The short version

A familiar logo, verified-looking account, or polished app proves nothing about the destination or request.

01

Every trust signal can be copied

Consider what actually convinces you that a page is genuine: the logo, the layout, a padlock in the address bar, a verified badge, a high search result, a link shared in an official-looking community. Each of these can be reproduced or purchased by an attacker, usually cheaply.

Sponsored search results are a routine delivery method, because paying for the top slot on a wallet's own name is legal and effective. App store listings can be counterfeit. Browser extensions can imitate a wallet interface. QR codes are unreadable to humans by design and can point anywhere.

The one signal that is expensive to fake is the destination itself. So verification has to rest on the exact hostname and on how you arrived, not on how the page looks. Read the full domain from the final dot before the first slash: a subdomain like example.com.attacker.site belongs to attacker.site. On a phone, where the address bar truncates, tap it and read the whole thing.

02

The verification trap

The most important habit in this lesson is one sentence: never verify through the channel that contacted you. Asking the sender whether the link is real, calling a number provided in the message, or clicking “contact support” on the suspicious page all route the check back through the attacker.

Instead, open a separate path you control. A bookmark you saved earlier, the provider's app you installed deliberately, or a domain you type yourself after checking it in official documentation. Then compare the exact request against what that channel says.

Legitimate organizations do not need your recovery phrase, a one-time code, remote control of your screen, or a payment to secure your account. Urgency is a technique, not evidence—a genuine deadline survives the ten minutes it takes to verify, and an attacker needs you to believe it does not.

03

Protect the recovery paths

Attackers frequently do not target the account directly. They target the email address that can reset it, the phone number that receives codes, or the cloud backup that holds a screenshot of something sensitive.

So the email account tied to financial services deserves the strongest protection you have: a unique password and phishing-resistant multi-factor authentication rather than SMS where the option exists. SMS codes can be intercepted by an attacker who convinces a mobile operator to reassign your number, which is a well-established technique rather than an exotic one. Where a service offers a withdrawal allowlist, enable it, so that a compromised login cannot send funds to a new address without a delay you would notice.

04

Reduce the blast radius

Assume that at some point something will get through. Good security design limits what a single mistake can reach rather than assuming no mistake will occur.

In practice that means a low-value wallet for unfamiliar applications, kept separate from long-term holdings; unique passwords so one breach does not cascade; and a habit of disconnecting sites and reviewing approvals periodically rather than accumulating open permissions indefinitely.

  • Stop the moment you feel rushed—urgency is the attack.
  • Open a fresh channel you control before verifying anything.
  • Read the complete hostname, especially on mobile.
  • Install wallet software only from a source you verified independently.
  • Report the impersonation without engaging further.

Sources and review

Primary and official sources anchor consequential claims. The review date changes only after the lesson and its references are checked again.

Written by
Crypto Academy Editorial Desk
Reviewed by
Crypto Academy Research Desk
Next review
Dec 2, 2026
Finished this lesson?Stored only in this browser.