Illustration of an envelope with a hook through it, representing a phishing message aimed at crypto holders

Most cryptocurrency theft does not involve a sophisticated hack of a blockchain or an exchange. It involves a person being convinced, for a few seconds, to click a link, type a phrase, or approve a transaction they did not fully understand. That is phishing, and industry trackers have consistently found it to be the leading cause of individual crypto losses year after year, even as the specific tricks evolve.

Blockchain security firm Scam Sniffer reported that wallet drainer phishing caused roughly 84 million dollars in losses across more than 106,000 wallets in 2025, down sharply from the 494 million dollars lost across over 332,000 wallets the year before. The drop in total losses is encouraging, but the number of separate incidents remaining high tells a more important story: the tools that power phishing attacks are now cheap, automated, and widely available, so attackers have shifted from occasional large scores toward higher volume campaigns against ordinary retail holders. The average loss per victim in 2025 was around 790 dollars, a figure low enough that many victims do not bother reporting it, which likely means the real numbers are higher still.

What phishing actually means in a crypto context

In traditional banking, phishing usually means tricking someone into typing a password into a fake login page. Crypto phishing borrows that same idea but has more ways to execute it, because a crypto wallet can be compromised through a password, a seed phrase, a private key, or a single malicious signature. Understanding which of these an attacker is after helps explain why the messages look the way they do.

Credential and seed phrase phishing

The oldest form simply asks for information. A fake exchange login page, a cloned wallet app, or a support form that asks you to type your recovery phrase to verify your identity are all trying to get you to hand over the master key to your funds directly. For a full breakdown of how this specific mechanism works, see our guide on seed phrase theft.

Malicious approval phishing

The more modern and now more common technique does not ask for your seed phrase at all. Instead, a fake airdrop claim page, NFT mint, or token swap tool asks you to connect your wallet and approve a transaction. Buried inside that transaction is a smart contract permission that gives the attacker the right to move tokens out of your wallet whenever they choose, sometimes immediately, sometimes days or weeks later when you have forgotten you ever visited the site. Because you technically signed the approval yourself, this is harder to reverse and harder to prosecute than outright theft of a password. Our guide on malicious token approvals covers this mechanism in more detail.

Key Point

A phishing attack does not always need your seed phrase. A single approved transaction on a fake site can hand an attacker standing permission to drain your wallet later.

A phishing attack from start to finish

It helps to walk through a realistic example rather than treating phishing as an abstract category, because the individual steps are each unremarkable on their own. It is only the sequence that adds up to a theft.

Step one: an alert that feels routine

The target receives an email that looks, at a glance, exactly like the security notifications their real exchange sends regularly. The subject line references a new device login from an unfamiliar location, the sender name matches the exchange, and the body includes the exchange's real logo and footer text copied directly from a genuine message. A button reads "Secure my account" and links to a domain that differs from the real one by a single character, something like an extra letter, a swapped domain extension, or a hyphen inserted between two words.

Step two: a login page that asks for one extra thing

The cloned page is visually identical to the real login screen, often built by copying the actual page's source code, so there is nothing to see that would raise suspicion. The target enters their email and password as usual. The fake page then asks for a two factor authentication code, exactly as the real site would, and quietly forwards both the password and the code to the attacker's own session with the real exchange in real time, a technique sometimes called an adversary in the middle attack. Because the code is used within seconds, the short validity window that normally protects two factor authentication provides no defense here.

Step three: the quiet withdrawal

With a live authenticated session, the attacker changes the account's withdrawal address or, if the exchange allows it, simply initiates a withdrawal to a wallet they control. On a self custody wallet flow, the equivalent step is a signature request rather than a login, where the target is asked to approve what appears to be a routine transaction but is actually a token approval or a transfer disguised behind a misleading function name. Either way, by the time the target notices anything unusual, the funds have typically already left the account and begun moving through several intermediate wallets.

None of these three steps looks dramatic in isolation. An email, a login page, a code entry field. What makes phishing effective is that each step mirrors a completely normal interaction the target has performed dozens of times before, so nothing in the sequence triggers the kind of hesitation a more obviously suspicious request would.

The delivery channels scammers rely on

The mechanism of theft is only half the story. The other half is how the phishing link reaches you in the first place, and this is where attackers have gotten far more creative.

  • Search engine ads that outrank the real wallet or exchange website for its own brand name, sending searchers to a pixel perfect clone
  • Fake browser extensions listed in official app stores, mimicking well known wallets
  • Direct messages on X, Telegram, or Discord from accounts impersonating support staff or project teams
  • Email campaigns spoofing exchange security alerts, warning of a login attempt that needs immediate verification
  • Compromised or cloned social media accounts of real crypto projects, posting fake airdrop or mint links
  • SMS messages claiming a withdrawal was blocked and asking the recipient to confirm their identity through a link

Why search engines have become a favored channel

Paid search placement is attractive to phishing operations because it does not depend on tricking a spam filter or getting past a platform's account verification, it simply requires paying for an ad slot. A search for a well known wallet's name can return a sponsored result sitting above the real website, and because the visitor typed the brand name themselves rather than clicking an unsolicited link, they often assume the top result must be legitimate. Ad platforms do remove these listings once reported, but new ones tend to reappear from different accounts within days, which means the channel keeps producing victims even as individual ads are taken down.

Why Telegram and Discord remain especially exploitable

Crypto communities live disproportionately on Telegram and Discord compared with most other industries, and both platforms make it trivial to create an account with a display name and profile picture that closely mirrors a real project's support team. A scammer can join a public server, monitor the channel for anyone describing a problem, and send a direct message within seconds, all without needing to compromise anything. Because the servers themselves are official and full of genuine participants, the setting lends the impersonator a form of borrowed credibility that a cold email never gets.

