Evergreen security guide

How to Spot a Crypto Scam Before You Connect Your Wallet

Most crypto scams win by creating urgency. A short pause and an independent check are stronger defenses than a perfect instinct.

Start with the source, not the message

Do not trust a link because it arrived in a familiar-looking email, social post, group, or direct message. Open the service from a saved bookmark, type the address yourself, or use its official app. Search results and sponsored listings can also lead to impersonators.

Common red flags

  • Urgency: “act now,” “your wallet will be closed,” or “claim before expiry.”
  • Support that starts in a DM, asks to screen-share, or pushes a remote-access tool.
  • Unexpected token drops, giveaways, airdrops, or recovery offers.
  • A domain with a small spelling change, strange subdomain, or unfamiliar approval prompt.
  • Any request to reveal a seed phrase, private key, or recovery code.

Use a connection checklist

  1. Confirm the exact site address through an official source.
  2. Read the wallet prompt—not just the page headline.
  3. Do not approve unlimited permissions you do not understand.
  4. Cancel if the request differs from what you intended to do.

If you already clicked

Close the suspicious page and stop signing or sending. From a trusted device, review your account and wallet activity using known-good paths. Do not accept a recovery offer from anyone who contacts you first.

Sources, updates & corrections

This evergreen guide is based on durable safety practices and is reviewed when wallet or provider guidance changes. For account-specific action, use the verified support and status channels of the wallet, exchange, or service involved.

Primary references

Correction policy: Send factual corrections through the site contact path. We will label substantive updates with a revised date and explain the change.