
Phishing doesn't hack the exchange and doesn't hunt for a vulnerability in the blockchain. It works in a simpler way. It gets you to hand over access to your money yourself. A link, an email, a Telegram message, a fake wallet-connect button, and the funds are already gone to someone else's address with no chance of reversing the transaction.
According to analytics firm Scam Sniffer, crypto phishing brought scammers $83.85 million in 2025, with 106,106 people affected. The number looks modest next to 2024, when losses came to around $494 million and over 330 thousand users became victims. A drop of almost 83%. But it's too early to celebrate. The peak fell in the third quarter of 2025, when on the back of ETH's rally scammers pulled $31 million out of the wallets of 40 thousand people in just three months. The average loss per victim in 2025 was $790 against $1500 a year earlier. Scammers moved from hunting big fish to mass-robbing retail traders. Crypto fraud in 2025 rarely looks like a spectacular hack, more often it's plain carelessness out of nowhere.
This article breaks down the main types of phishing, the signs that let you spot it before you click, and a working protection checklist. We'll talk separately about phishing aimed at the API keys of trading terminals, because for an active trader that's one of the most sensitive attack vectors.
Scam schemes change along with technology, but the point stays the same: get access to your funds by passing themselves off as something legitimate. Let's go through the four main categories that pretty much everyone who trades crypto for longer than a few months runs into.
A classic of the genre, a clone of the exchange site with an almost identical domain. One extra letter, a Latin "i" swapped for a lowercase "l", a hyphen instead of a dot, and an address like binancce.com or bybit-pro.com already looks real. The design is copied one to one, right down to the banners and support text.
A separate headache is poisoned ads. Scammers buy ad slots in search engines, and the phishing site ends up above the official one in Google results. The user searches "binance login" and clicks the first link without even checking whether it's an ad.
I once clicked an ad banner myself instead of my usual bookmark, I was too lazy to look the site up by hand. Good thing I noticed the extra letter in the domain while I was on the password entry page and closed the tab. Since then I only go to exchanges through saved bookmarks, no search queries.
Clones like this usually ask for your login and password, and the more advanced versions also ask for the two-factor authentication code in real time, hijacking the session in seconds.
An email supposedly from the exchange's security team. Your account is blocked, confirmation is required within two hours, otherwise the funds will be frozen. Inside is a link to a cloned site or an attachment with malware, often a keylogger that then quietly collects passwords and seed phrases.
The signs of such emails usually match. The return address looks real but differs by one character, the exchange logo is pulled from public sources, and the text is written with artificial deadline pressure. Sometimes you see more elaborate versions that imitate a notification about winning a token giveaway or an invitation to a closed list for a new listing.
Account security notifications are the ones most often faked. An email about a "suspicious login from a new device" looks more believable than a plain giveaway, because it hits the user's alarm directly.
Here it's social engineering in its purest form. They clone the channel of an exchange or a project, changing one letter in the name, buy bot subscribers for credibility and start sending direct messages from "support" that's ready to "solve the problem right now".
The second common scenario. A fake admin messages you first in DMs after you leave a comment with a question in the official chat. The wording is almost always the same, something along the lines of "write to us in DMs, we'll help". Real support at exchanges and serious projects almost never messages first.
Fake airdrop campaigns stand apart. The promise of free tokens for connecting a wallet to a site that actually requests a signature to move your assets out. In 2025 this vector became one of the most widespread, judging by Scam Sniffer's quarterly stats, where the number of victims grew faster than the loss amount.
The most technical category. A fraudulent site imitates the interface of a well-known protocol (a DEX, a staking landing page, an NFT marketplace) and asks you to connect your wallet. Then the worst part starts. A request to sign a transaction that looks harmless but actually gives a smart contract permission (permit) to dispose of your tokens without any further confirmation.
According to that same Scam Sniffer report, Permit and Permit2 attacks made up 38% of all thefts over a million dollars in 2025. The single biggest case, $6.5 million stolen in September through exactly that kind of signature. After the Ethereum Pectra upgrade a new vector appeared as well, exploitation of EIP-7702. Two incidents in August brought scammers $2.54 million between them.
