[{"data":1,"prerenderedAt":25},["ShallowReactive",2],{"blog-content-en-how-to-spot-crypto-phishing":3},{"slug":4,"title":5,"excerpt":6,"description":7,"bodyHtml":8,"faqItems":9},"how-to-spot-crypto-phishing","How to Spot Crypto Phishing: Fake Sites, DMs and Urgent Messages","You spot crypto phishing by the approach, not the artwork: unsolicited contact, a manufactured deadline, and a request for your seed phrase or a signature on a page you reached through a link. WATS is fully non-custodial and never holds a key, so nobody from WATS will ever need those words. Here is the full lure taxonomy, the URL checks that expose clones, and what to do after you click.","How to spot crypto phishing: clone sites in search ads, fake airdrops, DM support scams, urgency hooks and poisoned QR codes — plus the right-to-left domain check, the seed-phrase rule, what to do after clicking, and why WATS, being fully non-custodial, will never ask for your recovery phrase.","\u003Cblockquote>\u003Cp>Crypto phishing is spotted by the approach rather than the appearance: an off-channel contact you never asked for — a DM, a paid search ad, a QR code, a calendar invite — a manufactured deadline, and a request no legitimate party ever makes, namely your seed phrase or a signature on a page you reached through a link. No legitimate party ever needs your recovery phrase, and a fully non-custodial wallet like WATS — where you hold the keys and WATS never holds a key — has no account to unlock and no reason to ask for those words. Design proves nothing, so check the domain character by character and read it right to left: the registered name sits immediately before the top-level domain, which makes app.wallet.com.claim-rewards.io the site claim-rewards.io. Never arrive at a financial site through an ad, a DM or a QR code — bookmark the real address once and enter only through that bookmark, and remember that HTTPS and a padlock prove encryption, not honesty. If you already clicked, triage by what came after: closing the tab is usually harmless, connecting without signing only exposes your address, a signature means you should review recent activity and revoke unrecognized token approvals now, and an entered seed phrase means the wallet is permanently compromised and everything must move to a freshly generated one immediately.\u003C\u002Fp>\u003C\u002Fblockquote>\n\n\u003Ch2>How do you spot crypto phishing?\u003C\u002Fh2>\n\u003Cp>\u003Cstrong>Crypto phishing\u003C\u002Fstrong> reveals itself through three tells: an off-channel approach — a DM, ad or invite you never asked for — a manufactured deadline (“claim in 10 minutes”, “your wallet is at risk”), and a request no legitimate party ever makes: your seed phrase, or a signature on a page you reached through a link. Check the domain character by character, and verify through a channel you already trust.\u003C\u002Fp>\n\u003Cp>Phishing is the social half of the attack. The technical half — the malicious approval or signature waiting behind the link — belongs to \u003Ca href=\"\u002Fblog\u002Fwhat-is-a-wallet-drainer\">wallet drainers\u003C\u002Fa>, and that post covers the on-chain mechanics. This one is about the step before: recognizing the lure while your funds are still yours.\u003C\u002Fp>\n\n\u003Ch2>The lure taxonomy: five ways they reach you\u003C\u002Fh2>\n\u003Cp>Almost every campaign is a variation on five delivery methods. Learn the shapes, and the specific bait — the token name, the brand being impersonated — stops mattering.\u003C\u002Fp>\n\u003Ctable>\u003Cthead>\u003Ctr>\u003Cth>Lure\u003C\u002Fth>\u003Cth>How it works\u003C\u002Fth>\u003Cth>The tell\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd>Search-ad clone site\u003C\u002Ftd>\u003Ctd>A paid ad above the real result routes you to a pixel-perfect copy on a lookalike domain\u003C\u002Ftd>\u003Ctd>The domain — never the design\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd>Fake airdrop claim\u003C\u002Ftd>\u003Ctd>“You are eligible” for a token you vaguely remember; the claim page wants a connection and a signature\u003C\u002Ftd>\u003Ctd>Unsolicited eligibility plus a countdown\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd>DM “support”\u003C\u002Ftd>\u003Ctd>Minutes after you complain publicly, an official-looking account offers help via a “validation” form\u003C\u002Ftd>\u003Ctd>Real support never DMs first\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd>Urgency and fear hooks\u003C\u002Ftd>\u003Ctd>“Your wallet will be suspended”, “migration closes tonight” — panic is the product\u003C\u002Ftd>\u003Ctd>A deadline you cannot find on any official channel\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd>Poisoned QR codes and calendar invites\u003C\u002Ftd>\u003Ctd>Auto-added calendar events or QR stickers at conferences route you straight to the clone\u003C\u002Ftd>\u003Ctd>You never asked for it\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\n\n\u003Ch2>How do fake crypto sites trick people?