as a final review before you submit a transaction, signature or approval related to this topic.
- Use trusted entry points for websites
- Reject anyone asking for seed phrases or private keys
- Do not rush to interact with unsolicited airdrops
- Recheck addresses after pasting
- Stop and review approvals after suspicious activity
Never share a seed phrase, private key or verification code. A wallet provider generally cannot reverse a confirmed on-chain transaction, and third-party DApps or smart contracts can carry independent risk.