The problem is that the wallet shows a technical signature window, not a human explanation like "you are allowing all USDT to be withdrawn from this address". The user hits "Confirm" without reading what they're signing. This is called blind signing: the user approves a transaction without understanding what rights it gives the smart contract. This is what kills deposits more often than any passwords.
Crypto phishing losses compared (2024 vs 2025)
Good news. Most phishing schemes are built on the same patterns. Once you learn to see them, you cut off some ninety percent of the threats before you even open a suspicious link.
If at least two points from the list fire, it's worth stopping and checking the source separately, not through the link in the message.
The first rule is simple. Go to exchanges and wallets only through saved bookmarks, never through search results and certainly not through ads. Scammers buy ad slots in search regularly, and that's not a rarity but a systematic practice.
Second, hover over the link before clicking and look at the real address in the browser's status bar, not at the link text itself. In emails and Telegram messages the text and the actual URL can differ completely.
Third, compare the domain character by character with the official one, especially if the site opened after you came from an ad or a message. In my experience, better to spend five seconds on the check than to explain to yourself later where the funds from your account went.
Fourth, check the domain's age and the site certificate through whois services. A freshly created domain registered a week ago for a "major exchange with a ten-year history" is already a red flag on its own.
How do you protect yourself from phishing in crypto in practice rather than in theory? A short set of habits helps cut the risk to a minimum: go to exchanges only through bookmarks, keep your seed phrase offline and not in digital form, turn on 2FA through an app instead of SMS, and revoke smart contract permissions regularly. More on each point below.
Checking a link once doesn't save you from systemic risk. You need a habit that runs on autopilot, without straining your attention every day.
Save the official addresses of exchanges and wallets in your browser bookmarks and use only those.
Turn on two-factor authentication everywhere it's available. Google Authenticator is safer than SMS, because a SIM card can be reissued fraudulently.
Never enter your seed phrase on websites. Legitimate services simply don't ask for it, the wallet is generated locally and stays with you.
Regularly check and revoke smart contract permissions through services like Revoke.cash, especially after interacting with new DeFi projects or airdrop campaigns.
For new protocols set up a separate "test" wallet with a minimal amount, not your main one with the full deposit.
Three mistakes that drain deposits most often, despite all the checklists:
A checklist isn't a cure-all, and here's an example of when it doesn't save you. A trader had 2FA through Google Authenticator, checked domains and never entered his seed phrase, everything by the book. But scammers reissued his SIM card at the mobile operator (a typical SIM swap) and used the SMS recovery code to get into his email, and from there, without any seed phrase, reset the password on the exchange. The lesson is simple: tie account recovery not to your phone but to a separate protected email, and keep 2FA through an app there too, not SMS. I know a case from a traders' chat where a deposit was drained exactly like that in one evening, and the person was as careful as possible about everything else.
If you still haven't fully worked out how to set API key permissions properly and connect an exchange to the terminal, there really are nuances there, watch the free lesson from our trading-from-scratch course on YouTube. It's about API keys and connecting an exchange, and it's part of the full playlist "Trading from scratch | free course on crypto trading and scalping".
A separate topic is API key security for those who trade through terminals. The key gives a program access to your exchange account, and a phishing attack on the terminal or something like it is essentially equal to an attack on the exchange itself. A simple rule applies here. Give the key only the permissions it needs (futures separately, spot separately, withdrawals preferably not enabled at all), bind an IP White List where the exchange allows it, and never store the key in open notes or messengers. For a detailed breakdown of all the rules for creating and storing API keys see the article "Safely connecting API keys to the terminal".
By the way, this is exactly why the terminal's architecture matters. Secret Terminal stores API keys and secret data locally on the user's device, without sending them to third-party servers and without cloud storage. The connection to exchanges goes directly, which removes an extra link through which the key could theoretically be intercepted. For a trader that's not an abstract marketing phrase but a concrete reduction of the attack surface. The fewer places the key is stored, the fewer chances it gets stolen.