\u003C\u002Fh2>\n\u003Cp>Clone sites work because design is free to copy. An attacker mirrors a real dapp or wallet site — logo, layout, connect button — in minutes, hosts it on a lookalike domain, then buys a search ad so the fake sits \u003Cem>above\u003C\u002Fem> the original in results, or seeds the link in replies, DMs and fake airdrop posts. Ad-delivered clones are effective precisely because clicking the top search result feels like diligence rather than risk. The page behaves perfectly right up to the moment it asks you to sign or “verify” — how a site looks tells you nothing about what it is. Only the domain does.\u003C\u002Fp>\n\n\u003Ch2>How can you tell if a URL is fake?\u003C\u002Fh2>\n\u003Cp>The domain is the one thing an attacker cannot copy exactly — so they get close and count on you not looking. Four checks catch nearly all of it:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Read right to left.\u003C\u002Fstrong> The registered name sits immediately before the top-level domain (or public suffix — for country domains like .co.uk, it is the part before .co.uk): in app.wallet.com.claim-rewards.io, the real site is claim-rewards.io — everything left of it is decoration.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Hunt for swapped characters.\u003C\u002Fstrong> An rn standing in for m, a 1 standing in for an l, a 0 for an o, or a lookalike letter borrowed from another alphabet — one character is all a clone needs. Domain names are case-insensitive, so the trick is never capitalisation; it is shapes. Browsers often expose the borrowed-alphabet version by showing the address in its raw xn--… punycode form instead of the word you expected, which is itself a reason to stop.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Distrust the route, not just the address.\u003C\u002Fstrong> Never enter a financial site through an ad, a DM, a QR code or a calendar invite. Bookmark official sites once, from a source you trust, and arrive only via the bookmark.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Ignore the padlock.\u003C\u002Fstrong> HTTPS proves the connection is encrypted, not that the site is honest — phishing sites carry valid certificates too.\u003C\u002Fli>\n\u003C\u002Ful>\n\n\u003Ch2>The one rule that defeats most of it\u003C\u002Fh2>\n\u003Cp>Whatever the wrapper, nearly every campaign converges on the same two asks: type in your recovery phrase, or sign something on a page you did not navigate to yourself. One rule therefore does most of the defensive work: \u003Cem>no legitimate party will ever ask for your seed phrase\u003C\u002Fem>. Not a wallet team, not an exchange, not a “sync” or “validation” tool, not an airdrop claim. As \u003Ca href=\"\u002Fblog\u002Fwhat-is-a-seed-phrase\">what is a seed phrase\u003C\u002Fa> explains, the phrase \u003Cem>is\u003C\u002Fem> the keys — anyone holding those words holds the wallet, permanently and irreversibly. The instant they are requested, you are not in a support conversation; you are in a robbery.\u003C\u002Fp>\n\n\u003Ch2>Verify the channel, not the message\u003C\u002Fh2>\n\u003Cp>Phishing succeeds by borrowing a channel you trust for a moment — an inbox, a feed, a search page. The counter-habit is simple: \u003Cem>never act on the channel the message arrived on\u003C\u002Fem>. If “support” DMs you, close the DM and open a ticket from the project's official site. If an email says your wallet needs migrating, go to your bookmark and look for the announcement there. If an airdrop is real, it will be posted on the channels you already follow — not the ones that found you.\u003C\u002Fp>\n\u003Cp>Urgency exists to prevent exactly this check. A real deadline survives a ten-minute verification; a fake one is designed not to. These habits slot into a broader routine — signing discipline, approval hygiene, key storage — covered in \u003Ca href=\"\u002Fblog\u002Fcrypto-wallet-security-best-practices\">crypto wallet security best practices\u003C\u002Fa>.\u003C\u002Fp>\n\n\u003Ch2>What should you do if you clicked a phishing link?\u003C\u002Fh2>\n\u003Cp>Triage by what happened \u003Cem>after\u003C\u002Fem> the click — the click alone is rarely the damage.\u003C\u002Fp>\n\u003Col>\n\u003Cli>\u003Cstrong>You clicked and did nothing else.\u003C\u002Fstrong> Close the tab. A modern browser visiting a page does not, by itself, expose your keys.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>You connected your wallet but signed nothing.\u003C\u002Fstrong> Connecting reveals your address and lets the site propose transactions — it does not grant access to funds. Disconnect the site in your wallet settings and move on.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>You signed a transaction or message.\u003C\u002Fstrong> Assume something was granted: review your wallet's recent activity and revoke any token approvals you do not recognize. Be aware that an off-chain signature — a permit-style message — leaves no trace in your transaction history until the attacker actually uses it, so an empty history is not proof that nothing was authorized; if the wallet holds anything you cannot afford to lose, move those assets to a fresh wallet as well. The drainer post above explains exactly what those signatures authorize.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>You entered your seed phrase.\u003C\u002Fstrong> The wallet is compromised and cannot be repaired — generate a fresh wallet on a clean device and move everything to it immediately. Attackers automate sweeps of freshly phished phrases; speed is the only lever you have.