← GlossarySecurity
What Is Crypto Phishing? How to Spot and Avoid It
Crypto phishing is fraud that impersonates a wallet, exchange or support team — using fake websites, messages or apps — to trick you into handing over your keys or approving a transaction that drains your funds.
Key takeaways
- No legitimate wallet or support team will ever ask for your private key or recovery phrase.
- Fake sites and apps copy real ones closely; check the URL every time.
- Urgency ('your account will be locked') is the scammer's main tool.
- Bookmark the real site, verify before connecting, and never enter recovery information into a webpage or chat.
Common phishing tactics
- Fake wallet or exchange sites that look identical to the real one but live on a slightly different domain, often promoted through ads or search results
- Impersonation on social media and chat — someone posing as "support" who DMs you first
- Fake airdrops and giveaways that ask you to connect a wallet or 'verify' with your keys
- Malicious approvals — on smart-contract chains, signing a transaction that grants a scam contract permission to spend your tokens
- Counterfeit apps in app stores or shared as install links
Why it works
Phishing exploits urgency and trust, not technical flaws. A message that says your funds are at risk pushes you to act before thinking. Any legitimate service can be impersonated in a convincing way.
A simple routine
- Bookmark the real wallet URL and always use the bookmark
- Never type recovery information into a website, form or chat — a real wallet only ever asks for it during a restore inside the app
- Ignore unsolicited DMs claiming to be support; real support won't contact you first asking for credentials
- Read what you're signing — if a transaction gives a contract broad access, don't approve it
- Install only the official app from the official store link
If you've been phished
Move any remaining funds to a new wallet with fresh keys immediately, revoke any token approvals, and don't trust the compromised device or keys again.
Red flags worth memorizing
Real services do not create urgency, do not ask for recovery information, and do not contact you first to "fix" your wallet. If a message combines a deadline, a link and a request to connect or sign something, stop and go to the real site through your own bookmark instead. When in doubt, wait a day: a scam depends on you not doing that.
Example
You get a message saying your wallet is 'suspended' and to 'verify' at a link. The link goes to a page that looks like your wallet and asks for your recovery information. Entering it gives the attacker full control of your funds within minutes.
Put it into practice
Use the real wallet, and lock it down
The official Scrypt Wallet lives at wallet.scryptwallet.io and in the Android app. Turn on passkey login and PIN-protected sends, and remember: Scrypt Wallet support will never ask for your keys.
Open the official wallet Get Scrypt for AndroidFrequently asked questions
Will Scrypt Wallet ever ask for my recovery phrase or key?
No. Scrypt Wallet support will never ask for your recovery phrase or private key — anyone who does is attempting a scam.
How can I tell a fake site from the real one?
Check the full domain carefully, use a bookmark rather than a search result or link, and treat any request for recovery information as a red flag.
Can stolen crypto be recovered?
Almost never. Blockchain transactions are irreversible, so prevention is the only reliable defence.
Written by the Scrypt Wallet team · Updated 2026-09-29. General education, not financial, tax or legal advice.