Open menu

Wallet scam red flags: pause before you sign

A wallet scam red flag is a warning in a chat, ad, token, QR code, or signature prompt that means you should stop. In 2026 the steal usually looks like help: fake Ledger or MetaMask support, a “verify wallet” page, a WalletConnect QR from a stranger, or a claim button. This lesson is a beginner checklist with examples you can match to a real wallet prompt. If even one red flag is present, stop. On-chain transfers are usually irreversible.

TL;DR

Never type a seed phrase or private key into a website or chat. Type official URLs yourself. Treat DMs, airdrop claims, and unsolicited “support” as hostile. Read every wallet prompt in plain language before you confirm — especially Permit, Permit2, setApprovalForAll, and unlimited allowances. Keep long-term funds in a wallet you do not use for experiments.

Why a checklist beats a panic search

People searching “how to protect seed phrases,” “common crypto phishing red flags,” or “how to avoid crypto phishing scams” are usually already mid-scare: a pop-up, a Telegram DM, a token that appeared overnight, or a page that says the wallet will be frozen. Logos and domains change. The pressure script does not.

This page is the Security pillar’s pause-and-compare tool. For the recovery-word rules themselves, read seed phrase safety. For the wider scam catalog, see crypto scams and phishing. For the signature that can move tokens, see wallet approvals and token permissions.

The 30-second check before you sign

Use this every time a wallet opens a prompt. Say each line out loud if you need to slow down.

  1. Who opened this? Did you type the URL or open a bookmark, or did a DM, ad, search result, QR code, or unknown token send you here?
  2. Does anyone want secrets? Seed phrase, private key, “backup code,” remote-desktop access, or a photo of your recovery card → close everything.
  3. What asset moves? Can you name the token, the amount, and the destination in one short sentence? If not, reject.
  4. Is this spending permission? Words like approve, allowance, Permit, Permit2, setApprovalForAll, unlimited, or max mean a contract may spend later — not a harmless “login.”
  5. Is this your savings wallet? If the answer is yes and the app is new to you, reject and switch to a small experiment wallet first.

If any answer fails, you do not need a second opinion from a stranger in chat. Reject, close the tab, and come back only from a bookmark you saved on a calm day.

What are common crypto phishing red flags?

Beginners often want a short list they can compare to a live page, DM, or wallet prompt. These patterns show up repeatedly in 2026 consumer guidance from the U.S. FTC and official wallet makers:

  • Recovery words requested online. No brand needs your seed phrase in a browser tab, form, or chat.
  • Pressure timers and freeze warnings. Real maintenance does not require secrets before a countdown ends.
  • Links from ads, DMs, or search results. Type the official domain yourself or use a bookmark you saved earlier.
  • Unsolicited support after you posted a problem. Multiple fake agents arriving at once is a known 2026 pattern.
  • “Verify wallet” or surprise claim buttons. Connecting usually only shares an address; the signature that follows is the risk.
  • Wallet prompts that do not match the button. A “log in” click should not move tokens or set unlimited allowances.
  • WalletConnect QRs pasted in chat. Only start a session from a URL you typed yourself.
  • Unexpected SMS / iMessage “verify now” links. Open the brand from a bookmark — not from the text.
  • Sponsored or #1 search results for wallet downloads. Ad rank is not authenticity. Type the official domain yourself.

If two or more apply, treat the page as hostile even if the logo looks perfect. Use the ten-item list below for edge cases like address poisoning and paid recovery pitches.

How to protect a seed phrase (the short answer)

A seed phrase (often 12 or 24 words) can recreate the keys that control a self-custody wallet. Anyone who has those words can usually move the funds. That is why official wallet makers tell you never to enter the phrase on a computer or phone except during a restore you started yourself.

MetaMask’s Secret Recovery Phrase guide is explicit: support will not ask for it, and you should not type it into a website. Ledger’s recovery-phrase article says the same for hardware wallets: the phrase stays offline; a “firmware” or “sync” page that wants the words is the attacker.

Practical beginner rules:

  • Write the words on paper or metal. Do not screenshot them or paste them into chat, email, or a notes app that syncs to the cloud.
  • Only enter the phrase when you opened the official wallet app or device restore flow — never after a link from a DM, ad, or search result.
  • If a site, bot, or “agent” asks for the words, close it. Then follow seed phrase safety for storage, not this chat.

