Temple of FortuneDE
Menu

Security

Spot a phishing message: the four-question check

Many crypto thefts start with a message that looks real. Here is how to unmask it before you click.

By Femi Adler · Temple of Fortune · Updated:

Quick answer

You spot phishing by four signals: unexpected contact, artificial time pressure, a link to an almost-real address, and a request for keys, codes or an approval. Never click the link they sent — always open the site or app yourself from a known bookmark.

Many crypto thefts from private individuals start the same way: with a message that looks like it came from your exchange, your wallet maker or a support team. Email, SMS, chat, comment — the channel changes, the pattern stays. It is not the only route in — wallet drainers on malicious dApps, SIM swaps and address poisoning work differently — but the fake message remains one of the most common entry points, and it is the one you can defend against with the least effort. The US cybersecurity agency CISA sums up the warning signs like this: slightly altered sender addresses, spelling mistakes, unexpected links, and requests to take unusual actions.

These four questions unmask most attacks:

1. Did I expect this? Unsolicited messages about “security issues”, “account locks” or “winnings” are the most common way in. Unexpected is a warning sign, not a coincidence.

2. Am I being pressured? “Today only”, “act now”, “or your account will be locked”. Artificial urgency is meant to switch off your thinking. That is exactly when you should slow down, not speed up.

3. Where does the link really go? Fraudsters use addresses that closely resemble the original (swapped letters, a different ending). Do not click the link. Open the site or app instead from your own bookmark or the official app store — always navigate yourself, never follow the link they sent.

4. What are they after? The decisive question. If you are asked for your seed phrase, a 2FA code or a wallet approval, it is fraud — no exceptions. The FBI’s fraud guidance is unambiguous on this point, and wallet makers like Trezor say the same about their own support: no genuine support ever asks for your seed phrase. It belongs only in your own device, never in a chat window and never on a linked website.

If a message hits even two of these signals: don’t click, don’t enter anything, don’t approve anything. Check independently, via the official address, whether there is anything to deal with at all — usually there isn’t.

And if you are unsure whether you already went too far: disconnect the wallet from suspicious sites and revoke any token approvals you granted — most wallets have a built-in approval manager for this, or you can use an established revocation tool like Revoke.cash. In the worst case, move your funds to a new, clean wallet. Running through the four questions takes half a minute — and that half minute is cheaper than any rescue operation afterward.

FAQ

What if the message really is from my exchange?
Then the issue will also show up when you log in on your own — via bookmark or official app, never via the link in the message. A genuine notice loses nothing by you taking that route; a fake one loses everything.
I clicked the link but didn't enter anything. Am I safe?
On an up-to-date device, a single click without any input usually does no harm — but the risk is not zero. Close the page, enter nothing, and never sign or approve a wallet request that appears afterward. If you connected a wallet, disconnect it and revoke any approvals via your wallet's approval manager or an established tool like Revoke.cash. If your device or browser is outdated, run updates and a security scan too.
Does real support ever ask for a seed phrase or 2FA code?
No — never, under no circumstances. Any such request is fraud, regardless of how official the sender looks or how urgent it sounds.
I already entered my seed phrase. What now?
Act immediately: set up a new wallet with a fresh seed phrase and move your funds there. The old wallet is compromised and stays compromised — changing passwords does not help once the seed is out.

Sources

This article is for general information only.

Comments

Argue hard on substance, fair in tone. No financial "tips" with profit promises, no ads, no links to scams — that gets removed, and repeat offenders lose their account. Otherwise: welcome to the temple.