DeFi Intel

What is Phishing?

Plain-English explainer · Updated 2026-07-02 · By DeFi Intel

How it works

Attackers first identify a target platform—such as MetaMask, OpenSea, or a specific DeFi protocol like Uniswap. They then register a domain nearly identical to the legitimate one, e.g., 'metamask-connect.com' instead of 'metamask.io'. Using email, direct messages on Discord or Twitter, or even search ads, they distribute links to the fake site. When the user visits, the site mimics the real interface and prompts the victim to 'connect wallet' or enter their seed phrase.

Once the victim connects their wallet or enters credentials, attackers can instantly drain assets. In more sophisticated variants like 'ice phishing', the fake site requests a smart contract approval (ERC-20 approve) for a malicious contract. If the user signs this transaction, the attacker contract gains permission to transfer an unlimited amount of a specific token, enabling theft of all holdings of that token. This method bypasses the need for private keys and exploits the user's trust in standard Web3 interactions.

Advanced phishing campaigns also target hardware wallet users by distributing fake firmware updates or creating counterfeit Ledger Live software. Others exploit ENS (Ethereum Name Service) by registering similar domain names (e.g., 'uniswap.eth' versus 'un1swap.eth') and pointing them to malicious dApps. Some attackers use wallet drainer scripts embedded in fake airdrop or NFT mint sites that automatically approve token transfers when the user connects their wallet. These attacks leverage the non-reversible nature of blockchain transactions to steal funds instantly.

Why it matters

Phishing is one of the most common and effective attack vectors in crypto and DeFi because it directly targets the self-custody model. A single successful phish can empty a wallet of all funds, tokens, and NFTs—often permanently. Unlike traditional finance, there is no chargeback or recourse in most crypto transactions. As DeFi grows, phishing also undermines trust in legitimate protocols and onboarding, making security education critical. Understanding phishing is essential for any user who holds or transacts crypto assets.

Real-world examples

In 2020, a phishing attack targeted users of the Compound protocol with fake token claim sites. In 2022, OpenSea users faced a spear-phishing campaign where attackers sent fake emails about NFT delistings, leading to wallet drains. The Curve Finance front-end attack in 2022 involved a DNS hijack that redirected users to a phishing page. These incidents emphasize the need for URL verification and hardware wallet safety.

FAQ

How can I avoid phishing attacks in crypto?

Always double-check URLs, bookmark official sites, never share seed phrases, use hardware wallets, and verify transaction details before signing. Enable two-factor authentication on exchanges and avoid clicking links from unknown sources.

What is ice phishing in DeFi?

Ice phishing is a variant where attackers trick users into signing a smart contract approval (token spend permission) instead of revealing private keys. Once approved, the attacker can drain the specified tokens at any time.

How do I verify a DeFi protocol website is legitimate?

Use official links from sources like CoinMarketCap or the protocol's verified Twitter account. Check for SSL certificates, but be aware that phishing sites can also have HTTPS. Consider using browser extensions like MetaMask's phishing detection or Wallet Guard.

Related terms

Go deeper

Browse the complete crypto glossary to explore related terms and concepts.

Browse Glossary

Entities mentioned