Ten red flags to check every time

  1. Anyone asks for the seed phrase, private key, or “backup code.” Example: a chat that says “paste your 12 words so we can sync MetaMask / Phantom / Trust Wallet.” Real support cannot restore your self-custody wallet from those words, and does not need them.
  2. Urgency plus a countdown. Example: “Your wallet will be liquidated in 15 minutes unless you verify.” Phishing pages still use timers, red banners, and fake security alerts. Legitimate network events do not require you to paste secrets.
  3. A link you did not type. Example: an X/Twitter ad, Google ad, SMS, or email that looks like Ledger, Trezor, Coinbase Wallet, or a popular browser-wallet brand. Type the brand’s site from a bookmark you saved on a calm day.
  4. A DM that starts after you posted a problem. Example: you ask in Discord why a swap failed; three “official support” accounts message you with a ticket link. Support that arrives uninvited is a classic pattern in 2026.
  5. “Connect and sign to claim.” Example: a surprise airdrop, mint, or “refund” page. Connecting often only shows your address. The dangerous step is the next signature: a permit, setApprovalForAll, or a transaction you cannot explain in one sentence.
  6. The wallet prompt does not match the button you clicked. Example: the site says “log in,” but the wallet asks to transfer tokens, increase allowance, or sign a typed-data message with a spender address you do not recognize.
  7. A lookalike destination address. Example: you copy an address you used last week, but the first and last characters match while the middle is different (address poisoning). Always check more than the first four and last four characters, especially on mobile.
  8. A brand-new token sitting in the wallet. Example: an airdropped token named after a real project. Opening a random “claim” site from the token’s website field is a common drainer path. Ignore unknown tokens until you verify the project from a source you already trust.
  9. Software you did not intend to install. Example: a “wallet fixer,” remote-desktop tool, or browser extension pushed in a video call. Clipboard-stealing malware still swaps addresses after you copy them. If an address changes between copy and paste, stop.
  10. A paid “recovery” or “whitelist” service after a scare. Example: someone who already tricked you now offers to get the funds back for a fee, or to “clear a blacklist.” Guaranteed recovery is a second scam stacked on the first. The U.S. FTC cryptocurrency scam briefing treats recovery-for-a-fee pitches as a known follow-on fraud.
This is not investment advice

This lesson explains common attack patterns so you can avoid irreversible mistakes. It does not recommend coins, wallets as investments, or any product. If you already signed a malicious transaction, treat remaining funds as at risk and move them only to a wallet and address you created yourself.

How to read a wallet prompt like a receipt

Most beginner losses in 2026 are not “the blockchain was hacked.” Someone approved a permission they did not understand. Treat the wallet UI as a receipt, not a speed bump.

  • Network. Confirm you are on the chain you intended (for example Ethereum vs a lookalike test network name in the UI).
  • Action type. Send / swap should name an asset and amount. “Sign message,” “Permit,” or “typed data” may still authorize spending later.
  • Spender or contract. If a contract address appears, ask whether you navigated to that app yourself today.
  • Allowance. Unlimited or a huge number next to a token you hold is a red flag for a new or unfamiliar site.
  • Your role. Connecting shares an address. Approving or signing can move value. Reject anything you cannot explain to a friend in one sentence.

For the longer explanation of allowances and revokes, use wallet approvals and token permissions.

How to avoid crypto phishing scams

Phishing is a fake page or message that impersonates a brand you already trust. The goal is not to “hack Bitcoin.” The goal is to get you to type a secret or sign a permission. The FBI Internet Crime Complaint Center (IC3) is the U.S. reporting desk for internet crime; consumer guidance from the FTC (linked above) matches the same beginner rule: never give recovery words or remote access to a stranger.

A calm 2026 routine:

  1. Do not click wallet or exchange links from ads, DMs, or email. Open a bookmark you created earlier, or type the domain yourself.
  2. Check the exact domain character by character. Extra words, swapped letters, or a different ending (.app vs .com) are enough.
  3. If a page wants a seed phrase, you are on the wrong site. Close it.
  4. If a page wants a signature, read the wallet UI. If you cannot say what asset moves, to whom, and why, reject it.
  5. Use a small experiment wallet for new apps. Keep savings elsewhere — see hot wallets vs cold wallets.
  6. Never scan a WalletConnect QR from a stranger, a screenshot in chat, or a “support” ticket. Only start WalletConnect from a site you typed yourself.

2026 examples, in plain language

Fake hardware-wallet “firmware” pages. You search for a firmware update, click an ad, and land on a page that asks you to enter recovery words to “re-pair” the device. A hardware wallet’s job is to keep those words off the internet. If a website wants them, the website is the attacker.

Drainer sites dressed as mints and claims. A page looks like an NFT drop or a points dashboard. You connect. The prompt asks for unlimited token approval, a Permit-style signature, or several confirms in a row. One rushed “confirm” can let a contract empty the approved tokens. Slow down and read how approvals work before you experiment with new apps.

