warm background

What is phishing in crypto? How it works and how to spot it

What is phishing in crypto? How it works and how to spot it
AdminAdmin
發佈於 7 分鐘閱讀

Phishing in crypto is any attack that tricks you into handing over your keys, signing a malicious transaction, or sending funds to an attacker's address by impersonating something you trust. Of individual wallet losses, it is the largest single cause. In 2025, Scam Sniffer recorded $83.85 million stolen across 106,106 wallets, down 83% from $494 million in 2024, with the average victim losing $790.

Why phishing works in crypto specifically

Irreversibility.

In traditional finance, a phished bank login triggers fraud teams, chargebacks, and reversals. In crypto, a signed transaction is final the moment it confirms. There is no fraud department, no reversal, and no authority who can undo it. Knowing this, attackers invest far more effort per victim.

Second, the thing being stolen is a secret rather than an account. Whoever obtains a seed phrase or a spending approval has the funds, without needing to bypass anything else.

The main crypto phishing attack types

TypeHow it worksWhat the victim hands over
Seed phrase phishingFake wallet site or support impersonator requests your recovery wordsThe entire wallet
Signature phishingA transaction disguised as a login, claim, or mint grants a contract permission to spend your tokensA spending approval
Address poisoningA look-alike address is seeded into your transaction history so you copy it by mistakeA single payment to the wrong place
Fake airdropsUnsolicited tokens with a website in the name lure you to a malicious claim pageWhatever the claim page requests
ImpersonationFake support, fake executives, fake project accounts on social mediaKeys, approvals, or direct transfers
Physical lettersOfficial-looking mail impersonating hardware wallet makers with QR codes to fake setup pagesThe seed phrase

Signature phishing, the one that catches experienced users

Here is the mechanism that drains people who know never to share a seed phrase.

Many token standards allow a contract to spend your tokens if you have granted it approval. Presenting a transaction as something innocuous, a login, a claim, a mint, attackers build sites where what it actually does is grant their contract unlimited permission to move your assets.

You sign. Nothing happens immediately. Days or weeks later, your wallet empties.

Permit-based signatures accounted for 38% of losses among incidents exceeding $1 million in 2025, according to Scam Sniffer, and the largest single theft of the year, $6.5 million in September, used one. After Ethereum's Pectra upgrade in May 2025, attackers added a new variant exploiting the EIP-7702 account abstraction feature.

Address poisoning, the one that catches everyone

An attacker sends a tiny transaction to your wallet from an address engineered to look like one you regularly use, matching the first and last several characters.

Later, you copy an address from your history to send funds. You copy theirs.

Because victims are typically moving large amounts, losses run large. In December 2025 one person lost $50 million this way, and in January 2026 another lost $12.25 million. Published in January 2026, a Carnegie Mellon study identified more than 270 million poisoning attempts targeting over 17 million wallets between 2022 and 2024.

Warning signs of crypto phishing

  • Anyone, anywhere, asking for your seed phrase. No legitimate service needs it.
  • Urgency: a deadline, a security alert, a limited-time claim.
  • A transaction requesting unlimited spending approval when you expected to do something else.
  • Support that contacts you first, especially through direct message.
  • A website reached through a link in a message rather than one you typed.
  • An unexpected token in your wallet with a URL embedded in its name.
  • A hardware wallet letter or email asking you to complete a "mandatory update."
  • An address you are about to send to that matches your history only at the beginning and end.

How to protect yourself from crypto phishing

  • Never type a seed phrase into any website or app, for any reason. This rule has no exceptions.
  • Read what a transaction actually does before signing. Wallets increasingly display this in plain language.
  • Verify the full address, not the first and last characters, before every send.
  • Send a small test amount before any large transfer.
  • Reach sites through bookmarks or typed URLs, never through links in messages.
  • Revoke old token approvals periodically using a revocation tool.
  • Treat unsolicited contact as hostile until proven otherwise.
  • Use a hardware wallet for long-term holdings, and verify addresses on its screen.

What to do if you have been phished

Speed matters more than anything else.

