Security Center · Faq
Crypto Phishing Prevention — Frequently Asked Questions
Phishing succeeds by arriving when you expect it. The defences that work are the ones that do not depend on you noticing.
Why does phishing work so well in crypto?
Three properties make it unusually profitable: transactions are irreversible, there is no administrator to appeal to, and a single signature can transfer everything.
In most industries phishing yields credentials that must then be monetised, often reversibly. In crypto it can yield an immediate, final transfer. The economics attract far more effort, and that effort shows in the quality of the impersonation.
How does fake support work?
Someone contacts you claiming to represent an exchange, wallet, or project — very often within minutes of you posting publicly about a problem. They are helpful, patient, and steer you toward one of: revealing a seed phrase, approving a transaction, or installing "diagnostic" software.
They may know your project name, ticker, application status, or the specific error you posted. That research is what makes it work.
Two rules defeat the whole category: support never contacts you first, and no legitimate service ever needs your seed phrase.
How do I spot a lookalike domain?
You often cannot, reliably, and that is the point. Attackers use character substitutions, extra words, different TLDs, and internationalised characters that render identically to Latin ones.
So do not rely on spotting them:
- Type the domain yourself, or use a bookmark you created by typing it.
- Never reach a financial site from a search result — paid impersonation ads on brand searches are routine.
- Never follow a link from a message about your account.
- Use a password manager. It will not autofill on the wrong domain, which is a far more reliable detector than your eyes.
Why are passkeys better against phishing?
A passkey is a cryptographic credential bound to your device and to the specific domain. Your browser will only offer it to the real site.
That closes the gap TOTP leaves. A six-digit code can be relayed: a fake site asks for it and forwards it to the real one in real time. A passkey cannot be relayed, because there is nothing to type and the credential simply will not be offered to a lookalike domain.
CoinDock supports passkeys alongside app-based 2FA. See how to set up 2FA.
What is address poisoning?
An attacker sends a tiny or zero-value transaction to your wallet from an address whose first and last characters match one you have used before. It then sits in your transaction history.
Later, when you copy an address from history rather than from the source, you may copy theirs. Since most people verify only the first four and last four characters, it passes inspection.
Defence: check the middle of the address, use saved and labelled addresses rather than history, and send a test transaction for anything significant.
Are hardware wallets immune to phishing?
No. A hardware wallet protects the key, not the decision.
Phishing that persuades you to sign a malicious approval works exactly the same — you will approve it on the device, because you believe the transaction is legitimate. The device confirms what you are signing, which helps only if you read it.
Hardware removes remote key theft. It does not remove authorisation risk, which is the more common loss.
What about malicious browser extensions?
A real and under-discussed path. An extension with permission to read and modify page content can alter displayed addresses, inject prompts, or capture what you type.
- Install as few extensions as possible, especially on the browser you use for crypto.
- Review their permissions. "Read and change all your data on all websites" is total access.
- Consider a separate browser profile, or a separate browser entirely, used only for crypto with no extensions.
I clicked a phishing link but did not sign anything. Am I compromised?
Probably not. Visiting a page does not move funds — a transaction requires a signature you approve.
To be sure: check that you did not sign anything, review your wallet's approvals, and watch for anything unexpected. If you entered credentials, change that password and revoke sessions. If you entered a seed phrase, treat the wallet as permanently compromised and move funds immediately.
If you downloaded or ran anything, treat the device as suspect and move funds from a different, clean machine.
What should I do immediately after interacting with phishing?
Order matters — secure first, investigate later:
- Move funds from a clean device to a wallet whose seed never touched the suspect machine.
- Revoke approvals on the affected wallet.
- Assume the seed is burned if it may have been exposed; generate a new wallet.
- Secure surrounding accounts — email first, then exchange: password, sessions, trusted devices, API keys, withdrawal allowlist.
- Then capture evidence and report.
Someone offered to recover my stolen funds. Is that legitimate?
No. Treat every unsolicited recovery offer as a second fraud.
Recovering on-chain funds is generally not possible, and anyone charging a fee to attempt it is selling that impossibility. These approaches specifically target people who have just lost money — often within hours of a public post about it, which is one reason to be careful how publicly you describe a loss.
Related
Related on Security Center
-
Account Protection FAQ
The account-level controls CoinDock provides, what each one actually stops, and how to configure them.
-
Common Crypto Scams
Each scam here has a mechanism and a specific check that defeats it. Knowing the mechanism matters more than memorising...
-
How to Report Phishing
Secure yourself first, capture evidence second, report third. In that order — reporting does not stop an active compromi...
-
Security Glossary
Definitions of the security terminology used across CoinDock's guides.
-
Charting FAQ
Direct answers about charting, including honest ones about how much it can be relied on.
Review CoinDock Security Standards
Continue your CoinDock journey.
Go