Address poisoning after a real transfer. You send USDC to a friend. Later, a tiny incoming transfer from an address that looks like theirs appears in history. Next time you copy “the last address,” you paste the attacker’s. Check the full string, or use a saved contact / address book in the wallet if it offers one.

WalletConnect QR bait. Someone in Discord or Telegram pastes a QR and says “scan to sync support.” Scanning connects your wallet to their session. Only start a WalletConnect flow from a URL you typed, and cancel unknown sessions in the wallet settings.

QR-code swap at the last second. You are paying someone in person or scanning a poster. The scammer covers the real QR with another, or a malicious overlay in a screenshot. Confirm the human-readable address on your own screen, not on theirs.

Fake apps and “security extensions.” An ad or DM sends you to an app-store listing or a Chrome/Firefox add-on with a near-identical name. The fake app can show a normal home screen and still exfiltrate keys or swap the clipboard. Install wallet software only from a URL you typed, then confirm the publisher name against the brand’s own help site.

Typed-data prompts that do not look like a send. The button said “verify” or “log in,” but the wallet shows a Permit, Permit2, setApprovalForAll, or a blob of hex you cannot explain. Reject it. Connecting is not the same as spending. Spending needs a signature you understand.

AI-generated “support” voices and chatbots. Attackers pair voice-clone tools with social-media monitoring: after you post about a failed transaction, an automated bot can find it, open a DM, and arrange a voice call that sounds like an official support agent. The rule does not change — real support will never ask for a seed phrase, private key, or remote-desktop access, no matter how realistic the voice sounds. Consumer agencies still treat remote-access and recovery-word requests as fraud signals — see the U.S. FTC cryptocurrency scam briefing.

Deepfake “founder” claim events. A short video clip or live-stream overlay can show a recognizable face announcing a “limited claim window” with a countdown. The page behind the button still runs a standard drainer. Treat any unexpected claim URL as hostile even when the intro video looks convincing — the video is the lure, not the proof.

SMS / iMessage “wallet security alert.” A text claims your MetaMask, Ledger, Phantom, or exchange account will be locked unless you “verify” within minutes. The link often uses a lookalike domain or a shortened URL. Type the brand’s site yourself or open a bookmark — never the message link. The FTC’s cryptocurrency scam guidance treats unexpected security messages that demand immediate action as a classic social-engineering pattern.

Sponsored search / “top result” wallet downloads. You search “MetaMask download,” “Ledger Live,” or “Phantom wallet” and click the first result or a bright Sponsored label. The page looks official, but the domain is one character off — or it ships a lookalike installer/extension. Type the brand domain from memory or open a bookmark you saved earlier; do not trust ad rank as proof of authenticity.

What to do when a flag appears

What you saw Safe next step Unsafe next step
Request for seed phrase or private key Close the tab or chat. If you already typed words into a site, assume the wallet is burned and move funds from a device you still control to a new wallet you created yourself. Finish “verification,” screenshot the words, or send them to anyone claiming to be support.
Unexpected airdrop or claim page Ignore the token. Verify the project later from a bookmark or official account you already follow. Use a throwaway wallet if you still want to inspect it. Connect your main wallet and sign because the UI looks official.
Wallet prompt you cannot explain Reject. Screenshot the prompt for your own notes. Compare it with the button you clicked. Approve because a countdown is running.
Lookalike address Send a tiny test amount first, or re-copy from a source you typed yourself. Send the full amount because the first and last characters “look right.”
Unsolicited support after you posted a problem Ignore the DM. Open the project’s help from a bookmark. Never install remote-desktop tools for “wallet repair.” Share a screen, paste a phrase, or follow their “ticket” link.
WalletConnect QR from chat or “support” Do not scan. Start only from a site you typed. Disconnect unknown sessions in wallet settings. Scan to “sync” with a stranger’s ticket.
Voice or video “support” that sounds or looks perfectly real Hang up. Open help only from a bookmark you already trust. Ask whether they need a seed phrase, private key, or remote desktop — if yes, it is fraud. Install their remote tool, read recovery words aloud, or open a claim link from the call.
Deepfake “founder” video with a timed claim button Ignore the clip. Treat the URL as a drainer until you verify the project from a bookmark you typed yourself. Connect a savings wallet because the face and countdown feel urgent.
SMS or iMessage “verify now or lose access” Do not tap the link. Open the brand from a bookmark or typed URL. Real wallet makers do not unlock accounts via text links. Tap the message, enter a seed phrase, or install an “urgent security” app from that thread.
Sponsored or #1 search result for a wallet download Ignore ad rank. Type the official domain or use a bookmark. Confirm the publisher name against the brand’s own help site before installing. Click the first result because it “looks official,” then install the app or extension from that page.

