Phishing is the art of tricking you into handing over secrets — a password, a recovery phrase, or a click on a poisoned link — by pretending to be someone you trust. In crypto, a single phishing success can empty a wallet. The good news is that phishing follows predictable patterns you can learn to spot in seconds.
Step 1: Treat urgency as a warning, not a command
Phishing messages almost always try to rush you. "Your wallet will be locked in 24 hours." "Urgent security action required." Real organisations rarely demand instant action. The moment you feel a jolt of panic, slow down — that feeling is exactly what the attacker engineered.
Step 2: Inspect the sender and the link
- Hover over links before clicking to see where they really go.
- Check the web address for subtle misspellings or extra words, like a hyphen or an added letter.
- Be suspicious of any link arriving by email, text, or chat — even if it looks official.
Step 3: Never enter your recovery phrase anywhere online
This is the big one. No legitimate website, wallet, or support agent will ever ask for your recovery phrase. A page that asks you to "validate" or "sync" your wallet by entering the words is always a scam, with no exceptions.
Step 4: Reach sites the safe way
Instead of clicking links, type the official address yourself or use a bookmark you saved earlier. This single habit defeats most phishing, because the attacker can only fool you if you follow their link rather than your own.
Step 5: Watch for impersonation in chats
Scammers often pose as "support" or a "team member" who messages you first. Real support does not slide into your private messages offering to fix your wallet. When someone contacts you out of the blue offering help, assume it is phishing until proven otherwise.
Step 6: When unsure, ask the community
If a message leaves you uncertain, paste it (without your secrets) into the official Malairte community and ask. Experienced members spot phishing instantly and will happily confirm. A thirty-second question is far cheaper than a stolen wallet.
Phishing relies on a moment of haste. Replace haste with a calm check, and these attacks lose almost all their power.