
Crypto Phishing: Scams and How to Protect Yourself
Hyperliquid users lost around $550,000, and not a single private key was compromised. The attackers simply bought a search ad.
The fake platform posed as a venue for trading tokenised assets and sat above the real project in the results. According to Arkham Intelligence data, three of the transfers were large: 27,501, 82,503 and 440,015 USDC. The attacker addresses were published by a co-founder of FlashRescue, who traced the chain on-chain.
The case is so ordinary that it barely got any discussion. That is exactly why it is worth going through in full: this is how people lose crypto most often.
Why crypto phishing beats hacking
Breaking cryptography is expensive and pointless. It is cheaper to bring the owner of an asset to a state where they sign the transaction themselves.
This is the line between ordinary fraud and what happens in crypto. A card payment can be disputed, a signed operation cannot be reversed: there is no clearing window and no bank to call. So the whole design is built not around passwords but around one click that the user makes voluntarily.
The second difference is the cost of a mistake. A leaked email password costs you time. One wrong signature costs the entire balance, and no support desk or court will bring the funds back.
The third is speed. The automation on the attacker's side takes the assets the same second the permission appears. There is none of the twenty-four hours a bank uses to stop a payment.
Protection here is therefore not an antivirus but a set of habits: where you open a site from, what you read before signing, and how much you keep on the wallet you use every day.
Scheme one: a fake site in search ads
The most common story of the year. Criminals buy paid search ads on the name of an exchange or a service, and their page becomes the first line of results, above the organic listing.
Everything after that looks flawless: a copied design, the same logo, a familiar button. The user sees a familiar site, calmly connects their wallet and signs what is put in front of them. No hacking takes place. The person did it all themselves, on a page they opened themselves.
Hyperliquid is not the only case. In May more than $400,000 was drained through a clone of the Uniswap interface promoted the same way. In August the device maker Trezor reported a surge of fakes using its brand, some of which also appeared in search recommendations.
The danger of paid results is that they bypass the habit of looking at position. Users treat the first line as the main one, while the paid slot goes to whoever paid. Phishing pages live in such ads for a few days, and that is enough.
Scheme two: signing an approval instead of stealing a key
The most underestimated one. Nobody really asks for a seed phrase any more: everyone has learned not to dictate it.
Instead you are asked to sign an approval that allows spending from your balance. Formally this is a routine operation, and no exchange interface works without it. But in the fake version the limit is unlimited and the recipient is the attacker's address. The keys never leave, and the tokens can be taken out at any moment, even a month later when the page is long forgotten.
In July one investor lost 999,999 USDT by signing exactly one such operation on Ethereum. The attackers' automation tried to take about a million and adjusted the amount after the first attempt failed.
At that moment the user believes they are confirming a login. In reality they are issuing a power of attorney over their assets. The difference is visible only in the signing window, and that is precisely what most people scroll past.
Scheme three: phishing messages from support
After any leak of a customer database a second wave begins. The user is contacted by phone or message in the name of customer support, given correct details of their purchase, and offered help: releasing stuck funds, an urgent firmware update, an identity check.
Real support does not write first, does not ask for a seed phrase and does not send links to a recovery form. Any message that applies time pressure should be treated as part of a scam by default.
A separate variety is a mailout about a suspicious login to your account. The calculation is that the user panics and follows the link without checking the sender. Phishing emails of this type copy the exchange's design down to the signature and legal address, while the domain differs by one letter.
Scheme four: poisoning the transfer history
Attackers send dust from an address whose first and last characters match the one the user works with constantly. The bet is on copying from history: a person takes their own address from the list of operations, and it is somebody else's.
The scheme requires no access at all and runs on inattention. There is one defence: the recipient address is taken from an address book or verified in full, never by four characters.
Scheme five: fake apps and extensions
Fake mobile applications reach even official stores, and browser extensions reach add-on catalogues. Inside is an ordinary seed phrase form dressed up as an import screen.
Checking this is boring but reliable: the publisher, the install count, the publication date, and reaching the store from the project's official page rather than by searching the name. A fresh app with a hundred downloads and a well-known logo is a fake, not a lucky find.
