Most crypto phishing isn’t “hacking” in the Hollywood sense. It’s social engineering: you click a link, sign something, and the attacker uses your permissions to move funds.
Red flags in messages and comments
- Unexpected urgency: “Claim now, only today”.
- New accounts pushing the claim.
- Links that don’t match the official domain.
- Requests to sign/approve before any real verification.
Verify before connecting your wallet
Open the project website yourself (type the domain or use bookmarks). If an “airdrop” requires you to connect via a random page, stop there.
What to do if you already clicked
If you only visited: you’re usually fine. If you signed a transaction or approved tokens: revoke permissions where possible and move remaining funds to a safer wallet.
Not financial advice. Scam education only.