rabbitechnology.xyz

Crypto phishing and fake sites

Crypto phishing is the single most common way people lose their digital assets. It is not a brute-force hack of the blockchain itself. It is a deception: a fake site, a fake message, a fake transaction request that looks real enough that you sign away your funds with your own hand. The blockchain executes exactly what you signed. The problem is you signed the wrong thing.

This page surveys the entire landscape: how these attacks work, what tools exist to detect them, what the warning signs look like, and what decisions you will face. Each major topic below hands off to a dedicated spoke page that answers one specific question completely.


How fake crypto sites reach you

Attackers need to get you to a fake site before they can steal from you. They use several delivery mechanisms, and understanding each one helps you recognise the pattern before you click.

Phishing links sent through social media DMs are the most direct method. An account that looks like a project's official handle - sometimes with a verified badge that was bought or stolen - messages you with a link to "claim your airdrop" or "resolve an issue with your wallet." The link looks like the real domain but is not. The dedicated page on crypto phishing links sent through social media DMs and how to spot them walks through the exact patterns that reveal a DM link is malicious before you click.

Search engine ad impersonation results have become a major vector. Attackers buy Google Ads for the search term "Uniswap" or "MetaMask" and place a sponsored result above the real organic listing. The ad looks identical to the real site's branding. Users click the first result without checking the URL. The page on Google ads crypto phishing results and how to avoid them explains why these ads appear and how to distinguish a sponsored result from the real organic listing.

Discord webhook compromise and fake crypto announcements is a more sophisticated delivery method. Attackers compromise a Discord webhook - a tool that lets bots post messages to channels - and use it to post a fake mint or airdrop announcement directly into the official project's own Discord server. The message appears in the same channel where legitimate announcements are posted. The page on Discord webhook compromise and fake crypto announcements explains how attackers gain access to webhooks and what to check before trusting any announcement, even inside an official server.

Typosquatting on common misspellings is one of the oldest tricks. An attacker registers uniswaap.com or opensea.io with a character that looks identical at a glance. You type the address from memory, make one character error, and land on a perfect visual clone of the real site. The page on typosquatting crypto exchange domains and how they steal your funds covers the common misspelling patterns attackers use and what happens when you enter your seed phrase into the fake login form.


How to check a crypto URL before you connect

The single most effective defence is verifying the URL before you connect your wallet. This sounds trivial. In practice, most phishing victims never checked the URL at all, or checked it only at a glance.

How to check a crypto URL for phishing before you connect is the spoke page that covers manual inspection from start to finish. It explains how to read a domain name left to right, how to spot homoglyph characters (letters from other alphabets that look like Latin letters), how to verify the domain on CoinGecko or DefiLlama's official link directory, and how to use Whois domain age lookup to check whether the domain was registered yesterday.

Checking domain age to spot a recently registered crypto phishing site is a specific technique worth calling out separately. The vast majority of phishing domains are registered within the past 30 days. The spoke page on that topic shows you exactly how to run a Whois check, what a suspicious registration date looks like, and why an old domain is not automatically safe but a very new one is almost always dangerous.

MetaMask phishing detector warning and what the blocklist means is the first line of defence for many users. MetaMask maintains a blocklist of known phishing domains. When you visit a domain on that list, the wallet shows a red warning: "This site is on our blocklist." The spoke page explains what that blocklist actually detects, how quickly it updates, and - critically - what to do when the warning appears, and what to do when it does not appear but the site is still suspicious.

Deceptive site ahead Chrome warning for crypto phishing sites is a separate blocklist maintained by Google Safe Browsing. Chrome shows a full-page red warning that reads "Deceptive site ahead." The spoke page on this topic explains what triggers that warning, whether you should ever click through it, and why the absence of the warning does not mean a site is safe.

Your connection is not private SSL error on a crypto site is another browser-level warning. It means the site's SSL certificate is invalid or does not match the domain. Many users assume this is a minor technical glitch and click through anyway. The spoke page explains what this error actually means, why a valid SSL certificate does not prove a site is legitimate, and why the padlock icon alone tells you nothing about whether the site will steal your funds.


What happens when you connect or sign

The fake site has your attention. Now it needs you to connect your wallet or sign something. This is where the actual theft happens, and the mechanisms vary in sophistication.

Unlimited token approval phishing and how to check what you signed covers the most common approval-based attack. The site asks you to sign a transaction that grants it permission to spend an unlimited amount of a specific token. You see a standard wallet prompt. You sign. The attacker can now drain that token from your wallet at any time without further permission. The spoke page explains what the unlimited approval looks like in your wallet prompt and how to check and revoke existing approvals before they are exploited.

Permit signature phishing and why it bypasses approval transactions is a newer and more dangerous variant. Instead of submitting a transaction on-chain (which costs gas and leaves a clear record), the attacker uses the ERC-20 Permit function to have you sign a message off-chain. That signature can then be submitted by anyone as a transaction, approving token spending without you ever seeing a "send transaction" prompt. The spoke page explains how a permit signature phishing attack approves token spending without requiring a gas transaction, and how it is different from a standard approval.

Smart contract front-end cloning and fake DeFi protocol sites is the full-site clone. The attacker copies the entire front-end of a DeFi protocol - every button, every color, every chart - and deploys it on a fake domain. When you connect your wallet and try to deposit or swap, the fake front-end interacts with a malicious contract that steals your assets. The spoke page explains how attackers clone a DeFi protocol's front-end to create a visually identical site that interacts with a malicious smart contract instead of the real one.

