Have You Recently S…
 
Notifications
Clear all

Have You Recently Seen a New Crypto Phishing Technique?

1 Posts
1 Users
0 Reactions
6 Views
 adm
(@adm)
Member Admin
Joined: 5 days ago
Posts: 94
Topic starter   [#63]

Crypto phishing is getting harder to identify because attackers are no longer relying only on obvious fake websites or badly written emails. Many recent scams are built around realistic interfaces, copied branding, legitimate-looking wallet prompts and social engineering that feels much more targeted.

One technique I keep seeing discussed is phishing that starts with a real-looking support conversation. A user posts about a wallet or exchange problem, and within minutes someone pretending to be support contacts them through direct messages. The attacker then sends a “verification” or “recovery” link that leads to a fake wallet connection page.

Another increasingly dangerous approach is malicious transaction signing. Instead of asking directly for a seed phrase, the attacker convinces the user to connect a wallet and approve something that looks harmless. The transaction may actually grant token permissions, sign a permit or authorize asset movement.

Address poisoning is another tactic that can catch even experienced users. Attackers send tiny transactions from addresses designed to resemble addresses the victim has interacted with before. If the user later copies an address from transaction history without checking it carefully, funds can be sent to the attacker.

Fake airdrops and token claims are still extremely common, but the presentation is becoming more convincing. Scam pages may copy the exact interface of a real protocol and even use current project news to make the campaign feel legitimate.

I am also concerned about compromised social accounts. When a verified or well-known project account is hacked, malicious links can appear far more trustworthy than a random phishing message. Users may lower their guard simply because the post comes from an account they already follow.

Search-engine phishing is another problem. A fake exchange or wallet website can sometimes appear through paid ads or copied SEO pages. That makes blindly searching for a platform every time less safe than using a verified bookmark.

The common pattern is that phishing is becoming less about stealing credentials directly and more about convincing users to perform the dangerous action themselves.

What new crypto phishing techniques have you seen recently?

Are attackers relying more on fake support accounts, malicious wallet signatures, address poisoning, compromised social profiles or fake airdrop pages?

And what phishing method do you think experienced crypto users are currently most likely to underestimate?



   
Quote
Share: