Phishing emails are the most common way crypto is stolen. They look legitimate, create urgency, and trick you into revealing your credentials.
Anatomy of a Phishing Email
| Element | Legitimate Email | Phishing Email |
|---|
| Sender address | official@exchange.com | officiaI@exchange.com (spoofed) |
| Greeting | Dear [Your Name] | Dear Customer |
| Urgency | None | ”Action required within 24 hours” |
| Link | exchange.com/security | exchange-secure.com |
| Spelling | Professional | Minor errors or odd phrasing |
Common Crypto Phishing Themes
| Theme | Example |
|---|
| Account suspension | ”Your account will be suspended. Verify now.” |
| Unauthorised login | ”New login detected from Russia. Click to secure.” |
| Withdrawal pending | ”Your withdrawal is pending. Confirm to process.” |
| Wallet update | ”Update your wallet to continue using our service.” |
| Token airdrop | ”Claim your free tokens. Limited time.” |
| Security upgrade | ”We’ve upgraded our security. Re-verify your account.” |
How to Check a Link
Before clicking, hover over the link.
| Displayed Text | Actual Link | Verdict |
|---|
| binance.com/security | binance.com/security | Safe |
| binance.com/security | binance-secure.com | Phishing |
| Sign in to your account | http://192.168.1.1/login | Phishing |
| Claim airdrop | http://claim-uni.io | Phishing |
| metamask.io/unlock | metamask.io/unlock | Safe |
| metamask.io/unlock | metamask-extension.com | Phishing |
Red Flags
| Red Flag | Why It’s Suspicious |
|---|
| Generic greeting (“Dear customer”) | Real services use your name |
| Threats or urgency | Designed to bypass your judgement |
| Unexpected attachment | Never open attachments from crypto services |
| Requests for password | No legitimate service asks for your password |
| Requests for seed phrase | NEVER share your seed phrase |
| Mismatched sender name | ”Coinbase” from “support@gmail.com” |
| Grammar errors | Professional companies proofread their emails |
The “From” Address Trick
Scammers spoof the “From” address to look legitimate.
Check the full email header if you’re suspicious.
What Legitimate Companies Will Never Do
| Legitimate companies will NEVER |
|---|
| Ask for your password in an email |
| Ask for your seed phrase or private key |
| Ask you to “verify” by sending crypto |
| Send you a link to download their app |
| Ask you to connect your wallet to a website they link |
What to Do If You Receive a Phishing Email
| Step | Action |
|---|
| 1 | Don’t click any links |
| 2 | Don’t open attachments |
| 3 | Mark as spam/phishing in your email client |
| 4 | Forward to the company’s security team (report@company.com) |
| 5 | Delete the email |
What to Do If You Clicked
| Step | Action |
|---|
| 1 | Don’t enter any credentials |
| 2 | Close the page immediately |
| 3 | Change passwords on the real website (not from the link) |
| 4 | Enable or check 2FA |
| 5 | Check for unauthorised access |
| 6 | Monitor your accounts for suspicious activity |
Bottom Line
Phishing emails work by looking real and creating urgency. Always check the sender address, hover before clicking links, and remember: no legitimate service will ever ask for your password or seed phrase via email. When in doubt, type the website URL yourself instead of clicking the link.
This content is for educational purposes only. Not financial advice. Do your own research before investing.