Phishing
Golpe em que um atacante se passa por um serviço legítimo para enganar a vítima e obter credenciais, chaves ou autorizações que dão acesso aos fundos.
Key points
- Phishing is a scam in which an attacker poses as a legitimate service to trick the victim into handing over credentials, keys, or authorizations.
- In crypto, the target is usually the private key, the recovery phrase, or a signature that grants access to the funds.
- Because transactions are irreversible, falling for phishing usually results in permanent loss, which makes prevention essential.
What is phishing?
Phishing is a fraud technique that exploits user trust rather than technical vulnerabilities. The attacker creates a convincing imitation of an official website, app, or message and induces the victim to provide sensitive information or authorize an action. In crypto, the ultimate goal is almost always to gain access to funds, either by capturing secrets or by getting the victim to sign a malicious transaction.
How it works
A phishing scam typically starts through an apparently legitimate channel: an email, a message, an ad, or a website with an address that looks like the real one. The victim is led to enter their recovery phrase, private key, or login details, which go straight to the attacker. A common variation asks the person to connect their wallet and sign a transaction that, in practice, authorizes the transfer of their assets.
These scams exploit urgency and authority: messages claiming the account is at risk, that there is a prize to claim, or that immediate action is required. This pressure lowers the victim's attention and leads them to act without verifying. Many attacks use addresses that are nearly identical to official ones, with small differences that are hard to notice.
The most effective defense is to be distrustful by default: never share the recovery phrase, check addresses carefully, and never sign operations from an unknown source.
Why it matters
Phishing is one of the most common causes of fund loss in crypto, precisely because it does not depend on breaking cryptography, but on deceiving the user. For companies, training teams to recognize these scams and adopting verification processes is an essential part of security, just as important as protecting systems.
Risks and limitations
No tool fully eliminates the risk of phishing, because it attacks human behavior, not just technology. Scams evolve and become more sophisticated, precisely imitating real services. That is why prevention depends on consistent verification habits, which must be maintained even when everything seems legitimate. In the end, constant attention remains the most effective defense.