メニューを開く

Wallet scam red flags: pause before you sign

A wallet scam red flag is a warning in a chat, ad, token, or signature prompt that means you should stop. In 2026 the steal usually looks like help: fake Ledger or MetaMask support, a “verify wallet” page, or a claim button. This lesson is a beginner checklist with examples you can match to a real wallet prompt. If even one red flag is present, stop. On-chain transfers are usually irreversible.

TL;DR

Never type a seed phrase or private key into a website or chat. Type official URLs yourself. Treat DMs, airdrop claims, and unsolicited “support” as hostile. Read every wallet prompt in plain language before you confirm. Keep long-term funds in a wallet you do not use for experiments.

Why a checklist beats a panic search

People searching “how to protect seed phrases” or “common crypto phishing red flags” are usually already mid-scare: a pop-up, a Telegram DM, a token that appeared overnight, or a page that says the wallet will be frozen. Logos and domains change. The pressure script does not.

This page is the Security pillar’s pause-and-compare tool. For the recovery-word rules themselves, read seed phrase safety. For the wider scam catalog, see crypto scams and phishing. For the signature that can move tokens, see wallet approvals and token permissions.

How to protect a seed phrase (the short answer)

A seed phrase (often 12 or 24 words) can recreate the keys that control a self-custody wallet. Anyone who has those words can usually move the funds. That is why official wallet makers tell you never to enter the phrase on a computer or phone except during a restore you started yourself.

MetaMask’s Secret Recovery Phrase guide is explicit: support will not ask for it, and you should not type it into a website. Ledger’s recovery-phrase article says the same for hardware wallets: the phrase stays offline; a “firmware” or “sync” page that wants the words is the attacker.

Practical beginner rules:

  • Write the words on paper or metal. Do not screenshot them or paste them into chat, email, or a notes app that syncs to the cloud.
  • Only enter the phrase when you opened the official wallet app or device restore flow — never after a link from a DM, ad, or search result.
  • If a site, bot, or “agent” asks for the words, close it. Then follow seed phrase safety for storage, not this chat.

Ten red flags to check every time

  1. Anyone asks for the seed phrase, private key, or “backup code.” Example: a chat that says “paste your 12 words so we can sync MetaMask / Phantom / Trust Wallet.” Real support cannot restore your self-custody wallet from those words, and does not need them.
  2. Urgency plus a countdown. Example: “Your wallet will be liquidated in 15 minutes unless you verify.” Phishing pages still use timers, red banners, and fake security alerts. Legitimate network events do not require you to paste secrets.
  3. A link you did not type. Example: an X/Twitter ad, Google ad, SMS, or email that looks like Ledger, Trezor, Coinbase Wallet, or a popular browser-wallet brand. Type the brand’s site from a bookmark you saved on a calm day.
  4. A DM that starts after you posted a problem. Example: you ask in Discord why a swap failed; three “official support” accounts message you with a ticket link. Support that arrives uninvited is a classic pattern in 2026.
  5. “Connect and sign to claim.” Example: a surprise airdrop, mint, or “refund” page. Connecting often only shows your address. The dangerous step is the next signature: a permit, setApprovalForAll, or a transaction you cannot explain in one sentence.
  6. The wallet prompt does not match the button you clicked. Example: the site says “log in,” but the wallet asks to transfer tokens, increase allowance, or sign a typed-data message with a spender address you do not recognize.
  7. A lookalike destination address. Example: you copy an address you used last week, but the first and last characters match while the middle is different (address poisoning). Always check more than the first four and last four characters, especially on mobile.
  8. A brand-new token sitting in the wallet. Example: an airdropped token named after a real project. Opening a random “claim” site from the token’s website field is a common drainer path. Ignore unknown tokens until you verify the project from a source you already trust.
  9. Software you did not intend to install. Example: a “wallet fixer,” remote-desktop tool, or browser extension pushed in a video call. Clipboard-stealing malware still swaps addresses after you copy them. If an address changes between copy and paste, stop.
  10. A paid “recovery” or “whitelist” service after a scare. Example: someone who already tricked you now offers to get the funds back for a fee, or to “clear a blacklist.” Guaranteed recovery is a second scam stacked on the first. The U.S. FTC cryptocurrency scam briefing treats recovery-for-a-fee pitches as a known follow-on fraud.
This is not investment advice

This lesson explains common attack patterns so you can avoid irreversible mistakes. It does not recommend coins, wallets as investments, or any product. If you already signed a malicious transaction, treat remaining funds as at risk and move them only to a wallet and address you created yourself.

How to avoid crypto phishing scams

Phishing is a fake page or message that impersonates a brand you already trust. The goal is not to “hack Bitcoin.” The goal is to get you to type a secret or sign a permission. The FBI Internet Crime Complaint Center (IC3) is the U.S. reporting desk for internet crime; consumer guidance from the FTC (linked above) matches the same beginner rule: never give recovery words or remote access to a stranger.

A calm 2026 routine:

  1. Do not click wallet or exchange links from ads, DMs, or email. Open a bookmark you created earlier, or type the domain yourself.
  2. Check the exact domain character by character. Extra words, swapped letters, or a different ending (.app vs .com) are enough.
  3. If a page wants a seed phrase, you are on the wrong site. Close it.
  4. If a page wants a signature, read the wallet UI. If you cannot say what asset moves, to whom, and why, reject it.
  5. Use a small experiment wallet for new apps. Keep savings elsewhere — see hot wallets vs cold wallets.