A calmer beginner setup

Keep two mental buckets. Savings: funds you are not using this week, preferably with a backup you understand — see hot wallets vs cold wallets. Spending / experiments: a small wallet you use to try apps, claims, and new sites. If that wallet is drained, the loss is limited.

If addresses and keys still feel abstract, start with keys and wallet addresses. Live prices and tickers do not tell you whether a site is safe — they only show market data — but you can open live rates from this site without connecting a wallet at all.

The Education hub at /education and the Security pillar are the right next clicks after this checklist. Bookmark those, not random search ads.

If you already clicked or signed

  1. Do not send more funds to “unlock,” “tax,” or “gas refund” addresses.
  2. If you only opened a page, close it. Change passwords on email if you typed them on the same device.
  3. If you connected and signed, treat remaining assets as exposed. From a clean device, move what you still control to a newly created wallet whose seed phrase never touched the phishing page.
  4. Review and revoke token approvals on the chain you used, using a revoke tool you navigated to yourself — not a link from the scammer. See wallet approvals.
  5. If an exchange account was involved, use that exchange’s official app or a URL you typed, then lock sessions and turn on stronger two-factor authentication (not SMS if you can avoid it).
  6. If you are in the United States and lost funds to a scam, you can file a complaint with IC3. Filing does not reverse a confirmed transfer.

Nobody on this site can reverse a confirmed on-chain transfer. Anyone who promises they can, for a fee, is showing red flag ten.

FAQ

Is this different from the general phishing lesson?

Yes. The phishing overview explains the industry. This checklist is the pause-and-compare tool for wallet prompts, seed-phrase traps, address poisoning, WalletConnect bait, and claim-page drainers that beginners hit in 2026.

How do I protect my seed phrase from phishing?

Keep it offline. Never type it after a link, ad, or DM. Official restore happens only inside the wallet app or hardware device you opened yourself. Details are in seed phrase safety.

What are common crypto phishing red flags?

Urgency timers, unsolicited support, lookalike domains, requests for recovery words, claim buttons that need a signature, WalletConnect QRs from chat, and wallet prompts that do not match the button you clicked.

How do I avoid crypto phishing scams in practice?

Bookmarks over ads, reject any seed-phrase request, read every signature like a receipt, use a separate experiment wallet, and never scan a stranger’s WalletConnect QR.

Can I screenshot my seed phrase if I lock my phone?

A screenshot can still sync to cloud backups, laptops, and stolen-device restores. Prefer an offline copy.

Are all airdrops scams?

No, but fake claims are common enough that you should never sign from your savings wallet. Verify the source first, or skip it.

Does a hardware wallet make this checklist unnecessary?

No. A hardware wallet protects keys from a compromised computer, but it will still sign a malicious transaction if you approve the prompt. You still have to read what you are signing.

Does connecting a wallet empty it?

Usually no. Connecting typically shares an address. The dangerous step is a separate approval or signature. If you do not understand the prompt, reject it.

Should I trust a support video call where the agent looks and sounds completely real?

Not automatically. AI voice and video cloning can produce convincing support agents. The test is not how realistic they sound or look — it is whether they ask for a seed phrase, private key, or remote-desktop access. Legitimate support never needs any of those, regardless of how the conversation started.

I got a text saying my wallet will be frozen — is that a phishing red flag?

Yes. Unexpected SMS or iMessage “security alerts” with a verify link are a common 2026 lure. Do not tap the link. Open the brand from a bookmark you saved earlier, or type the official domain yourself. No legitimate wallet restores access by collecting your seed phrase through a text message.

Is the top Google result for a wallet download safe?

Not automatically. Sponsored and lookalike results are a common way beginners land on fake MetaMask, Ledger, Phantom, or Trust Wallet pages. Treat search ads as untrusted. Type the official domain yourself, or use a bookmark you created on a calm day, then confirm the publisher name on the brand’s own help site before you install anything.

Knowledge check

Quick quiz

01 What should you do if a “support agent” asks for your seed phrase?
02 Which 2026 wallet-scam pattern is easiest to miss?
03 Does connecting a wallet by itself usually let a site spend your tokens?
04 What is a safe response to an unexpected airdrop claim page?
05 A stranger in Discord pastes a WalletConnect QR and says “scan to sync support.” What should you do?
06 A voice on a support call sounds exactly like an official agent and asks for remote desktop. What should you do?
07 You receive an SMS saying your wallet will be locked unless you verify in the next 10 minutes. What should you do?
08 You search “MetaMask download” and the top Sponsored result looks official. What should you do?

What to read next

Use the checklist, then deepen the two skills that stop most beginner losses: recovery-word storage and reading approvals.