Most self-custody losses do not start with a broken hardware chip. They start with a link, a search ad, a fake app, or a chat that looks helpful. You click. You type. You sign. Then the coins move.

This is a practical checklist for phishing: when someone pretends to be your wallet, exchange, or support so you hand over a seed or approve a harmful signature. It pairs with seed phrase hygiene, token approvals, and sending safely.

Not financial advice. If you already entered a seed or signed something you did not understand, stop using that wallet for new value and follow the recovery steps at the end. Practice checks on empty wallets first.

What phishing looks like in crypto

In ordinary banking, phishing often steals a password you can reset. In self-custody, two outcomes are common:

  1. Seed theft. A fake site, app, popup, or “support agent” asks for your 12 or 24 recovery words. Once they have the phrase, they own every address it derives. There is no chargeback.
  2. Signature / approval theft. You never type the seed. You connect a real wallet to a fake site and approve a transfer, a permit, or an unlimited token allowance. The drain happens on-chain after you click Confirm.

Both start the same way: urgency, official branding, and a request that feels routine. MetaMask’s safety guide is blunt: only two real products (extension and mobile), no free-token giveaways, and almost never a need for your Secret Recovery Phrase outside setup or restore.

Common phishing paths into a self-custody walletFake downloadapp / extensionLookalike sitetyposquat URLFake supportchat / email / DMMalicious dappWalletConnectSeed phrase enteredfull wallet lossHarmful signaturedrain / approvalStop before either box: verify the source, then read what you sign

Rule zero: never enter your seed on a website

  • No legitimate wallet website needs your recovery phrase to “verify,” “unlock,” “sync,” or “claim.”
  • Ledger support states the same line vendors repeat for a reason: they will never ask for your 24 words.
  • MetaMask lists the only normal times you type a Secret Recovery Phrase: first-time confirmation that you wrote it down, wallet restore, or password reset flows inside the real extension or app.

If a page, email, PDF, Google Form, or chat asks for the words, close it. Do not paste “just one word to check.” Do not photograph the card for support.

Download only from sources you already trust

Attackers buy ads and rank fake download pages above the real one. They clone logos. They ship lookalike extensions and store apps.

Browser wallets (example: MetaMask)

  1. Type the official domain yourself, or open a bookmark you created on a clean day.
  2. Start at metamask.io/download and use only the Install path from there, or the official Chrome / Firefox store listing linked from that page (MetaMask’s verify guide).
  3. Ignore sponsored search results above the organic listing. Read the URL character by character: metamask.io, not metamask-wallet.app or a long subdomain chain.
  4. After install, pin the extension. Open it from the browser toolbar, not from a site button that claims to “launch wallet.”

Hardware companion apps (example: Ledger)

  1. Download desktop software only from the manufacturer’s site (for Ledger, paths under ledger.com).
  2. On mobile stores, check the publisher name, not only the icon. Real Ledger iOS listings are published by Ledger SAS (or the current legal name on ledger.com). A pretty icon from an unknown developer is a hard stop.
  3. Never buy a “pre-configured” device that arrives with a seed card already filled in. Generate the seed yourself on the device.

Mobile wallets in general

  1. Open the App Store or Play Store from the OS, not from a chat link.
  2. Confirm publisher, install count, newest reviews, and update date.
  3. Prefer the project’s official download only after the domain matches its verified docs.
  4. A wallet that demands your seed to “import your balance” before you chose Restore is a red flag.

Clone apps still appear in official stores. Kaspersky’s reporting on fake crypto apps stresses publisher verification on top of the store listing.

Check the URL before you connect

  1. Bookmark official domains for every wallet, exchange, and dapp you use monthly. Next time, open the bookmark. Do not re-search.
  2. Read the full host. app.uniswap.org is not the same family as uniswap-app.org or uniiswap.com. Extra hyphens, swapped letters, and odd country TLDs are classic.
  3. Prefer HTTPS, but treat the lock icon as necessary, not sufficient. Phishing sites use valid certificates too.
  4. Watch for MetaMask phishing warnings. MetaMask maintains a community blocklist (eth-phishing-detect) and shows deceptive-site alerts on known bad domains. If the wallet flashes red, leave.
  5. Never trust a link from cold outreach. Emails, Telegram DMs, WhatsApp groups, and “airdrop claim” posts are the delivery system. Chainalysis still treats seed-phrase phishing as a primary loss path.