WalletConnect session hijacking and fake connection requests targets users who connect via WalletConnect rather than a browser extension. Attackers create fake WalletConnect QR codes or deep links that connect your wallet to their malicious interface. Once connected, they can request signatures and transactions that appear to come from the legitimate dApp. The spoke page on WalletConnect session hijacking and fake connection requests explains how attackers hijack or impersonate WalletConnect sessions to trick users into signing malicious transactions on a fake dApp interface.

Clipboard hijacking that replaces your copied crypto address does not require a fake site at all. Malware on your device monitors your clipboard. When you copy a wallet address to send funds, the malware replaces it with the attacker's address. You paste what appears to be your intended recipient, but the funds go to the attacker. The spoke page explains how clipboard hijacking malware works and how to verify the address before sending - including checking the first and last few characters of the address that appears in your send confirmation.


Tools and decisions that determine whether you lose funds

You have tools available at every stage of the interaction. The question is whether you use them, and in what order.

Revoke.cash versus Etherscan token approval checker compared is a practical decision many users face. Both tools let you see and revoke token approvals. Revoke.cash presents a cleaner interface and batch revocation. Etherscan's approval checker is built into the block explorer and does not require visiting a separate site. The spoke page compares the practical differences between using Revoke.cash and Etherscan's built-in token approval checker to find and revoke risky allowances.

Transaction simulation failed error and why your wallet rejected it is a feature that is saving an increasing number of users. Modern wallets like Rabby and MetaMask with Blockaid integration simulate the transaction before you sign. If the simulation shows your tokens leaving your wallet to an unexpected address, the wallet rejects the transaction and shows an error. The spoke page explains what a "transaction simulation failed" error actually means and how transaction simulation protects against malicious contracts.

Using a burner wallet for new crypto sites and airdrop claims is a strategy that completely eliminates the risk to your main wallet. You create a separate wallet with only the funds you are willing to lose, connect that wallet to untrusted sites, and keep your main holdings in a wallet that never touches experimental dApps. The spoke page explains how to set up and use a burner wallet to interact with new or untrusted crypto sites without exposing your main wallet funds.

Hardware wallet blind signing and why it does not stop all phishing is a dangerous misconception. Many users believe that a hardware wallet is invulnerable. It is not. If you blind-sign a transaction - approve it on the device without understanding what it does - the hardware wallet will happily sign a transaction that drains all your assets. The spoke page explains why a hardware wallet can still approve a malicious transaction that drains your wallet, and how blind signing makes phishing effective even with cold storage.


Common misconceptions that enable phishing

Several persistent myths make phishing far more effective than it should be.

A padlock icon means the site is legitimate. This is false. The padlock only means the connection between your browser and the server is encrypted. It does not mean the server is honest. Attackers generate valid SSL certificates for fake domains every day. The padlock tells you nothing about the site's intent.

Hardware wallets prevent all phishing losses. They do not. A hardware wallet signs what you tell it to sign. If you tell it to sign a malicious approval transaction, it will do so. The hardware wallet secures your private key from remote theft, but it cannot read the fine print of a transaction for you.

Only new users fall for phishing. This is also false. Experienced users fall for sophisticated phishing because they rely on pattern recognition and shortcuts. They see a familiar interface, they recognise the workflow, and they stop checking the details. Phishing attacks against DeFi power users often succeed because the victim was in a hurry and trusted their instincts instead of verifying.

Google search results are vetted and safe. Google's organic results are not vetted for safety. Google's ad results are paid placements with minimal verification. Attackers routinely buy ads for crypto brand names, and those ads pass Google's review process. The organic result below the ad is often the real site, but users click the ad first.

MetaMask will always warn me about phishing. MetaMask's blocklist is maintained by a third party (PhishFort) and is reactive. New phishing domains are registered and used before they are added to the blocklist. The absence of a warning does not mean the site is safe. It may mean the site is too new to have been reported yet.


The cost of getting it wrong

Phishing losses in crypto are not theoretical. They are the primary cause of user fund loss across every chain.

The immediate cost is financial. A full wallet drain via unlimited token approval can remove every token and NFT from your wallet in a single transaction. Staked assets can be unstaked and stolen. Credentials entered on a fake exchange login page can be reused to drain your exchange account.

The recovery cost is often zero. There is no reversal mechanism for most blockchain transactions. The gas cost of an approval revocation transaction is small - usually a few dollars - but that only prevents future theft. It does not recover what was already taken.

The time cost is significant. Manual verification of every contract interaction, every URL, every DM link adds friction to every crypto interaction. But the alternative is permanent loss.


The decisions you will make

Every crypto interaction involves a series of decisions that determine your risk.

Do you connect your wallet to a site in view-only mode first, or do you connect and approve immediately? Do you sign a blind transaction, or do you simulate it first? Do you use your main wallet for a new airdrop claim, or do you use a burner wallet? Do you trust a link from a verified Twitter account, or do you verify the domain independently?

The spoke pages listed throughout this pillar page answer each of these questions in detail. Each one is designed to be read independently, but together they form a complete reference for identifying, avoiding, and recovering from crypto phishing attacks.

Start with how to check a crypto URL for phishing before you connect. That single skill prevents the majority of attacks. Then work through the specific attack types that are most relevant to how you use crypto. The tools and decisions sections will help you build a workflow that makes phishing much harder to pull off against you.

Not financial advice. rabbitechnology.xyz publishes market data and general information about digital assets. Crypto assets are volatile and you can lose everything you put in. Nothing here is a recommendation to buy, sell or hold, and we make no price predictions.

Prices are sourced from third parties and may be delayed or wrong. Verify anything you intend to act on against a primary source.