A polished interface proves nothing. Trust the destination, the request, and your own verification process—not the page’s confidence.
Start somewhere the attacker does not control
The riskiest moment is often the first click. Sponsored search results, copied social accounts, Discord messages, and typo domains can all lead to convincing replicas. Instead of following the link in front of you, open a bookmark you created earlier or navigate from the project's independently verified documentation.
Check the whole hostname, not the logo or page title. On a long mobile URL, tap the address bar and read from the final dot before the slash. A subdomain such as example.com.attacker.site belongs to attacker.site, not example.com.
- Use a saved bookmark or a link from independently verified official documentation.
- Read the complete hostname and confirm the expected top-level domain.
- Treat search ads and urgent social posts as leads to investigate, not destinations to trust.
Know what “connect” can and cannot do
A basic wallet connection normally lets a site see the public address you choose. It should not require a recovery phrase. A later signature or approval can have very different consequences, so do not collapse every prompt into the harmless word “connect.”
Pause when a site asks for unlimited token spending, a message you cannot understand, or a transaction whose destination and value are hidden. A legitimate deadline can survive the time it takes to verify. An attacker needs you to feel that it cannot.
Use a two-minute exit protocol
If the page behaves differently from the documentation, close it. Do not test it with a small amount and do not ask the person who sent the link whether it is genuine. Open a fresh browser tab, find the official support channel independently, and compare the exact domain and requested action.
If you already signed something suspicious, move from diagnosis to containment: disconnect the site in your wallet, review token approvals, preserve transaction hashes and screenshots, and contact the wallet provider through a verified channel. Never pay a stranger who promises asset recovery.
Sources and review
We use primary sources where possible and review this page when referenced guidance or underlying systems materially change.
- Ethereum security and scam prevention
- FTC: What to know about cryptocurrency and scams
- CISA phishing guidance
- Written by
- Crypto Academy Editorial Desk
- Reviewed by
- Crypto Academy Research Desk
- Next review
- Dec 1, 2026
