The word combines "fishing" with "phreaking". Phishing is among the most widespread cyberattack techniques. It relies on psychological manipulation rather than technical exploits, so every internet user is a potential target.
Most phishing attacks arrive as fraudulent emails designed to convince the user to open a fake website, typically asking them to reset a password or confirm payment details. Phishing can also be done through SMSes, phone calls, voicemails, and QR codes.
Phishing can also be used to steal crypto. A cybercriminal may copy a merchant website and swap the payment address for one of their own, so the user pays a scammer while believing they are paying a legitimate service.
AI has made phishing cheaper and more convincing. By late 2025, AI-generated emails made up the majority of reported phishing threats, and scammers increasingly combine email with fake calls, cloned voices, and deepfake video. One careless click or keystroke can be costly, so it is important to recognize phishing scams before you become a victim.
Phishing is dangerous because it targets people rather than machines, and even careful users can be deceived. The damage is significant: according to a CertiK report, crypto users lost over 366 million USD across 63 incidents in H1 2026.
Treat any attempt to request information, login credentials, or money with suspicion. Practical habits that prevent most phishing attacks:
Verify unexpected requests through a second channel. Contact the company using a phone number or website you find on your own, never one provided in the suspicious message.
Type website addresses manually or use bookmarks instead of clicking email links, and check the sender address carefully for lookalike domains.
Legitimate websites typically use HTTPS, but so do scam sites.
If you’re using Google Chrome, you may see the padlock icon after clicking on the “tune” icon in your address bar. However, this just means the connection is encrypted, not that the site is trustworthy. You should still remain vigilant when browsing.
For crypto specifically, verify the blockchain address before sending a payment, since confirmed transactions cannot be reversed or canceled.
Keep private keys and recovery phrases safely stored, preferably offline, and never share them. No legitimate service will ask for them.
Бул компьютердин ишин көзөмөлгө алып, төлөм жасалбаса файлдарды жок кылуу же ачыкка чыгаруу менен коркуткан...
Мындан тышкары көпчүлүк чабуулу деп да белгилүү. Бир же бир нече майнерлер тобу тармактын майнинг хэш ылдам...
Тармактагы түйүндөрдүн көпчүлүгү зыяндуу болуп, айрым түйүндөрдүн чынчыл түйүндөрдөн маалымат алышына жол б...
Binance Academy редакциясы