Digital Asset Self-Custody HubGet the App
← Back to Self-Custody Hub

How to Recognize a Phishing Attempt

This guide covers how to spot phishing attempts aimed at self-custody users. It's meant to be run through quickly whenever a message, call, or request feels slightly off.

Recognition Steps

  1. Treat urgency or pressure to act immediately as a warning sign in itself, rather than a reason to move faster than you normally would.
  2. Check sender addresses and domains character-by-character, since substituted letters, extra characters, and lookalike domains are extremely common in these attempts.
  3. Never enter a seed phrase or private key into any website, form, or chat, no matter how official or urgent the request appears.
  4. Verify unusual requests through a separate, already-known channel before acting on them, rather than replying through whatever channel the request arrived on.
  5. Be wary of unsolicited contact that references your account activity or a supposed problem, since that framing is designed to feel urgent and personal.

What to Watch For

No legitimate support process ever needs your seed phrase or private key, and no legitimate organization will ask you to read one aloud or type it anywhere. Any message that asks for one, however it's framed or however official it looks, should be treated as an attempt to gain access.

For a broader look at common attack patterns, see Security Awareness, and for how to double-check requests before approving them, see How to Verify a Transaction Before Approving It. Building the habit of pausing on unexpected contact is one of the simplest, highest-value defenses available.