Thirteen attacks, and what each one needs from you
Almost nobody loses crypto to cryptography. They lose it because they were persuaded to sign something, or told somebody a phrase, or trusted a face on a screen.
Phishing emails and messages
A message that looks like it came from a service you use, built to get a click.
How it worksExtortionSextortion phishing
An email claiming to have recorded you, demanding payment in crypto. It is a bluff.
How it worksMalwareRansomware
Software that encrypts your files and demands crypto to release them.
How it worksSurveillance and baitWallet dusting
Tiny unrequested amounts sent to your wallet so somebody can follow what you do next.
How it worksLong conPig butchering and romance scams
A relationship built over weeks, then an investment platform that is entirely fake.
How it worksImpersonationFake support and impersonation
Somebody posing as help, reaching you first, after you asked a question in public.
How it worksImpersonationGiveaway and doubling scams
Send one and get two back. Nobody has ever got two back.
How it worksAccount takeoverSIM swap attacks
Somebody moves your phone number to their SIM, then resets everything that trusts your number.
How it worksDrainerMalicious airdrops and claim sites
A free token you did not ask for, and a claim page built to empty the wallet.
How it worksMalwareClipboard hijacking
Malware that swaps the address you copied for one belonging to somebody else.
How it worksImpersonationCounterfeit wallets and extensions
A wallet app or browser extension that is a working copy, plus a copy of your keys.
How it worksReal worldPhysical safety and operational security
The attack that does not need any code: somebody who knows you hold crypto.
How it worksImpersonationDeepfakes and AI impersonation
Video and voice of somebody real, saying something they never said.
How it worksFour moves, in the same order, every time
Contact you did not start
An email, a message, a reply, a search advert, a wrong number. Almost every loss begins with something that arrived rather than something you went looking for.
A reason to feel something
Urgency, fear, greed or affection. The emotion is not a side effect, it is the mechanism. It is there to stop you doing the boring check that would end the whole thing.
One irreversible action
A signature, a seed phrase, a transfer, an install. Every attack narrows to a single moment where you do something that cannot be undone.
Silence afterward
By the time anything looks wrong the transaction has confirmed. There is no chargeback, no fraud department, and no reversal.
The same list, grouped
| Attack | Type | What it wants |
|---|---|---|
| Phishing emails and messages | Impersonation | A message that looks like it came from a service you use, built to get a click. |
| Sextortion phishing | Extortion | An email claiming to have recorded you, demanding payment in crypto. It is a bluff. |
| Ransomware | Malware | Software that encrypts your files and demands crypto to release them. |
| Wallet dusting | Surveillance and bait | Tiny unrequested amounts sent to your wallet so somebody can follow what you do next. |
| Pig butchering and romance scams | Long con | A relationship built over weeks, then an investment platform that is entirely fake. |
| Fake support and impersonation | Impersonation | Somebody posing as help, reaching you first, after you asked a question in public. |
| Giveaway and doubling scams | Impersonation | Send one and get two back. Nobody has ever got two back. |
| SIM swap attacks | Account takeover | Somebody moves your phone number to their SIM, then resets everything that trusts your number. |
| Malicious airdrops and claim sites | Drainer | A free token you did not ask for, and a claim page built to empty the wallet. |
| Clipboard hijacking | Malware | Malware that swaps the address you copied for one belonging to somebody else. |
| Counterfeit wallets and extensions | Impersonation | A wallet app or browser extension that is a working copy, plus a copy of your keys. |
| Physical safety and operational security | Real world | The attack that does not need any code: somebody who knows you hold crypto. |
| Deepfakes and AI impersonation | Impersonation | Video and voice of somebody real, saying something they never said. |
Six things, in order of how much they help
The seed phrase never leaves paper
No photo, no cloud, no file, no support agent, no validation page. This one rule alone prevents most total losses.
A hardware wallet for anything meaningful
It puts a second screen between a malicious site and your keys, and that screen cannot be faked by a website.
Authenticator app, never SMS
SMS two factor is only as strong as the support desk at your mobile carrier, and that has repeatedly not been strong enough.
Bookmarks instead of search
Most drainer traffic arrives through paid adverts sitting above the real site. Never search for a crypto site you already use.
A burner wallet for anything new
Claims, mints, unfamiliar apps. Fund it with gas and nothing else, and a bad signature costs you nothing.
A pause before anything irreversible
Every one of these attacks needs you to act now. Waiting ten minutes and checking independently breaks almost all of them.
Go through your own setup with somebody
We look at what you actually hold and how it is stored, check approvals, fix the weak points, and set up a recovery plan. You keep control of everything and we never ask for keys.