If you suspect you've already become a phishing victim, act fast. Move the remaining funds to a new, clean address. Revoke all smart contract permissions from the old wallet. Change passwords and recreate API keys on all exchanges if there's even the slightest suspicion of a leak. Reaction speed decides more here than anything else, because getting back crypto that's already been sent is, as a rule, impossible.
For more on the signs of scam projects and hype-pumping schemes read the article "How to spot a scam project in crypto", and for a general breakdown of protecting your wallet and account, including working with cold storage, see the piece "How to protect your crypto assets".
Phishing in crypto is a type of fraud where the attacker gets the user to hand over access to a wallet or exchange themselves, through a fake site, email or message. Unlike a hack, here the victim performs the action that leads to the loss of funds. They enter a password, sign a transaction or share a seed phrase.
Compare the domain character by character with the official address and pay attention to how you got to the site. If you arrived through an ad in search or a link in a message rather than through a bookmark, the odds of a fake go up sharply. Additionally, look at the domain's age through whois and at small grammar mistakes in the interface.
If you only opened the site but didn't enter any data and didn't sign a transaction, close the tab and don't go back there. If you managed to enter a password or sign a permission, immediately change your passwords, revoke smart contract permissions through Revoke.cash and move the remaining funds to a new address.
In the vast majority of cases, no. Blockchain transactions are irreversible, and once funds have gone to a scammer's address, rolling the transfer back is technically impossible. The only chance is contacting the exchange, if the funds passed through its wallet and it managed to freeze the withdrawal, but that's the exception rather than the rule.
Give the key only the permissions it needs, disable withdrawal rights, bind the key to your IP address where the exchange supports it, and never save the key in text files, notes or messengers. Terminals with local key storage, without sending anything to the cloud, reduce the interception risk further.
Yes, and it's one of the most widespread attack channels of 2025. Scammers clone official channels, buy bot subscribers and send direct messages on behalf of "support". Remember a simple rule: real support at major exchanges almost never messages first in DMs.
Real airdrop campaigns don't require signing a transaction with broad rights to move your tokens and don't ask for a seed phrase. If the campaign site asks you to connect a wallet and immediately offers you to sign something resembling a permission (permit) without a clear explanation of what exactly you're allowing, better close the tab and check the project through official channels separately.
Phishing works not because scammers are technically more sophisticated than exchanges, but because it hits carelessness and haste. Scam Sniffer's numbers for 2025 speak for themselves. Total losses fell by almost 83%, but the number of small attacks on retail traders grew. That means the scheme shifted from hunting whales to mass collection from ordinary users, the kind who trade on an exchange every day. To answer the question of how to protect yourself from phishing in crypto briefly: fewer clicks on autopilot, more of the habit of checking the source by hand.
Basic hygiene saves you in most cases. Bookmarks instead of search, checking the domain character by character, sensible permissions on API keys, the habit of revoking smart contract approvals. For those working through a terminal, an architecture with local key storage gives an extra plus. Secret Terminal doesn't send API keys to third-party servers and doesn't store them in the cloud: if you want to trade without worrying about where your access sits, set it up using the checklist above. The fewer points a key can leak through, the more calmly you can focus on the trading itself, rather than on whether your account got taken while you were reading the tape.

Has 5 years of trading experience and spent 3 years as a mentor, training over 2,000 students. He is developing Secret Terminal to make professional trading tools accessible to every trader.
Was helpful
Your rating will help us improve the quality of published materials and increase their usefulness.
We publish product updates, setup guides, and practical materials on working with Secret Terminal tools

Crypto account security rules: 2FA, API keys, phishing, and storage best practices

How to safely create an API key on Binance and Bybit. Which permissions to grant and what not to do.

Types of Cryptocurrency Scams: Phishing, Rug Pull, Fake Exchanges