Researchers have also flagged a sharp rise in AI generated phishing content, with one 2025 analysis finding a roughly 70 percent increase in AI written phishing emails, which read more naturally and are harder for spam filters and human readers alike to flag compared with the clumsier, typo ridden messages of a few years ago. AI tools have also made it far cheaper to produce convincing cloned websites, translated phishing campaigns targeting non English speaking users, and personalized messages that reference a target's real activity, such as a recent NFT purchase or a specific token holding pulled from public blockchain data.

Why phishing still works on experienced users

It is tempting to assume phishing only catches beginners, but that is not what the data shows. Sophisticated traders have lost six and seven figure sums to a single misclicked approval, often because the pressure of a live token launch or a limited time airdrop window pushes people to act before they read carefully. Scammers deliberately manufacture urgency, a countdown timer, a claim that only the first thousand wallets qualify, a warning that your account will be suspended in 24 hours, because urgency short circuits the caution that would otherwise catch an unfamiliar domain name or an unusual permission request.

Fake customer support is a particularly effective variant of this pattern, since it exploits a moment when the victim is already anxious about their funds and actively looking for help. That approach is common enough that it deserves its own explanation, covered in our article on fake customer support scams.

How phishing became an industrialized business

A meaningful part of why phishing volume has stayed high even as individual losses have fallen is that running a phishing campaign no longer requires much technical skill. So called phishing kits and wallet drainer kits are sold or rented on underground forums as ready made packages, complete with cloned website templates, pre written smart contracts designed to request maximally broad approvals, and dashboards that let a buyer track how many wallets have connected and how much has been drained. Some of these kits operate on an affiliate model, where the kit's original developer takes a cut, often around 10 to 20 percent, of everything a customer steals using the tool, similar in structure to a legitimate software as a service business.

  • Pre built cloned websites for popular exchanges and wallets that only require the buyer to plug in a wallet address to receive stolen funds
  • Drainer smart contracts designed to request the broadest possible spending approval by default, maximizing what can be taken from a single signature
  • Automated Telegram bots that alert the operator the moment a new wallet connects, so time sensitive draining can happen quickly
  • Customer support style channels within the criminal marketplace itself, where kit buyers can get help configuring their scam pages

This industrialization explains a pattern that otherwise seems confusing, why phishing pages targeting the same wallet brands keep reappearing within days of being taken down. The buyer of a kit did not build the page from scratch and does not need deep technical knowledge to relaunch it on a new domain after the old one is blacklisted.

Practical ways to reduce your exposure

  • Bookmark the real URLs of exchanges and wallets you use, and never navigate to them through a search engine result or a link in a message
  • Treat every wallet connection request as a decision that deserves a pause, especially anything involving an approval rather than a simple transfer
  • Use a wallet interface or browser extension that decodes and displays what a transaction actually does before you sign it
  • Periodically review and revoke old token approvals using a reputable revocation tool, since forgotten permissions are a common entry point
  • Treat unsolicited direct messages from support accounts as a red flag by default, since legitimate support teams generally do not initiate contact
  • Enable a hardware wallet for any holdings beyond what you need for active trading, since a hardware device forces a physical confirmation step that a remote attacker cannot replicate
  • Check the certificate details and exact spelling of a domain character by character before entering any credentials, especially when you arrived at the page through a link rather than typing it yourself

A quick checklist before you connect a wallet

Before connecting a wallet to any site, it is worth running through a short mental checklist: did you arrive at this page by typing the address yourself or through a bookmark, rather than a link. Does the domain match the official one exactly, with no extra characters or substituted letters. Is there any urgency being applied, a countdown, a claim of limited availability, a warning that time is running out. If a signature request appears, does your wallet interface show a plain language description of what it does, and does that description match what you expected to happen. Any single one of these checks failing is a reason to stop and verify independently before proceeding.

If you already approved a transaction you regret, our guide on revoking token approvals walks through how to check and undo standing permissions before they can be used against you.

If you think you have been phished

Speed matters. If you suspect a wallet has been compromised through a phishing link, move any remaining funds to a new wallet with a freshly generated seed phrase immediately, rather than trying to clean up the old one. Do not interact further with the site or contract involved, and document every transaction hash, timestamp, and message you received, since this record is what any later investigation or exchange complaint will depend on. Firms like Coin Trace work with victims to trace where stolen funds moved after a phishing incident and to prepare the documentation exchanges and law enforcement typically require, though no legitimate investigator can promise that funds will be recovered.

phishingcrypto securitywallet drainersseed phrase theft

Frequently asked questions

Yes. A fake airdrop or minting site can ask you to approve a smart contract permission instead of asking for your seed phrase directly. Once you sign that approval, the attacker can move tokens out of your wallet without ever knowing your recovery phrase, sometimes long after you visited the original site.

Check the exact domain spelling character by character, since clones often use lookalike characters or extra words. Confirm the site through an official social media account or bookmark rather than a search result or link, and be suspicious of any site pressuring you to connect your wallet quickly.

Attackers have automated much of the process, making it cheap to run large numbers of smaller campaigns rather than a few big ones. Reported data shows losses per incident have fallen, but the total number of incidents remains high, which suggests broad, low cost targeting rather than a decline in the underlying threat.

No transaction on a public blockchain can be reversed once confirmed. What is possible is tracing where the funds moved afterward, which can sometimes lead to an exchange freeze if the funds land in an account subject to identity verification.


Sources and further reading


Related reading

How Seed Phrase Theft Happens and How to Prevent ItHow Malicious Token Approvals Are Used to Empty a WalletReviewing and Revoking Token Approvals, A Practical GuideFake Customer Support Scams Targeting Crypto Users