Skip to content
Markets 24H · USDT TR EN Updated 02:07
6 min read

Guides

How to spot crypto phishing links and fake tokens

Illustrative wallet security cover with fictional tokens and a phishing warning
Save article

Quick answer

To check crypto phishing risks, verify the source independently, match the network and full token contract, and understand each requested permission. A gasless signature or visible wallet balance is not proof of safety. Recovery-phrase disclosure needs a different response from a normal connection.

A fake token can copy the real name and logo. Verify the domain, network, full contract address and requested authority before interacting with an unfamiliar asset.

Spotting crypto phishing links and fake tokens requires more than checking a logo, price label or browser padlock. Compare what the page promises with what the wallet asks you to authorize. A page that says “view your reward” but requests spending permission is asking for a different action.

This guide provides a defensive checking sequence before funds are put at risk. We reviewed official wallet-security documentation on September 28, 2026. We did not connect to malicious sites or sign dangerous test requests. The domains and token scenarios below are illustrative, not destinations to visit or trades to try.

Separate connection, signatures and secret keys

Connecting a wallet generally shares an address with an application. Approving token spending, signing a message and disclosing a recovery phrase are different actions. None should be accepted as an automatically harmless continuation of a Connect button. MetaMask’s explanation of token approvals sets out the purpose of a spending authorization.

Diagram distinguishing connection, spending permission and recovery phrase disclosure

An illustrative decision aid, not a screenshot of a wallet. It separates three requests with different consequences.

If a supposed sign-in asks for an unlimited amount, an unfamiliar spender or authority over an entire NFT collection, pause. Reject a request you cannot explain. Readable wallet summaries help, but missing detail should not be interpreted as proof that nothing consequential will happen.

1. Verify the domain independently

A sponsored search result, direct message or compromised social account can lead to an imitation site. Compare the address against a previously verified bookmark or a separate official channel. Several new profiles pointing to each other do not establish independent verification if they all originate from the same unknown source.

Suppose you expect wallet.example but arrive at wallet.example.reward.example. The familiar name on the left does not establish who controls the second domain. A copied brand and an HTTPS padlock do not prove affiliation. These .example names are reserved illustrations and are not real services.

Do not proceed through browser, wallet or security warnings. The absence of a warning is not certification either: a new malicious domain may reach victims before appearing on a blocklist.

2. Match the network and full contract address

Names, symbols and artwork can be copied across contracts. Match the network and entire contract address against the project’s independently verified official record. Checking the first and last four characters is insufficient. Native network assets do not always have token contracts; native ETH and an ERC-20 representation should not be treated as the same record.

MetaMask’s token-safety guidance cautions against interacting with unexpected assets. A wallet’s high dollar valuation does not prove the balance can be sold. Metadata and external price matching can mislead, while liquidity and transfer or selling restrictions require separate evaluation.

For example, an unsolicited token appears with a “$3,000 reward” label and directs you to another site. A demand for payment, approval or a recovery phrase to unlock it does not validate that balance. Instead of trying to sell, send or burn the token, use the wallet’s local hide or spam-marking function. Merely receiving it does not itself grant spending access to all your assets.

3. A gasless signature can still carry authority

Some permissions are signed off-chain and can be used later. In signature phishing, the damage may not appear when the signature is collected. No gas payment and no immediate balance change are not meaningful safety tests.

Where available, inspect the chain, token, spender, amount and expiry. A Permit or Permit 2 label is not by itself evidence of fraud; legitimate applications use those mechanisms too. The question is which party receives which authority, under which limits. Do not sign unreadable content simply because a page describes the action as free.

Our token-approval checking and revocation guide explains the permission-management workflow. Disconnecting a site is not the same as revoking an on-chain allowance, and removing ordinary visible approvals may not address every kind of signed authorization.

4. Do not copy a recipient from lookalike transaction history

Address poisoning exploits familiar-looking beginning and ending characters to place a misleading entry in a wallet’s history. MetaMask’s address-poisoning guidance explains how copying from that history can send funds to the wrong destination.

Obtain the recipient from a verified address-book entry or a trusted channel with the intended recipient. Compare the whole wallet address and the selected network. A small test transfer can help catch your own destination mistake; it does not make a malicious site or contract safe.

5. If you already interacted, identify the exposure

Different wallet actions require different responses
Action takenFirst assessmentInsufficient response
Only connected an addressClose and disconnect; establish whether any later signatures or transactions occurredAssuming disconnection erases earlier approvals
Signed an approval or messageIdentify affected assets and authority; use verified official tools to determine revocation or protection optionsWaiting because nothing has moved yet
Disclosed the recovery phraseTreat the phrase as compromised; plan a fresh phrase and safe migration from a clean environmentChanging the app password or adding another account under the old phrase

MetaMask’s sweeper-bot warning explains why assets sent to a compromised wallet to pay gas can also disappear quickly. Do not repeatedly fund it without understanding the situation. The clean-device and fresh-key distinctions in our recovery-phrase backup guide matter if the phrase has leaked; another account derived from that phrase is not a clean escape route.

Preserve transaction IDs, addresses and relevant screenshots, but never post private keys in a support channel. Do not pay or disclose secrets to a “recovery expert” who contacts you privately. Recovery is not guaranteed; use verified official support to assess the specific exposure.

A repeatable check before signing

You should be able to explain three things in your own words: which site you reached, what authority you are granting and what outcome you expect. If the request does not match, stop. Our MetaMask review shows the context of permission and network controls; other wallets may name or position those controls differently.

No single indicator is a perfect filter. A verified domain, matching contract and understood action form a stronger check together. Reducing interaction with an unsolicited token is more defensible than testing it through a transaction, just as independent verification is more useful than overriding a warning.

Frequently asked questions

How can I check whether a crypto token is real or fake?

Match its network and full contract address to the project’s independently verified official record. A logo, ticker or displayed price is insufficient. Matching the genuine contract does not guarantee the project’s economic safety.

Should I transact to remove an unsolicited token?

Use the wallet’s local hide or spam-marking function instead of interacting with an unknown asset. Cleaning up the display should not require sending, burning or approving a transaction on the token’s linked site.

Can simply connecting a wallet drain it?

An ordinary connection generally shares an address; spending authority requires a separate authorization. Check what happened after connecting rather than assuming you only shared your address.

Is a message safe to sign if it costs no gas?

Not necessarily. An off-chain signature may authorize actions that can be submitted later. Understand the assets, amount, spender and expiry before signing.

Does disconnecting revoke a token approval?

No. Connection records and on-chain spending permissions are different. Each relevant allowance or suspicious authorization needs its own assessment and, where possible, revocation.

Is changing my wallet password enough after a phrase leak?

No. An app password does not stop someone who knows the keys. Plan a fresh recovery phrase in a clean environment and a safe migration; another account under the old phrase is still exposed.

PRIVACY PREFERENCES