Skip to content
Finvane

Phishing and Wallet Drainers: How to Spot Crypto Scams Early

How fake sites, fake airdrops, malicious approvals and address poisoning empty wallets, how to check every prompt, and what to do if you are hit.

SecurityOctober 9, 20263 min read
On this page
  1. Fake websites and fake airdrops
  2. How wallet drainers work
  3. Address poisoning and fake support
  4. Checking URLs and transaction prompts
  5. Revoking approvals and what to do if you are hit

Most crypto losses from scams do not involve clever hacking. They happen because someone is tricked into signing something or typing a secret into the wrong page. Learning the common tricks, and slowing down before every click, prevents most of them.

Fake websites and fake airdrops

Phishing means tricking you into handing over access by pretending to be someone you trust. In crypto, the classic version is a copy of a real exchange or wallet website at a slightly different address: an extra letter, a swapped character or a different ending. These copies often appear as sponsored search results or as links in replies on social media.

Fake airdrops are a close cousin. An airdrop is a free token distribution that some projects run. Scammers announce fake ones, or send worthless tokens to your wallet with a website name written in the token's label, hoping you visit the site to claim a reward. The claim button is the trap.

How wallet drainers work

A wallet drainer is a malicious website or script built to empty your wallet once you approve something. It rarely needs your seed phrase. Instead it asks you to sign a transaction or message that hands over control of your tokens.

  • Token approvals: on Ethereum and similar networks, apps ask permission to spend a token on your behalf. A malicious site asks for unlimited permission, then moves all of that token out of your wallet.
  • Signature requests: some signed messages, such as permit signatures, can grant spending rights without a separate approval transaction. They can look like a harmless login request.
  • Direct transfers: a prompt that simply sends your assets away, disguised as a mint, a claim or a verification step.

Once the approval or signature is given, the attacker can move funds within minutes, and blockchain transactions cannot be reversed.

Address poisoning and fake support

Address poisoning exploits the habit of copying addresses from your transaction history. The attacker creates an address whose first and last few characters match one you use often, then sends a tiny or zero-value transfer from it so it shows up in your history. If you later copy the lookalike instead of the real address, your funds go to the scammer. Check the full address, or use a saved address book.

Fake support is another common route. Scammers watch public forums and social media for people asking for help, then reply or message privately while posing as staff. Real support teams do not contact you first by direct message, and never ask for your seed phrase, passwords or screen sharing.

Checking URLs and transaction prompts

  • Bookmark the official sites you use and open them only from your bookmarks, not from ads, search results or messages.
  • Read the full domain name before connecting a wallet, and check the spelling letter by letter.
  • Read every wallet prompt. Ask what you are approving, which token, how much, and to which address or contract.
  • Be wary of unlimited approvals. Many wallets let you edit the amount down to only what you need.
  • Treat urgency as a warning sign. Countdowns, last-chance claims and threats to close your account are pressure tactics.
  • Use a separate wallet holding small amounts for trying new apps, and keep savings in a different wallet, ideally a hardware wallet.

Revoking approvals and what to do if you are hit

Token approvals stay active until you remove them. Block explorers for major networks, and some wallets, offer an approval checker where you can see which contracts may spend your tokens and revoke the ones you no longer use. Revoking is itself a transaction, so it costs a small network fee.

If you think you signed something malicious, act quickly. Move any remaining funds to a new wallet created with a fresh seed phrase on a clean device. Revoke approvals on the affected wallet, but do not send more money into it. If you typed your seed phrase anywhere, treat that whole wallet as permanently compromised. Report the scam site to your wallet provider and to the platform where you found it, and report the theft to your local police or fraud authority.

Stay alert afterwards. Recovery services that promise to get stolen crypto back for an upfront fee are very often a second scam aimed at the same victims.

For education only, not financial advice. Crypto assets are volatile and you can lose money.

Get one like this every morning

A 5-minute briefing in your inbox each weekday. Free, unsubscribe anytime.

Free. One email each weekday morning. Unsubscribe in one click.

Or follow the Telegram channel @pakaoqp