In Latin America, much of this arrives over WhatsApp and Telegram: “exchange support,” “your transfer is stuck,” “verify in 10 minutes or funds freeze.” Apply the same reflex banks already taught: urgent chat support can be fake. Real support does not DM first and never needs your seed.

Fake support: the script that repeats

TellWhat to do
They messaged you firstIgnore. Open the official site yourself and use in-product support only.
They want a screen shareRefuse. Scammers watch you open the wallet, then guide a drain.
They want the seed “to restore access”End the chat. That is theft.
They send a Google Form / PDF / “security report”Close it. Enter nothing.
They create urgency (“blocked in 1 hour”)Slow down. Urgency is the product.

WalletConnect and connect prompts

WalletConnect lets many mobile wallets talk to a website. It is not automatically safe. A real wallet can still connect to a fake domain.

  1. Read the domain in the wallet prompt. Compare it to the address bar on the site you intended.
  2. Many wallets surface WalletConnect Verify states: Domain match, Unverified, Mismatch, or Threat. Treat Mismatch and Threat as refuse. Treat Unverified as “slow down and verify another way.”
  3. Reject sessions that request broad permissions you did not initiate.
  4. After you finish, disconnect the session in the wallet. Disconnect is not the same as revoking token approvals, but it closes the live bridge.

Never scan a WalletConnect QR code from a DM or an unsolicited flyer.

Read the signature before you confirm

  1. Genuine wallet popups follow your click. MetaMask notes that a real extension does not pop up unprompted the moment a page loads. A random full-screen “verify wallet” form is not your extension.
  2. Demand context. Destination, asset, amount, network, and fee should be readable. A blank “Sign” with no details is a hard no.
  3. Watch for unlimited approvals on tokens you care about. Prefer a limited amount when the UI allows it. Clean old allowances later with the approvals guide.
  4. Hardware wallets help only if you read the device screen. If the computer shows one thing and the device another, abort.
  5. No free mint needs your seed. Airdrops that require recovery words are fake.

A five-minute pre-sign checklist

  1. Did I open this site or app from a bookmark or a typed official URL?
  2. Does the publisher / domain match what I already trust?
  3. Is anyone asking for my seed phrase? If yes, stop.
  4. Does the wallet show a clear domain and a Verify state I accept?
  5. Can I explain, in one sentence, what this signature does?
  6. Am I under time pressure from a chat or ad? If yes, pause overnight.

If any answer fails, close the tab. The blockchain will still be there tomorrow. Your coins may not be if you rush.

If you already typed a seed or signed something bad

Act in order. Do not wait for “support” that contacted you.

  1. Assume the seed is burned if you entered it anywhere networked: website, form, chat, cloud photo, shared screen. Create a new wallet on clean hardware or a freshly installed official app. Generate a new seed. Never reuse the compromised phrase.
  2. Move remaining funds to the new wallet from a machine you trust. Prefer small test sends first (send safely).
  3. Revoke token approvals on the old address if assets remain, then still migrate. Revoking does not fix a stolen seed.
  4. Disconnect WalletConnect sessions and remove unknown browser extensions.
  5. Document the URL, time, and tx hashes; report the domain via your wallet when possible.
  6. If funds already left, treat cold-call “recovery” firms as a second scam wave. On-chain theft is usually final.

Build habits that survive a busy week

  • Keep a short list of official domains (wallet, two exchanges, one explorer per chain).
  • Update wallet apps only through those same paths.
  • Practice a seed restore on a spare device before you need it (seed phrases guide).
  • Teach household members: nobody legitimate asks for the words.

Self-custody removes the bank as middleman and as fraud desk. Verify the source first. Read the prompt second. Sign last, or not at all.