10 screens. Decide, then find out
Each one is a moment where somebody would have had to make a call. Pick an answer and the tells are revealed underneath, along with the habit that would have caught it.
A swap site you reached from a search result
You searched for the DEX you always use and clicked the first result. This is what loaded.
What would you do?
What gives it away
- The real site is tidepool.fi. This is tidepool-swap.app, a different domain that anyone can register.
- It was the first search result because it is a paid advert. Paid ads sit above organic results, and drainer operators buy them constantly.
- The padlock means the connection is encrypted, not that the site is honest. Any site can get a certificate in minutes, free.
- Everything else is a pixel accurate copy, because copying a front end is a weekend of work.
Reach sites you use from your own bookmarks, never from search. If you must search, check the domain character by character before you connect anything.
A signature request during an airdrop claim
You clicked claim on an airdrop page and your wallet popped this up. The claim is free, so there is no payment to approve.
What would you do?
What gives it away
- setApprovalForAll hands one address permission to move every token in a collection, at any time, for as long as the approval stands.
- A free claim needs a claim function. It never needs blanket approval over things you already own.
- The operator is an address you have never seen and cannot check from inside this popup.
- The fee is tiny, which is the point. The cost is not the gas, it is the permission.
Read what the wallet says the transaction does, not what the website said it would do. Reject anything granting approval you did not ask for, and review your open approvals periodically.
A page asking you to restore your wallet
Your wallet showed a zero balance after a network glitch. A search for help led here.
What would you do?
What gives it away
- A recovery phrase is the wallet. Anything holding it can move everything, instantly, from anywhere, forever.
- No wallet, exchange, support agent or website ever needs it. Not to fix a balance, not to validate, not to migrate, not to unlock support.
- A zero balance is almost always the wrong network selected or a node problem, and it costs nothing to check that first.
- The word validate is doing the work here. There is no such process.
The phrase goes on paper and never anywhere else. No photo, no cloud, no password manager note, no form. If you have typed it into anything at all, move your funds to a new wallet now.
A swap confirmation on a site you opened from a bookmark
You opened your usual DEX from a bookmark, entered an amount, and pressed swap.
What would you do?
What gives it away
- The domain matches the site you actually bookmarked.
- The function is a swap, which is what you asked for, and both sides of the trade are shown with a minimum received.
- No approval is being granted here beyond the swap itself.
- Nothing on screen is rushing you, and the numbers match what the interface quoted.
This one is fine. Recognizing normal is as important as recognizing wrong, because a simulator where everything is a scam just teaches you to freeze.
A direct message minutes after you asked for help
You posted a question in a project group chat. Ninety seconds later this arrived privately.
What would you do?
What gives it away
- Real support does not message you first. This is close to universal across every wallet and exchange.
- The account name is free to set. Anyone can be Kelpwave Support with the same photo in about ten seconds.
- It arrived because you posted publicly. Bots watch project groups for exactly that and message everyone who asks a question.
- The fifteen minute deadline exists to stop you checking anything, which is the whole mechanism.
Turn off direct messages from non contacts. Treat every unrequested message as hostile, and if you need support, start from the official app or site yourself.
An address that changed between copy and paste
You copied your exchange deposit address and pasted it into your wallet. This is the confirmation screen.
What would you do?
What gives it away
- The first four and last four characters match. Everything in the middle does not, which is exactly what clipboard malware is designed to exploit.
- People check the ends of an address because the whole thing is unreadable. Attackers generate addresses that match the ends for that reason.
- The swap happens silently on your own machine, between the copy and the paste. Nothing on the website is involved.
- Once sent, it is gone. There is no reversal on any chain.
Check the middle of the address, not just the ends, or better, send a small test amount first and confirm arrival before sending the rest.
A surprise mint in an official announcements channel
You hold an NFT from this collection. This appeared overnight in the real announcements channel, posted by the real bot.
What would you do?
What gives it away
- Coming from the real channel proves the channel was compromised, not that the message is real. Moderator accounts and webhooks get stolen constantly.
- Surprise, holders only, going fast and a thirty minute timer are four pressure devices in three sentences.
- The link is a different domain from the project site, which is the one detail people skip when they are hurrying.
- Overnight posting is deliberate. It maximizes the window before a real moderator wakes up and deletes it.
Cross check any announcement against the project's other channels before acting, and never connect your main wallet to a mint. Use a wallet holding nothing but gas.
An official bridge warning you about a seven day wait
You are withdrawing from a layer 2 back to Ethereum using the network's own bridge.
What would you do?
What gives it away
- The seven day wait is the challenge period an optimistic rollup uses. A bridge that explains a delay rather than hiding it is behaving correctly.
- The domain is a subdomain of the network's own site, not a lookalike.
- Nothing is rushing you and nothing is being approved beyond the withdrawal itself.
- Third party bridges offer instant exits for a fee. That is a real service, not a scam, but it is a different trust assumption.
This is fine. A slow official bridge is usually the safer of the two options, and being suspicious of a normal delay is its own kind of mistake.
A reply under a post from a project you follow
A project you follow posted an update. This reply sits directly underneath it with a lot of engagement.
What would you do?
What gives it away
- The handle is @tidepool_finonce, not @tidepool_fin. One character, placed where nobody reads.
- The verified badge is bought, not earned. It costs a few dollars a month and proves nothing about identity.
- Send money to receive more money back is the oldest fraud there is, and it has never once been real.
- The engagement is bought too. Replies and likes cost a fraction of what a single victim returns.
No legitimate project has ever asked you to send crypto to receive crypto. Not once. Treat that sentence alone as sufficient evidence, whatever else the account looks like.
A wallet app listing with strong reviews
You are installing a wallet on a new phone and searched the app store for it.
What would you do?
What gives it away
- The developer name is not the real company. That single field is the most reliable check in any app store and almost nobody looks at it.
- Reviews are bought in bulk. A five star average across twelve thousand ratings costs less than one stolen wallet returns.
- Fifty thousand downloads sounds like a lot until you compare it with the real app, which has millions.
- A counterfeit wallet generates a seed phrase the attacker already knows, so it drains on a delay, sometimes months later.
Install wallets only from the link on the project's own website. Check the developer name against the real company, and treat a recently published listing as a red flag.
Done
Ask them in this order
Did I go looking for this, or did it arrive?
Almost every loss starts with something that arrived: a message, a reply, a search advert, a notification. Anything unrequested is hostile until proven otherwise, including things that look official.
Is the domain exactly right?
Not nearly right. Exactly. Read it character by character, and notice that a padlock says the connection is encrypted, not that the site is honest.
What does my wallet say this does?
The website tells you what it wants you to think. The wallet tells you what will actually happen. When those two disagree, the wallet is right.
Why am I in a hurry?
Every one of these needs you to act now. If waiting ten minutes and checking independently would cost you the opportunity, it was not an opportunity.
Four settings, done once
Phrase on paper only
No photo, no file, no cloud note, no form on any site. This alone prevents the total losses.
Seed phrase securityHardware wallet for real size
A second screen that a website cannot fake, between a malicious page and your keys.
Hardware walletsBookmarks, never search
Most drainer traffic arrives through paid adverts sitting above the real listing.
Phishing and drainersA burner wallet for anything new
Mints, claims, unfamiliar apps. Gas and nothing else, so a bad signature costs nothing.
Token approvalsGo through your real setup
We look at what you actually hold, check your open approvals, fix the weak points and set up a recovery plan. You click everything and we never ask for keys.