Orca Crypto
Impersonation

Phishing emails and messages

A message that looks like it came from a service you use, built to get a click.

Loading live prices
Updated 2026-08-305 min read
The short answer

A message that looks like it came from a service you use, built to get a click. Phishing is somebody pretending to be a company you trust so you hand over something. In crypto that something is almost never a password. It is a wallet signature, a seed phrase, or a login to the exchange where your money actually sits.

What it is

Phishing is somebody pretending to be a company you trust so you hand over something. In crypto that something is almost never a password. It is a wallet signature, a seed phrase, or a login to the exchange where your money actually sits.

How it plays out

  1. It arrives looking normal

    An email from "support", a text about a suspicious login, a Discord message from a moderator. The branding is right because branding is trivial to copy.

  2. It creates a reason to hurry

    Your account is suspended. Your funds are at risk. Claim before the window closes. Urgency is the whole trick, because it stops you checking.

  3. The link goes somewhere that looks right

    A domain one character off, or a lookalike using different alphabets. On a phone the address bar truncates, which is why phishing works better on mobile.

  4. The site asks for the one thing

    A seed phrase, a wallet connection, a signature, or an exchange login with the two factor code. Any of those and it is over.

What gives it away

  • Any request for a seed phrase or private key. There is no legitimate version of this.
  • A link in the message rather than an instruction to open the app yourself.
  • Urgency, a deadline, or a threat about your account.
  • A sender address that is close but not exact, or a display name that hides the real address.
  • Contact you did not initiate. Real support does not message you first about your funds.

How to not be caught by it

  • Never click through. Open the app or type the domain yourself, every time.
  • Bookmark the real sites you use and only ever arrive through the bookmark.
  • Use a hardware wallet so a signature request has to be confirmed on a separate screen.
  • Turn on an app based authenticator rather than SMS for every exchange.
  • Treat unsolicited contact as hostile by default, including from people who seem to know you.
The hard part is not technical
None of these require technical skill to avoid. They require doing the boring check at the exact moment you feel most rushed, which is the whole difficulty.

If it already happened

  • Stop. Do not sign anything else and do not enter anything else.
  • If you signed something, move remaining assets to a fresh wallet immediately, gas permitting.
  • Revoke token approvals for the wallet that signed, then assume that wallet is burned.
  • Change the exchange password from a different device, and rotate two factor.
  • Report the domain so the next person gets a warning instead of a loss.
Recovery scams
Anybody who contacts you offering to recover lost crypto for a fee is running the second scam on the same victim. There is no recovery service that can reverse a blockchain transaction, because nobody can. Report it through official channels and ignore everyone else.

Common questions

How common is phishing emails and messages?

Common enough that it has a name and a playbook. The specific numbers move constantly, so rather than quote a figure that will be wrong next quarter: assume you will meet this one, and set your wallet up so meeting it is survivable.

Can the money be recovered?

Once a blockchain transaction confirms, no. What reporting can occasionally do is get funds frozen at the exchange where a thief tries to cash out, which is why reporting quickly is worth doing even when it feels pointless.

Does a hardware wallet stop this?

It stops anything that needs your keys, because the keys never leave the device. It does not stop you approving a malicious transaction on the device itself, so read what the screen says before you press confirm.

Where to go next

Check your setup before you need to

An hour on a screen share, going through your wallets, your approvals, your backups and your recovery plan. You click everything and we never ask for keys.