Phishing
Look-alike domains and fake support can redirect users to malicious requests.
Learn look-alike domains, fake support, fake airdrops, malicious signatures and clipboard risk with practical security checks and on-chain verification guidance.
Phishing pages often use look-alike domains, ads, private messages or forged QR codes. Prefer trusted bookmarks or known entry points for important actions.
Look-alike domains and fake support can redirect users to malicious requests.
A persistent token permission can remain active after a DApp session ends.
Screenshots, remote control and public devices can reveal sensitive material.
Wrong network, address or amount can lead to irreversible outcomes.
Some attacks seek a malicious message signature, token approval or contract transaction rather than recovery secrets. Review the requesting site, spender and permission scope before signing.
Malware can replace clipboard addresses, and remote-control tools can expose screens and wallet actions. Re-check pasted addresses and avoid sensitive actions while someone else controls the device.
For look-alike domains, fake support, fake airdrops, malicious signatures and clipboard risk, use a deliberate sequence: verify the entry point, confirm the network, check the address or contract, review the exact request, then submit. For asset movement, also verify the amount, fee and transaction hash. For DApps, distinguish connection, message signatures, transaction signatures and token approvals because they create different permissions.