\u003C\u002Fli>\n\u003C\u002Fol>\n\n\u003Ch2>How WATS fits in\u003C\u002Fh2>\n\u003Cp>\u003Ca href=\"\u002Fsecurity\">WATS\u003C\u002Fa> is fully non-custodial across all four of its products — the Chrome Extension, the Mobile App, the Hot Wallet and the NFC Metal Card. You hold the keys, and WATS never holds a key. That is what makes the one rule trivial to apply: there is no WATS-side account for a fake “support agent” to unlock, no WATS-side copy of your recovery phrase to “re-verify”, and no situation in which WATS needs those words at all. Any message that asks for them while wearing WATS branding is phishing by definition, however well the logo is copied.\u003C\u002Fp>\n\u003Cp>It is worth being precise about what that does and does not buy you, because overselling it is how people get hurt. Non-custody is not an anti-phishing feature: self-custody means the defence is your habits, and a phrase typed into a clone site is gone no matter which wallet generated it. What non-custody removes is an entire social-engineering surface — the “account recovery”, the “compliance unlock”, the “frozen balance” story — because those pretexts only work where a company is holding something on your behalf. The WATS \u003Ca href=\"\u002Fnfc-card\">NFC Metal Card\u003C\u002Fa> belongs to the same clarification: it stores no private keys and no seed phrase, it tap-authenticates to keys that stay inside the WATS apps, and each card carries a unique ID paired to exactly one device. So anyone asking you to “activate”, “register” or “validate” a card by typing your recovery phrase into a page is running a scam, not a setup step.\u003C\u002Fp>\n\u003Cp>The practical version of all of this is short. Install WATS from the official \u003Ca href=\"\u002Fdownload\">download page\u003C\u002Fa> rather than from an ad, a DM or a QR code you were handed, bookmark that address the first time, and enter through the bookmark every time afterwards. Write down the phrase WATS generates, keep it offline, and treat every request for it — in any channel, in any wording, from anyone — as the attack it is. Those three habits, plus the right-to-left domain check, are what actually keep a self-custodial wallet intact.\u003C\u002Fp>",[10,13,16,19,22],{"q":11,"a":12},"Will a legitimate crypto company ever ask for my seed phrase?","No — never, under any circumstances. The seed phrase is the master key that regenerates every private key in your wallet, and no wallet team, exchange, support agent or airdrop needs it for anything: support issues are solved in software, not by taking custody of your keys. Any form, DM, pop-up or “validation tool” that requests those words is a phishing attempt, full stop, regardless of how official it looks.",{"q":14,"a":15},"Will WATS ever ask for my seed phrase?","No. WATS will never ask for your seed phrase, in any channel, for any reason. WATS is fully non-custodial — you hold the keys and WATS never holds a key — so there is no account to unlock, no balance to release and no support action that could require those words. Your phrase is only ever typed into your own WATS app during setup or recovery. Anyone contacting you as WATS and asking for the phrase, or directing you to a page that asks for it, is running a phishing attack, and the correct response is to stop and navigate to the official site yourself rather than replying.",{"q":17,"a":18},"How can I check if a crypto website is real?","Read the domain right to left: the registered name sits directly before the top-level domain (or public suffix — for country domains like .co.uk, it is the part before .co.uk), so app.wallet.com.claim-site.io is claim-site.io, not wallet.com. Check for swapped characters like rn standing in for m. Never arrive through an ad, DM or QR code — navigate from a bookmark you saved from an official source. A padlock only proves encryption; phishing sites carry valid certificates too.",{"q":20,"a":21},"Does using a non-custodial wallet like WATS protect me from phishing?","Partly, and it is important to know which part. WATS being fully non-custodial removes the pretexts that phishing leans on hardest — there is no WATS-held account to “recover”, “unlock” or “verify”, and WATS never holds a key or needs your recovery phrase — so any message using that script is immediately identifiable as fake. What it does not do is stop you from typing your phrase into a clone site or signing a malicious transaction; in self-custody those decisions are yours alone. The wallet removes the lie; your habits — bookmarks, domain checks, reading what you sign — stop the theft.",{"q":23,"a":24},"What should I do if I entered my seed phrase on a phishing site?","Treat the wallet as permanently compromised — the phrase cannot be un-shared, and changing a password does nothing because the phrase is the keys. Create a brand-new wallet with a freshly generated seed phrase on a clean device, installing the app from an official source you navigated to yourself rather than any link in the message that caught you, then move every asset to the new addresses immediately; attackers automate sweeps of phished phrases, so speed matters. Afterwards, review anything else the old phrase protected and retire it everywhere.",1786059328302]