Start with the source, not the message
Do not trust a link because it arrived in a familiar-looking email, social post, group, or direct message. Open the service from a saved bookmark, type the address yourself, or use its official app. Search results and sponsored listings can also lead to impersonators.
Common red flags
- Urgency: “act now,” “your wallet will be closed,” or “claim before expiry.”
- Support that starts in a DM, asks to screen-share, or pushes a remote-access tool.
- Unexpected token drops, giveaways, airdrops, or recovery offers.
- A domain with a small spelling change, strange subdomain, or unfamiliar approval prompt.
- Any request to reveal a seed phrase, private key, or recovery code.
Use a connection checklist
- Confirm the exact site address through an official source.
- Read the wallet prompt—not just the page headline.
- Do not approve unlimited permissions you do not understand.
- Cancel if the request differs from what you intended to do.
If you already clicked
Close the suspicious page and stop signing or sending. From a trusted device, review your account and wallet activity using known-good paths. Do not accept a recovery offer from anyone who contacts you first.
