Phishing
Fraud using fake emails, text messages, websites or calls that look like genuine exchanges, wallet makers or banks. The goal is your passwords, 2FA codes – and above all your seed phrase.
Alsophishing emailsmishingfake websitevishingcredential phishing
Phishing, a blend of ‘password’ and ‘fishing’, means scammers fishing for login details. They pose as a bank, a service provider or a public authority and lure you to fake websites by email, text message (‘smishing’) or phone call (‘vishing’).[1] With Bitcoin, they are mainly after your seed phraseGlossarySeed phrase (recovery phrase)A sequence of usually 12 or 24 words from which your wallet derives all its private keys. Anyone who knows the words has full access to your bitcoin – so they belong in an offline backup and never in anyone else’s hands.On the learning path: Stage 5 · Step 3 – Backing up your seed phrase →In the glossary →. Anyone who knows it can empty your wallet – and the money can practically never be recovered.[2]
Typical schemes and how to protect yourself
- Fake warnings styled like a wallet maker’s: you’re asked to ‘confirm’ your words or install an ‘update’. Never enter your seed phrase anywhere – except when restoring it in your own wallet. Only get apps and updates from the official app store or the maker’s website.
- Fake login pages with a slightly altered web address, linked from emails, ads or chats: only open your exchange and wallet via a bookmark or the official app.
- Fake support by direct message, shortly after you’ve asked for help in public: legitimate companies never ask for your seed phrase, passwords or security codes.[2]
The European financial supervisory authorities also name time pressure (‘Your account will be blocked in 24 hours’) as a warning sign.[2] Two-factor authenticationGlossaryTwo-factor authentication (2FA)Logging in with two independent proofs, such as a password plus a code from an authenticator app. For accounts with exchanges and Bitcoin apps, 2FA is a must – and SMS codes are the weakest option.On the learning path: Stage 4 · Step 3 – Buying Bitcoin →In the glossary → using an app or a security key adds protection. More schemes: Spotting & avoiding scams.
Test yourself
Genuine or scam?
0/3 points
We have detected unusual activity. Confirm your recovery words within 24 hours using the link below, or your wallet will be deactivated.
How to tell
- No legitimate company asks for your seed phrase.
- Artificial time pressure (‘within 24 hours’).
- Nobody can ‘deactivate’ a self-custody wallet.
New sign-in from an unknown device. If this wasn’t you, change your password in the app settings.
How to tell
- No link, no request for data.
- Points you to the app you open yourself anyway.
Your parcel (hardware wallet) is awaiting customs clearance. Please pay a €1.99 fee: parcel-customs.example
How to tell
- Unexpected text message with a link (‘smishing’).
- Small amount used as bait for your card details.
- An unfamiliar address instead of the sender’s official website.
We will never contact you via a messenger or ask for your seed phrase.
Related terms
These terms are closely connected.
- This termPhishing
- Seed phrase (recovery phrase)A sequence of usually 12 or 24 words from which your wallet derives all its private keys. Anyone who knows the words has full access to your bitcoin – so they belong in an offline backup and never in anyone else’s hands.
- Two-factor authentication (2FA)Logging in with two independent proofs, such as a password plus a code from an authenticator app. For accounts with exchanges and Bitcoin apps, 2FA is a must – and SMS codes are the weakest option.
- SIM swappingFraudsters get your mobile number transferred to their own SIM card and so receive your text-message codes. They use this to take over accounts that are only protected by SMS. Protection: 2FA via an app or security key instead of SMS.
- Hot walletA wallet whose private keys are stored on a device connected to the internet – such as a smartphone app. Handy for payments and small amounts, but more exposed to online attacks than cold storage.
- Wrench attack ($5 wrench attack)An attack using violence or threats instead of technology: criminals force Bitcoin owners to unlock their wallet or transfer bitcoin. The best protection is discretion – if nobody knows you own bitcoin, you are less likely to become a target.
Explained in depth
These articles go into more detail:
- Stage 6 · Step 2Spotting scamsPhishing, fake support, investment and romance scams, AI fakes: how to spot 13 typical Bitcoin scams – and what to do if the worst happens.
- Deep dive · Stage 6Security checklistThree checklists to tick off – basics, your own hardware wallet, significant holdings: how to secure your account, wallet and seed phrase step by step.
More from „Wallets & security“
Sources2 sources · 2 publishers
The superscript numbers in the text refer to these sources.
- Passwortdiebstahl durch Phishing (password theft through phishing) – Bundesamt für Sicherheit in der Informationstechnik (BSI, Germany’s Federal Office for Information Security) (accessed 28/09/2026)
- Krypto-Betrug – Seien Sie wachsam und schützen Sie sich (crypto fraud factsheet, German version) – EBA, EIOPA and ESMA, 15.12.2025 (accessed 28/09/2026)
This entry is for education only and is not investment, tax or legal advice.