Phishing and Wallet Drainers

Phishing tricks you into revealing your seed phrase or signing a malicious transaction. Real support never DMs you first and never needs your recovery phrase — treat any such request as a scam.

What it means

Phishing is social engineering: a scammer builds a convincing fake — a website, a support 'agent', a pop-up — to get you to hand over access. A wallet drainer is the transaction they want you to sign: once approved, it moves your assets out.

Why it matters

Fakes can look pixel-perfect. You cannot judge safety by how something looks. You judge it by how you arrived, who contacted whom, and exactly what is being requested.

How it works

Almost every phishing attempt combines three signals: unsolicited contact (they reached out first), a request for something they should never need (your seed phrase, or an unusual signature/approval), and urgency (act now or lose access). Spotting any one should slow you down.

What happens if you ignore this

Signing a drainer or entering your seed phrase is usually irreversible. There is no support line that can claw funds back on-chain. The only reliable defense is not signing or sharing in the first place.

Safety considerations

Bookmark official sites and open them yourself — never from a link in chat or email. Never type your seed phrase anywhere. If a request feels urgent, that is a reason to slow down, not speed up.

Story

Maya gets a friendly DM: 'BlackPebble Support here — we detected suspicious activity. Verify your wallet in the next 10 minutes or it will be locked.'

She thinks she is protecting her funds by acting fast.

The 'agent' asks for her 12-word recovery phrase to 'restore access.' The moment she pastes it, the wallet is emptied.

Support never messages first and never needs your recovery phrase. Urgency is the tell — real security processes don't put a countdown on your funds.

Beginner tips

Common mistakes

Related lessons