B.BlockAxis⌕ Search
Menu

Recognise a wallet scam

Attackers can imitate a support agent, a familiar website or a message from a friend.

BeginnerContent revised · 14.09.20263 min reading · allow 5–10 more minutes for the workshopBlockAxis

Your learning plan

Inspect the request before trusting the appearance

By the end, explain the diagram in your own words, solve the case and justify the correction.

Prerequisites : Hot, warm and cold wallets

Level 1 · Beginner →

Reading path · 11 / 12 · Beginner

Key takeaway

Attackers can imitate a support agent, a familiar website or a message from a friend.

The essentials

Attackers can imitate a support agent, a familiar website or a message from a friend. Their objective may be a recovery phrase, a signature, a token allowance or a direct transfer. Identify the requested action before judging the visual appearance of the message.

How it works

A recovery phrase can give control over derived keys. A signature can authorise an action even if no immediate payment appears. An allowance can let a contract transfer tokens later. Read the wallet’s operation details and reject requests you cannot explain. A small initial payment or an apparently successful test does not establish that subsequent requests are safe.

What to watch

Urgency and threats are reasons to pause. Reach a service through a previously verified route rather than through the message. If exposure is suspected, preserve evidence and assess what was disclosed. Revoking an allowance does not repair a disclosed recovery phrase, and disconnecting a website does not automatically revoke on-chain permissions.

Understand the details

Separate three checks: where did the request originate, what action would approval enable, and can that action be independently justified? A correct-looking domain shown inside a message is not proof of the actual destination. A padlock protects a connection, not the honesty of its operator. For institutional workflows, unexpected instructions should return through the established independent approval channel.

Boundaries and common mistakes

No checklist detects every attack. Do not paste real phrases, keys or client details into exercises, forms or chats. The examples here require no wallet.

The mechanism at a glance

  1. Pause
  2. Identify the permission
  3. Verify independently
  4. Reject and preserve evidence
Inspect the request before trusting the appearance. Conceptual map: read these four landmarks together with the explanation above.
Applied workshop · work at your own pace

Apply the lesson to a case

A fictional support message says: “Your wallet expires in ten minutes. Enter your recovery words to preserve access.” The page has the expected logo.

What is the appropriate first action?

Choose one answer.

Prepare a correction note

Describe the passage and the proposed correction. This creates a local note for you to share; it sends nothing. Do not include personal or confidential information.