Social engineering attacks manipulate people into revealing sensitive information or approving malicious transactions.
Common Techniques
| Technique | How It Works |
|---|
| Phishing | Fake emails/websites that look legitimate |
| Vishing | Voice calls impersonating support |
| Smishing | SMS texts with malicious links |
| Pretexting | Attacker creates a fake scenario to get information |
| Baiting | Offering something free to install malware |
| Tailgating | Following someone into a restricted area |
| Impersonation | Pretending to be a known person or company |
Crypto-Specific Social Engineering
| Attack | How It Works |
|---|
| Fake support | ”Binance support” DMs you on Telegram |
| Seed phrase recovery | ”Enter your seed phrase to fix your wallet” |
| Fake airdrop | ”Claim your free tokens — connect wallet” |
| Romance scam | Builds trust over weeks, then asks for crypto |
| Impersonation of known figure | ”Elon Musk is giving away Bitcoin” |
| Fake team member | Pretends to be from the project team on Discord |
Red Flags
| Red Flag | Why It’s Suspicious |
|---|
| Urgency | ”Do this now or lose your funds” |
| Asks for seed phrase | No legitimate service ever asks for this |
| Unsolicited contact | You didn’t reach out to them |
| Too good to be true | Free crypto, guaranteed returns |
| Poor grammar/spelling | Common in phishing attempts |
| Mismatched URL | Link says binance.com but goes to binance-secure.net |
| Asks you to install software | Remote access tools |
The Psychology Behind It
| Trigger | How Attackers Use It |
|---|
| Fear | ”Your account has been compromised” |
| Greed | ”Free airdrop — connect now” |
| Urgency | ”Offer expires in 10 minutes” |
| Authority | ”I’m from Coinbase security” |
| Trust | ”I’m a friend of your brother” |
| Scarcity | ”Only 100 spots available” |
How to Defend Yourself
| Rule | Why |
|---|
| Never share your seed phrase | No one legitimate needs it |
| Verify all contacts | Call the official number, don’t use the one they give |
| Check URLs carefully | Hover before clicking |
| Use 2FA | Prevents account takeover |
| Don’t answer unknown calls | Let it go to voicemail |
| Use a hardware wallet | Transactions need physical approval |
| Enable transaction simulation | Ledger/Trezor show what you’re signing |
| Verify on official channels | Check Twitter/Discord for scam alerts |
The SEED Mnemonic (Checklist)
| Letter | Rule |
|---|
| S | Stop — don’t act immediately |
| E | Examine — does this make sense? |
| E | Evaluate — what’s the real motivation? |
| D | Decide — is this safe? |
What to Do If You’ve Been Manipulated
| Step | Action |
|---|
| 1 | Don’t send more crypto |
| 2 | Move remaining funds to a new wallet |
| 3 | Change all passwords |
| 4 | Revoke all approvals |
| 5 | Report to authorities |
| 6 | Warn others |
Bottom Line
Social engineering targets you, not your technology. Attackers use fear, greed, and urgency to make you act without thinking. Never share your seed phrase, verify all contacts independently, and always stop before acting under pressure. If something feels wrong, trust your instinct.
This content is for educational purposes only. Not financial advice. Do your own research before investing.