
How to protect your crypto wallet from phishing
The habits that stop the single most common way crypto gets stolen
Most crypto isn't lost to brilliant hackers breaking cryptography. It's lost to ordinary people clicking a link, connecting a wallet to a convincing fake, and signing a transaction they didn't fully read. That's phishing, and it accounts for a huge share of stolen funds every year. The reassuring part: it relies on you making one specific mistake, and a handful of durable habits close nearly every door an attacker uses.
What phishing actually is in crypto
In email phishing, the goal is usually your password. In crypto, passwords barely matter — what an attacker wants is either your recovery phrase or your signature on a malicious transaction. Those are two different attacks, and it's worth understanding both.
The first is theft by disclosure: a fake site, app, or "support agent" convinces you to type your 12- or 24-word seed phrase somewhere. The moment you do, they can recreate your wallet on their own device and empty it. There is no undo. We cover exactly why in why you should never share your seed phrase.
The second is theft by approval: you never reveal your keys, but you connect your wallet to a malicious site and sign a transaction that grants the attacker permission to move your tokens — or drains them outright. This one is sneakier, because you did click approve. It just wasn't doing what you thought.

Never enter your seed phrase online — no exceptions
Your recovery phrase belongs on paper (or metal), offline, and nowhere else. No legitimate wallet, exchange, airdrop, migration tool, or support desk will ever ask you to type it into a website or chat. Not to "verify" your wallet, not to "sync" it, not to claim a reward. Every single request for those words is an attempt to rob you.
Internalise this as an absolute, not a guideline, because attackers are specifically engineering the moment you'll doubt it — a scary security warning, a time-limited airdrop, a friendly agent who "just needs to validate your wallet." The rule holds in every one of those cases. If the phrase is being requested, it's a scam.
Bookmark real sites and use only the bookmark
A large slice of phishing starts with you landing on the wrong URL. Attackers buy search ads and register lookalike domains that swap a character or bolt on a word: metamask-wallet.app, atexhub-support.com, a capital "I" standing in for a lowercase "l". Under pressure, these are almost impossible to spot in a hurry.
The fix is boringly effective. Bookmark the wallets, swaps, and explorers you use, and reach them only through those bookmarks. Stop clicking search-engine ads for crypto sites — the ad slot above the real result is a favourite phishing channel. When you do type or land on a URL, read it character by character, and be especially wary of anything with "support," "wallet," "claim," or "airdrop" grafted onto a brand name.
Slow down and actually read what you sign
The approval attack lives or dies on you clicking through a wallet pop-up without reading it. Before you sign anything, pause and answer three questions:
- What action is this? A transfer, a token approval, a contract interaction, or a plain message signature? Each has different consequences.
- What am I granting, and to whom? A request for unlimited spending on a token should make you deeply suspicious unless you know exactly why it's needed.
- Did I initiate this? If a site triggered a signing request you weren't expecting, that mismatch is the warning.
If anything is unexpected, unclear, or asks for more than the task requires, reject it. A legitimate action can always be retried; a malicious signature cannot be taken back.
Revoke the approvals you've forgotten
Every time you use a decentralised app, you may grant it permission to spend specific tokens from your wallet. Those approvals don't expire on their own. Over months, you accumulate a pile of standing permissions — and if any of those apps is later compromised, a forgotten approval becomes a live door into your funds.
Periodically review and revoke approvals you no longer use with a reputable approval-checker (reached via your bookmark or the wallet's own tools, never a link someone sent you). Think of it as closing accounts you stopped using. It's a five-minute habit that removes risk you're no longer even aware you're carrying.
Verify every address before you send

One of the quietest attacks doesn't need a fake website at all. Clipboard-hijacking malware watches for you to copy a crypto address and silently replaces it with the attacker's before you paste. You copy your own address; you paste theirs; you never notice.
The defence is a fixed habit: after pasting any receiving address, check the first four and last four characters against the source, and for anything sizeable, send a small test amount first and confirm it arrives before sending the rest. On-chain transfers are irreversible, so this ten-second check is the difference between a caught mistake and a permanent loss. Our guide to spotting crypto scams covers the broader set of red flags worth memorising.
Common mistakes that turn a near-miss into a loss
- Trusting urgency. "Act now or lose access" exists to stop you thinking. Real services are fine with you taking your time.
- Using one wallet for everything. Connecting your main holdings to every new or unaudited site maximises exposure. Keep a dedicated "clean" wallet with small balances for experiments.
- Approving to save a click. Signing blindly to skip reading a pop-up is exactly the behaviour attackers count on.
- Reusing a compromised wallet. If your seed phrase may have been exposed, funds in that wallet are never safe again — move them to a fresh wallet, don't just "be careful."
- Assuming hardware wallets are immune. A hardware wallet protects your keys, but you can still approve a malicious transaction on one. Read the device screen, not just the app.
Quick answers
Can someone steal my crypto just from my wallet address? No. Your public address is safe to share to receive funds. Theft requires your recovery phrase or your signature on a transaction — never the address alone.
Is a hardware wallet enough on its own? It's a major upgrade, because your keys never touch an internet-connected device. But it doesn't stop phishing by approval — you must still read and understand each transaction before confirming it on the device.
I think I connected to a phishing site but didn't sign anything. Am I safe? Connecting a wallet by itself doesn't move funds — signing does. If you signed nothing, you're likely fine, but review and revoke any approvals to that site and watch the wallet closely.
What if I already typed my seed phrase into a fake site? Treat those funds as compromised immediately. Create a brand-new wallet with a fresh phrase and move everything there now — a stolen phrase can be drained at any moment.
The takeaway
Phishing doesn't beat cryptography; it beats attention. Keep your recovery phrase offline and never type it anywhere, reach your sites only through bookmarks, read every transaction before you sign, revoke stale approvals, and verify addresses on every send. None of this is technical, and all of it compounds. When you use non-custodial tools like the swap page, your keys never leave your control in the first place — which means the habits above are most of what stands between your wallet and the people trying to empty it. Careful beats fast, every time.