A crypto phishing attack doesn’t announce itself. One minute you’re clicking what looks like a MetaMask security alert or a Discord message from a friend. The next minute you’re on a site that looks completely real — and you may have just handed over your credentials, connected your wallet, or worse.
If you clicked a link and entered anything into a site that now looks suspicious, act in the next five minutes. Here’s how to contain the damage.
First: What Did You Actually Do on the Site?
Before you panic (or keep reading), triage what happened. The right response depends entirely on what information you gave up. Find your situation below and jump directly to that section.
- Entered your exchange username and password → Section A
- Connected your wallet or signed a transaction → Section B
- Entered your seed phrase (12 or 24 words) → Section C — the most severe situation
- Clicked the link but didn’t enter anything → Section D
Section A: You Entered Your Exchange Credentials
You gave a phishing site your login information for Coinbase, Kraken, Binance, or another exchange. Here’s what to do right now.
1. Go directly to the real exchange site. Do not click any links. Type the URL directly into your browser address bar or use a bookmark you created yourself.
2. Change your password immediately. Make it something entirely new — not a variation of the old one.
3. Switch to an authenticator app for two-factor authentication (2FA). 2FA means “two-factor authentication” — a second verification step beyond your password. If you’re still using SMS codes, a phisher can intercept them. Google Authenticator or Authy generates time-based codes directly on your device, with no interception possible.
4. Check active sessions. Most exchanges have a “Security” or “Devices” section in account settings. Revoke every session that isn’t your current one.
5. Review your recent transaction history. Look for any withdrawals you didn’t initiate. If you see anything suspicious, contact the exchange’s fraud team immediately — use their official support page, not an email link you received.
The window for preventing loss is narrow. Exchange support teams have limited ability to reverse confirmed transfers, but they can freeze accounts if you reach them quickly enough.
Section B: You Connected Your Wallet or Signed a Transaction
This is more serious than many people realize. When you connect a wallet like MetaMask to a fake site and approve a transaction or signature, you may have granted that site permission to move tokens out of your wallet — even after you close the tab.
1. Go to revoke.cash immediately. This free tool shows every site your wallet has ever granted spending approval to. Connect your wallet there and revoke any approvals you don’t recognize. An “approval” means you authorized a smart contract — a piece of automated code on the blockchain — to move your tokens on your behalf.
2. Move remaining tokens to a fresh wallet address. If you had significant funds in that wallet, create a new wallet and transfer everything out. Treat the compromised address as exposed.
3. Check your transaction history on Etherscan. Etherscan is a public blockchain explorer — think of it as a search engine for all activity on the Ethereum network. If an attacker already drained tokens, you’ll see it there. Etherscan can decode transaction data so you can see what you actually authorized.
4. Do not deposit new funds to the compromised wallet address until you’ve reviewed and revoked all approvals.
A hardware wallet would have prevented this — the physical device displays the exact approval you’re signing before you confirm it, making it much harder to trick you into signing something malicious. It’s worth understanding why hardware wallets exist and how they protect you before your next DeFi interaction.
Section C: You Entered Your Seed Phrase — Act Now
Stop reading this sentence. If your funds are still in that wallet, open it right now and move everything to a brand new wallet before doing anything else. Do it before you finish reading this section.
A seed phrase — the 12 or 24 random words generated when you first created your wallet — is the complete master key to everything inside it. Anyone who has those words owns that wallet. There is no “change your password” option. The wallet is compromised, permanently.
- Create a brand new wallet on a clean device, or use a hardware wallet. Write down the new seed phrase on paper. Do not store it digitally.
- Move every token and every coin from the old wallet to the new one immediately — attackers often drain wallets within minutes of receiving a seed phrase.
- Never use the old wallet again. The old address is permanently compromised.
- Do not import the old seed phrase into a new app thinking that “resets” anything. It doesn’t. The phrase is the wallet — same phrase, same exposure.
If the attacker was faster and the funds are already gone, they are most likely unrecoverable. But document everything: the phishing URL, the wallet addresses involved, and any transaction hashes. You’ll need this for reporting.
Section D: You Clicked But Didn’t Enter Anything
Lower risk, but not zero. Some malicious sites attempt drive-by exploits targeting browser vulnerabilities — though these are less common than credential-stealing attacks.
- Close the tab and clear your browser cache and cookies.
- Run a malware scan with a reputable tool (Malwarebytes free tier works well for this).
- Monitor your exchange accounts and wallet addresses for unexpected activity over the next 24–48 hours.
You’re probably fine. Keep an eye on things for a couple of days and move on.
How to Recognize a Crypto Phishing Attack Before It Hooks You
Once you’re safe, here’s what to internalize for the future.
Check the URL every single time. Phishers buy domains designed to look nearly identical to real ones: coinba5e.com, metamask-wallet.io, binance-support.com. The real sites are coinbase.com, metamask.io, binance.com. A fake crypto website victim almost always says “it looked exactly like the real site” — because it was designed to. One character off is all it takes.
Legitimate platforms don’t DM you first. If someone contacts you on Discord or Telegram claiming to be support for an exchange or protocol, it’s a scam. Real support doesn’t reach out unprompted. A crypto phishing email or message that “finds you” is always suspicious.
Real airdrops never ask for your seed phrase. Ever. If any site or message asks for your 12 or 24 words to “verify your wallet” or “claim your tokens,” close it immediately. No legitimate project needs your seed phrase for anything.
Use bookmarks. Bookmark every exchange and DeFi site you use regularly. Navigate from the bookmark. Don’t Google “Coinbase login” and click the top result — phishers buy search ads that appear above the real site.
Verify before you connect. Taking a few minutes to evaluate any crypto project before connecting your wallet can prevent you from becoming a statistic.
Report What Happened
Even if your funds are already gone, reporting matters. It creates records that help investigators build cases and warns others.
- IC3.gov — The FBI’s Internet Crime Complaint Center. Include the phishing URL, any wallet addresses involved, and transaction hashes.
- Google Safe Browsing — Report the phishing URL at safebrowsing.google.com/safebrowsing/report_phish/ so Chrome will warn future visitors to that site.
- The platform where the link was shared — Discord, Twitter/X, and email providers all have abuse reporting tools. Report the account or email that sent the link.
The Bottom Line
A crypto phishing attack is designed to move faster than your ability to think clearly. The attacker’s advantage is your panic and the seconds it takes to realize something went wrong. Triage what you gave up, act on the appropriate section above, and document everything — even if it already feels too late.
Overwhelmed? Book a “Was I Scammed?” session ($149) — on-chain trace + a documentation pack for the FBI/IC3, police, and your bank. I will NOT promise to recover your funds; anyone who promises that is scamming you a second time. Book here