Skip to content

Phishing

Clicks that authorize irreversible transfers

Modern crypto phishing uses fake mint pages, permit signatures, and session hijacks—not just password forms.

Phishing losses

Victims sign malicious transactions or reveal exchange credentials through cloned interfaces.

Losses may occur in seconds via automated sweeper bots.

Attack chain

  1. 01

    Lure

    Email, X DM, or sponsored ad promising airdrops.

  2. 02

    Wallet connect

    Malicious dApp requests token approvals or seed entry.

  3. 03

    Drain

    Automated transfer to operator wallets.

Signals

  • URLs one character off from official domains
  • Unlimited token approvals requested
  • Urge to act before a countdown expires

Movement

Drained assets are swapped and bridged rapidly.

  • — NFT and ERC-20 sweeps in one TX bundle
  • — Routing through mixers or privacy pools
  • — Exchange deposits within minutes on high-volume campaigns

Evidence

  • Phishing URL captures
  • Wallet connect logs
  • Malicious transaction hashes
  • Email headers

Focus

01

Drainer infrastructure

Contract addresses reused across campaigns.

02

Post-drain tracing

Follow outbound from victim wallet.

Now

  • 01Revoke approvals via reputable tools if assets remain
  • 02Move remaining funds to clean wallets
  • 03Never re-enter seed on any linked page

Never provide a seed phrase, private key, or authentication code to anyone claiming they can recover funds—including parties who contact you unsolicited. Legitimate investigators do not need wallet secrets to begin a case review.

Frequently asked questions

Can drained NFTs be traced?

Often yes on public marketplaces until laundered.

Investigate phishing loss

Provide malicious TXIDs and URLs.