Phishing

Beginner
Жаңыртылган Sep 24, 2026

What Is Phishing?

Phishing is a social engineering attack that impersonates a trusted entity to trick people into revealing sensitive information or wallet private keys.

The word combines "fishing" with "phreaking". Phishing is among the most widespread cyberattack techniques. It relies on psychological manipulation rather than technical exploits, so every internet user is a potential target. 

Most phishing attacks arrive as fraudulent emails designed to convince the user to open a fake website, typically asking them to reset a password or confirm payment details. Phishing can also be done through SMSes, phone calls, voicemails, and QR codes.

How Phishing Works

A typical phishing email looks like it comes from a company or service you already use. The email urges you to act quickly and links to a website that imitates the real one. When you sign in, you hand your credentials to the attacker. Other variations use urgent stories or demands for money, such as the infamous "Nigerian Prince" email scam.

Phishing can also be used to steal crypto. A cybercriminal may copy a merchant website and swap the payment address for one of their own, so the user pays a scammer while believing they are paying a legitimate service.

Attackers use a related technique called address poisoning: they send tiny transactions so their lookalike address appears in the victim's transaction history, betting the victim will copy the wrong one later. 

AI has made phishing cheaper and more convincing. By late 2025, AI-generated emails made up the majority of reported phishing threats, and scammers increasingly combine email with fake calls, cloned voices, and deepfake video. One careless click or keystroke can be costly, so it is important to recognize phishing scams before you become a victim.

Why Phishing Matters

Phishing is dangerous because it targets people rather than machines, and even careful users can be deceived. The damage is significant: according to a CertiK report, crypto users lost over 366 million USD across 63 incidents in H1 2026. 

Such losses show why phishing is often the first step of larger scams: stolen credentials and seed phrases are cashed out through follow-up attacks.
Crypto adds a higher-stakes variant. A stolen password can usually be reset, but a leaked private key or recovery phrase transfers full control of the funds, with no customer support to reverse the damage. Understanding phishing is therefore a core security habit for anyone who owns digital assets.

How To Prevent Phishing

Treat any attempt to request information, login credentials, or money with suspicion. Practical habits that prevent most phishing attacks:

  • Verify unexpected requests through a second channel. Contact the company using a phone number or website you find on your own, never one provided in the suspicious message.

  • Type website addresses manually or use bookmarks instead of clicking email links, and check the sender address carefully for lookalike domains.

  • Legitimate websites typically use HTTPS, but so do scam sites. 

If you’re using Google Chrome, you may see the padlock icon after clicking on the “tune” icon in your address bar. However, this just means the connection is encrypted, not that the site is trustworthy. You should still remain vigilant when browsing. 

  • For crypto specifically, verify the blockchain address before sending a payment, since confirmed transactions cannot be reversed or canceled.

  • Keep private keys and recovery phrases safely stored, preferably offline, and never share them. No legitimate service will ask for them.