If you exposed a seed phrase, move everything to a new wallet immediately, before the attacker does. If you signed a malicious approval, revoke it now using a revocation tool. If you sent to a poisoned address, the funds are almost certainly unrecoverable, and the priority is confirming no other approvals or exposures exist.

To the platform involved and to law enforcement, report it. Rare as recovery is, documentation still matters for tax and insurance purposes.

Security you can verify on mb.io

Phishing exploits the gap between what a transaction looks like and what it does. Regulated custody adds controls at that gap.

mb.io is a regulated crypto spot exchange backed by MultiBank Group, a financial institution founded in 2005 that serves more than 2 million clients across 100+ countries.

  • Institutional-grade MPC custody powered by Fireblocks, with segregated client funds
  • 10/10 security score from Hacken, an independent blockchain security auditor
  • Regulated by VARA in the UAE and AUSTRAC in Australia
  • Withdrawal controls that let you verify a destination before funds move
  • Buy, sell, and swap in three steps, from sign-up to purchase
  • 24/7 multilingual client support

Open your account and start trading on mb.io.

Frequently asked questions

What is phishing in crypto?

Any attack that tricks you into handing over keys, signing a malicious transaction, or sending funds to an attacker by impersonating something you trust. It caused $83.85 million in losses across 106,106 wallets in 2025.

How much is lost to crypto phishing?

Scam Sniffer recorded $83.85 million in 2025, down 83% from $494 million in 2024. The average loss per victim was $790, and the largest single theft was $6.5 million.

What is signature phishing?

A transaction disguised as a login or claim that actually grants a contract permission to spend your tokens. Nothing happens immediately, then the wallet empties later. Permit-based versions accounted for 38% of large losses in 2025.

What is address poisoning?

An attacker seeds your transaction history with a look-alike address matching yours at the start and end. You copy it by mistake later. One victim lost $50 million this way in December 2025.

Can I recover funds lost to phishing?

Rarely. Transactions are irreversible. If you exposed a seed phrase, move remaining funds immediately. If you signed an approval, revoke it. Report the incident regardless, for documentation.

Does a hardware wallet prevent phishing?

A hardware wallet protects against malware, not against you entering the seed phrase into a fake site or approving a malicious transaction. Scammers mailed letters impersonating hardware wallet makers in early 2026 for exactly this reason.

Why did phishing losses fall in 2025?

Improved wallet warnings, major drainer operations shutting down, and lower on-chain activity all contributed. Losses track market cycles closely, rising during rallies and falling in quiet periods.

What is a wallet drainer?

Malicious software sold to scammers that automates emptying a wallet once a victim signs an approval or exposes a key. Drainer operators take a percentage of what is stolen.

RELATED POSTS

常見問題

常見問題

My Account
What is mb.io?mb.io is a secure, regulated crypto exchange designed to make cryptocurrency trading simple, fast, and stress-free. Whether you're buying your first Bitcoin or managing a diversified portfolio, mb.io gives you the tools you need without the complexity.Built on institutional-grade security and backed by MultiBank Group, mb.io offers spot trading with competitive fees, MPC-powered custody, and a clean interface that adapts to your experience level. Trade with confidence knowing your assets are protected by the same security standards trusted by major financial institutions.How long does account verification take?Most verifications are completed within a few minutes.Once you submit your documents, our system reviews them automatically. If everything looks good, you'll be verified and ready to trade almost immediately.In some cases, we may need to review your documents manually. This can add a bit of time, but it's usually still done the same day.Why is my account verification pending?If your verification is taking longer than expected, here are a few common reasons: Document quality issues: Blurry photos, missing corners, or glare can slow things down.Mismatched information: The details on your documents need to match what you entered during signup.High volume: During busy periods, manual reviews can take a bit longer. If your verification has been pending for more than an hour, contact our support team. They'll check what's happening and help you get verified quickly. They're available 24/7 via live chat or email.
Adding Funds
Withdrawing funds
Features
Regulations
Client Support
Account Security
Deposits & Withdrawals
查看更多

還需要其他幫助?