Crypto scams usually succeed by pushing a user to act before verifying what is happening. An attacker may copy an official website, impersonate support, promote a fake token, request a seed phrase, or create a transaction that grants dangerous permissions. The safest response is to pause and verify the link, wallet prompt, contract, recipient, and requested action independently.
This guide focuses on practical prevention. For a detailed explanation of individual scam patterns, read Common Crypto Scams Explained .
Quick answer
Never reveal a seed phrase or private key. Do not trust links supplied by unsolicited messages. Confirm domains through an independently verified source, read every wallet request, avoid unnecessary unlimited approvals, verify recipient addresses, and reject pressure to act immediately. A legitimate service should not require recovery secrets or remote access to your device.
Before clicking a crypto link
- Open the project through a previously verified bookmark or official documentation.
- Check the complete domain, including spelling, subdomains, and domain ending.
- Do not assume a sponsored search result is official.
- Treat shortened links and unexpected QR codes as unverified.
- Be cautious when a social reply or direct message claims to provide support.
Logos, copied page designs, HTTPS, and familiar wording do not prove that a website is legitimate. Compare the address against an independent official source. See How to Check Official Links for a more detailed verification process.
Before connecting a wallet
Connecting a wallet normally exposes the selected public address to the website. It should not require a seed phrase or private key. Before connecting, confirm why the website needs the connection and whether a read-only action can be completed without it.
- Use a separate wallet for unfamiliar applications and claims.
- Keep long-term holdings away from experimental websites.
- Disconnect sessions that are no longer needed.
- Do not treat a successful wallet connection as proof that the site is safe.
Before signing a message
A signature can represent login, ownership verification, an order, or a permission with financial consequences. Read the wallet prompt and reject requests that are unclear, unreadable, unrelated to the expected action, or presented with artificial urgency.
- Check the requesting domain and selected account.
- Confirm that the message matches the action you intended.
- Be suspicious of blind signing and unexplained structured data.
- Do not sign merely because a support account tells you to do so.
Before approving token access
A token approval can allow a smart contract to spend tokens from a wallet. The approval transaction is separate from the later transfer, so a malicious spender may remain dangerous after the original website is closed.
- Verify the spender contract and token contract.
- Prefer a limited allowance when the application supports it.
- Reject approval for an unrelated token or unexpected amount.
- Review and revoke permissions that are no longer required.
Learn how allowances work in What Is Token Approval?. If an approval is no longer trusted, review How to Revoke Token Approval Safely .
Before sending crypto
- Verify the destination address using more than one trusted channel.
- Confirm the network, token contract, amount, and destination format.
- Recheck the beginning and end of an address after pasting it.
- Use a small test transfer when the situation justifies it.
- Never send funds to unlock a prize or receive a larger amount in return.
Blockchain transfers are often difficult or impossible to reverse. A copied address can be replaced by malicious software, and an attacker may imitate a familiar address using similar characters. Pause after pasting and verify before confirming.
Warning signs that should stop the interaction
- A website or person requests a seed phrase or private key.
- Support contacts you first through a direct message.
- A claim requires an unrelated token approval.
- A message promises guaranteed profit or risk-free returns.
- You are told to install remote-control software.
- The website creates urgency through a countdown or threat.
- The wallet prompt does not match the action shown on the page.
- You are asked to send funds before receiving a giveaway or recovery.
What to do after a suspicious interaction
The correct response depends on what occurred. Opening a link is different from connecting a wallet. Connecting is different from signing, approving, transferring assets, or revealing recovery secrets.
- Stop interacting with the website or account.
- Record the domain, transaction hash, contract, and wallet prompts.
- Check recent transactions and token approvals using trusted tools.
- Revoke suspicious allowances when it is safe to do so.
- Move assets only when wallet compromise is reasonably suspected.
- Use a clean device and new wallet if recovery secrets were exposed.
If you only clicked a suspicious link, review What to Do After Clicking a Suspicious Link . Revealing a seed phrase or private key should be treated as a more serious wallet-compromise event.
Compact crypto scam prevention checklist
- Verify the domain independently.
- Never share recovery secrets.
- Read the complete wallet request.
- Check token and spender contracts.
- Confirm recipient addresses and networks.
- Use separate wallets for higher-risk activity.
- Reject unsolicited support and urgency.
- Review old token approvals regularly.
- Keep software and wallet extensions updated.
- Pause whenever the requested action is unclear.
Can a legitimate service ask for a seed phrase?
A legitimate wallet, exchange, DEX, support representative, claim page, or recovery service should not ask you to send a seed phrase or private key. Recovery words are used locally to restore control of a wallet. Anyone who obtains them may be able to control the associated assets.
Does disconnecting a wallet remove approvals?
No. Disconnecting a website session does not automatically revoke on-chain token allowances. Existing approvals must be reviewed separately and, when appropriate, revoked through a trusted interface or direct contract interaction.
Is every unexpected token or airdrop a scam?
Not every unexpected token is malicious, but an unknown token should not be treated as trustworthy. Avoid visiting URLs embedded in token names, do not approve unknown contracts, and verify claims through independent official sources.
Final safety principle
Crypto security depends on verifying the exact action before authorizing it. Slow down, separate low-trust activity from valuable assets, inspect wallet permissions, and reject requests for secrets. No checklist can eliminate every risk, but consistent verification can prevent many common scams.
Eonwell does not recommend any specific wallet, exchange, token, DEX, blockchain, security tool, approval checker, recovery service, or investment. This page provides neutral education and is not legal, financial, investment, tax, cybersecurity incident-response, or asset-recovery advice.