2026 examples, in plain language

Fake hardware-wallet “firmware” pages. You search for a firmware update, click an ad, and land on a page that asks you to enter recovery words to “re-pair” the device. A hardware wallet’s job is to keep those words off the internet. If a website wants them, the website is the attacker.

Drainer sites dressed as mints and claims. A page looks like an NFT drop or a points dashboard. You connect. The prompt asks for unlimited token approval, a Permit-style signature, or several confirms in a row. One rushed “confirm” can let a contract empty the approved tokens. Slow down and read how approvals work before you experiment with new apps.

Address poisoning after a real transfer. You send USDC to a friend. Later, a tiny incoming transfer from an address that looks like theirs appears in history. Next time you copy “the last address,” you paste the attacker’s. Check the full string, or use a saved contact / address book in the wallet if it offers one.

QR-code swap at the last second. You are paying someone in person or scanning a poster. The scammer covers the real QR with another, or a malicious overlay in a screenshot. Confirm the human-readable address on your own screen, not on theirs.

Fake apps and “security extensions.” An ad or DM sends you to an app-store listing or a Chrome/Firefox add-on with a near-identical name. The fake app can show a normal home screen and still exfiltrate keys or swap the clipboard. Install wallet software only from a URL you typed, then confirm the publisher name against the brand’s own help site.

Typed-data prompts that do not look like a send. The button said “verify” or “log in,” but the wallet shows a Permit, Permit2, setApprovalForAll, or a blob of hex you cannot explain. Reject it. Connecting is not the same as spending. Spending needs a signature you understand.

What to do when a flag appears

What you saw Safe next step Unsafe next step
Request for seed phrase or private key Close the tab or chat. If you already typed words into a site, assume the wallet is burned and move funds from a device you still control to a new wallet you created yourself. Finish “verification,” screenshot the words, or send them to anyone claiming to be support.
Unexpected airdrop or claim page Ignore the token. Verify the project later from a bookmark or official account you already follow. Use a throwaway wallet if you still want to inspect it. Connect your main wallet and sign because the UI looks official.
Wallet prompt you cannot explain Reject. Screenshot the prompt for your own notes. Compare it with the button you clicked. Approve because a countdown is running.
Lookalike address Send a tiny test amount first, or re-copy from a source you typed yourself. Send the full amount because the first and last characters “look right.”
Unsolicited support after you posted a problem Ignore the DM. Open the project’s help from a bookmark. Never install remote-desktop tools for “wallet repair.” Share a screen, paste a phrase, or follow their “ticket” link.

A calmer beginner setup

Keep two mental buckets. Savings: funds you are not using this week, preferably with a backup you understand — see hot wallets vs cold wallets. Spending / experiments: a small wallet you use to try apps, claims, and new sites. If that wallet is drained, the loss is limited.

If addresses and keys still feel abstract, start with keys and wallet addresses. Live prices and tickers do not tell you whether a site is safe — they only show market data — but you can open live rates from this site without connecting a wallet at all.

The Education hub at /education and the Security pillar are the right next clicks after this checklist. Bookmark those, not random search ads.

If you already clicked or signed

  1. Do not send more funds to “unlock,” “tax,” or “gas refund” addresses.
  2. If you only opened a page, close it. Change passwords on email if you typed them on the same device.
  3. If you connected and signed, treat remaining assets as exposed. From a clean device, move what you still control to a newly created wallet whose seed phrase never touched the phishing page.
  4. Review and revoke token approvals on the chain you used, using a revoke tool you navigated to yourself — not a link from the scammer. See wallet approvals.
  5. If an exchange account was involved, use that exchange’s official app or a URL you typed, then lock sessions and turn on stronger two-factor authentication (not SMS if you can avoid it).
  6. If you are in the United States and lost funds to a scam, you can file a complaint with IC3. Filing does not reverse a confirmed transfer.

Nobody on this site can reverse a confirmed on-chain transfer. Anyone who promises they can, for a fee, is showing red flag ten.

FAQ

Is this different from the general phishing lesson?

Yes. The phishing overview explains the industry. This checklist is the pause-and-compare tool for wallet prompts, seed-phrase traps, address poisoning, and claim-page drainers that beginners hit in 2026.

How do I protect my seed phrase from phishing?

Keep it offline. Never type it after a link, ad, or DM. Official restore happens only inside the wallet app or hardware device you opened yourself. Details are in seed phrase safety.

What are common crypto phishing red flags?

Urgency timers, unsolicited support, lookalike domains, requests for recovery words, claim buttons that need a signature, and wallet prompts that do not match the button you clicked.

Can I screenshot my seed phrase if I lock my phone?

A screenshot can still sync to cloud backups, laptops, and stolen-device restores. Prefer an offline copy.

Are all airdrops scams?

No, but fake claims are common enough that you should never sign from your savings wallet. Verify the source first, or skip it.

Does a hardware wallet make this checklist unnecessary?

No. A hardware wallet protects keys from a compromised computer, but it will still sign a malicious transaction if you approve the prompt. You still have to read what you are signing.

Does connecting a wallet empty it?

Usually no. Connecting typically shares an address. The dangerous step is a separate approval or signature. If you do not understand the prompt, reject it.

Knowledge check

Quick quiz

01 What should you do if a “support agent” asks for your seed phrase?
02 Which 2026 wallet-scam pattern is easiest to miss?
03 Does connecting a wallet by itself usually let a site spend your tokens?
04 What is a safe response to an unexpected airdrop claim page?