A wallet popup asks you to sign setApprovalForAll for a free NFT claim. What is happening?
It grants blanket transfer permission over a collection, standing until revoked. A genuine free claim never needs authority over things you already own.
You post a question in a project group and get a private message from support ninety seconds later. This is:
Bots watch public groups for anyone asking for help. Names, photos and badges are all trivially copied, and support desks essentially never initiate contact.
The single most reliable way to reach a crypto site you use regularly is:
Paid adverts sit above organic results and drainer operators buy them constantly. A bookmark you made when you knew the domain was right removes the entire attack surface.
Address poisoning works by:
The attacker sends a dust transaction from an address matching yours at the start and end. Later you copy from your own history and send to them, and nothing was hacked at all.
You are told to hurry because an offer expires in ten minutes. The correct response is:
Urgency is not a side effect of these attacks, it is the mechanism. It exists specifically to stop the boring check that would end the whole thing.
Which of these can a hardware wallet NOT protect you from?
The device protects the key, not your judgment. If you press confirm on a malicious transaction after reading it, the device does exactly what you told it to.
Somebody offers to recover crypto you lost to a scam, for a fee. This is:
Nobody can reverse a confirmed blockchain transaction, so there is nothing to sell. Recovery offers target people who have just proven they can be persuaded.
What does revoking a token approval actually do?
It cancels future authority, not past transfers. Wallets drained months after the fact are almost always an old approval being called, which is why periodic revocation matters.
Work through what you got wrong
A session is one to one and screen shared, on your own accounts, at your pace. We never ask for keys and you click everything yourself.