Who gets targeted
There is a widespread belief that crypto phishing hunts large holders. In practice the target is chosen by behaviour, not by portfolio size.
Newcomers suffer first: they have no habit of double-checking an address, but plenty of anxiety about doing something wrong. Next come airdrop and testnet participants, who are used to connecting to dozens of unfamiliar interfaces in a row, so one malicious page in that stream stands out in no way at all.
The third group is active traders. They are in a hurry, work with several tabs at once and approve operations on autopilot. That is why phishing pages imitate trading interfaces more often than storage apps: in trading the user is rushing by definition.
The scale of the problem
Individual cases add up to statistics that explain why these attacks do not stop. One investor lost $25.6 million in fifteen minutes to a targeted attack. Losses in the hundreds of thousands, like the Hyperliquid case, pass as routine episodes and do not even make industry summaries.
The economics favour the attacker: an ad costs tens of dollars, a copy of a site takes an hour to build, and the attack scales automatically to thousands of users at once.
There is a separate problem in crypto: there is no industry body where complaints accumulate. A malicious resource gets blocked once enough victims report it, and until then it lives its own life and collects signatures. The average lifetime of such a page is measured in days, but hundreds of people pass through it in those days.
What to check before connecting a wallet
The first rule: you do not reach a platform from an ad and you do not follow links from emails. A bookmark or an address typed by hand, nothing else. That single rule closes most of the stories that end with an empty balance.
Second: check the domain in full, character by character. Fakes are built to survive a glance, not a careful reading, so look for an extra letter, a hyphen, a different top-level domain.
Third: before connecting to an unfamiliar service, check what exactly you are being asked to sign. The interface shows the operation type and the limit; an unlimited right to spend your tokens on an unknown site is a reason to close the tab.
Fourth: keep a separate wallet for experiments. A small amount is not a loss, and your main balance is never connected to unfamiliar interfaces at all.
Fifth: keep verified sites in bookmarks and maintain that list yourself. Search results change every day, your bookmarks do not. Any new site connected with crypto goes into bookmarks only after you found it through the project's official channel.
Sixth: review previously granted approvals at least once a month. An old spending permission stays alive until it is revoked, and people usually remember it only after the money is gone.
What to do if you have already signed
Revoke the active approvals. This is done in the wallet interface or through an approval checker. While the permission is live, the funds can leave at any moment, even if the malicious page was closed long ago.
Move the remaining balance to a new address. If the signature covered a specific token, move that one first: it is what they will come for soonest.
Turn on two-factor authentication where an exchange account is involved rather than self-custody. It will not save you from a signed transaction, but it closes the other half of the perimeter.
And do not pay the recovery services that will appear in the comments under your complaint. That is the same crowd coming back for a second pass: deceiving someone who has already lost money is easier than finding a new victim.
Short checklist
Reach platforms only from bookmarks. Check the domain in full. Read what you sign. Do not keep your main balance on the wallet you use to connect to unfamiliar interfaces. Revoke stale approvals at least monthly.
FAQ
Can crypto be recovered after a phishing attack?
Almost never. The transaction is irreversible and in self-custody there is no intermediary who could cancel it. The only step that works is revoking the approval and moving the remainder before the automation triggers.
Does a hardware wallet help?
Against key theft, yes. Against phishing, only partly. The device will show what is being signed, but if the user confirms without looking, the result is the same.
How do I tell a fake site apart if it looks identical?
By the address and by how you got there. Appearance copies perfectly, a domain does not. So check the address bar, and reach the platform from bookmarks.
What is more dangerous, phishing emails or search ads?
Ads. An email raises suspicion by itself, while the first line of search results is read as a choice made by the search engine and gets more trust.
Should I report a phishing site?
Yes, and immediately: to the official project whose brand was copied, and to the search engine through its ad complaint form. These pages live exactly as long as it takes to get them blocked, and every report shortens that.
Crypto markets expert and head of content and marketing at EIDEX. Covers market structure, exchange infrastructure and cross-chain trading — turning on-chain data and market shifts into clear, actionable research for traders.


