Look-alike Domains and Search Ads
Look-alike Domains and Search Ads is best treated as a verification point rather than a background detail.
Practical checks for look-alike domains and search ads
Phishing often relies on look-alike domains, search ads, fake support, fake airdrops, and urgency. Do not judge authenticity by branding alone. Verify the domain and source, read the actual request, and reject any demand for recovery credentials.
Seed phrases and private keys are sensitive recovery and control credentials. Keep them under your own control and do not submit them to forms, chats, email, screenshots, or remote-support sessions. Requests framed as verification, synchronization, or recovery are not a valid reason to disclose them.
The security of the phone or computer affects whether the wallet and signing screen can be trusted. Keep the operating system updated, use a strong device lock, limit remote-control and screen-sharing access, and be cautious with public Wi-Fi, shared computers, clipboards, and unknown applications.
Fake Support
When working with fake support, focus on what can be confirmed before you approve an action.
Practical checks for fake support
For troubleshooting, collect non-sensitive facts first: the network, public address, transaction hash, and visible error message. Seed phrases, private keys, and verification codes are not support credentials, and unknown helpers should not be given remote control of a device.
Phishing often relies on look-alike domains, search ads, fake support, fake airdrops, and urgency. Do not judge authenticity by branding alone. Verify the domain and source, read the actual request, and reject any demand for recovery credentials.
Seed phrases and private keys are sensitive recovery and control credentials. Keep them under your own control and do not submit them to forms, chats, email, screenshots, or remote-support sessions. Requests framed as verification, synchronization, or recovery are not a valid reason to disclose them.
Fake Airdrops and Rewards
The practical value of understanding fake airdrops and rewards is that it reduces ambiguity during real wallet use.
Practical checks for fake airdrops and rewards
Phishing often relies on look-alike domains, search ads, fake support, fake airdrops, and urgency. Do not judge authenticity by branding alone. Verify the domain and source, read the actual request, and reject any demand for recovery credentials.
Seed phrases and private keys are sensitive recovery and control credentials. Keep them under your own control and do not submit them to forms, chats, email, screenshots, or remote-support sessions. Requests framed as verification, synchronization, or recovery are not a valid reason to disclose them.
The security of the phone or computer affects whether the wallet and signing screen can be trusted. Keep the operating system updated, use a strong device lock, limit remote-control and screen-sharing access, and be cautious with public Wi-Fi, shared computers, clipboards, and unknown applications.
Clipboard and Address Replacement
For clipboard and address replacement, the safest workflow separates what the interface shows from what the blockchain actually records.
Practical checks for clipboard and address replacement
A wallet address is generally public, but that does not make verification optional. After copying an address, compare key characters, confirm the network, and check the asset being sent. For a new destination, a small test can be reasonable when fees and transaction size justify it.
Phishing often relies on look-alike domains, search ads, fake support, fake airdrops, and urgency. Do not judge authenticity by branding alone. Verify the domain and source, read the actual request, and reject any demand for recovery credentials.
Seed phrases and private keys are sensitive recovery and control credentials. Keep them under your own control and do not submit them to forms, chats, email, screenshots, or remote-support sessions. Requests framed as verification, synchronization, or recovery are not a valid reason to disclose them.
Response Principles
Use response principles as a checkpoint: identify the network, the intended action, and the information you can independently verify.
Practical checks for response principles
Phishing often relies on look-alike domains, search ads, fake support, fake airdrops, and urgency. Do not judge authenticity by branding alone. Verify the domain and source, read the actual request, and reject any demand for recovery credentials.
Seed phrases and private keys are sensitive recovery and control credentials. Keep them under your own control and do not submit them to forms, chats, email, screenshots, or remote-support sessions. Requests framed as verification, synchronization, or recovery are not a valid reason to disclose them.
The security of the phone or computer affects whether the wallet and signing screen can be trusted. Keep the operating system updated, use a strong device lock, limit remote-control and screen-sharing access, and be cautious with public Wi-Fi, shared computers, clipboards, and unknown applications.
Final check before you finish
- The address, network, and asset match the intended destination
- The signature or approval matches the action you intended
- No seed phrase, private key, or verification code has been shared