Skip to content
buybitcoinsmart

Glossary / Privacy & security

Phishing

Definition
Phishing is a fake message or website built to look like your exchange, wallet, or hardware wallet vendor, so that you hand over a password, a code, or your seed phrase.

Crypto pays phishers better than card fraud does, because there is no chargeback and no issuer to call. The FBI's 2023 cryptocurrency fraud report counted more than 69,000 complaints and losses above 5.6 billion dollars, and one hardware wallet vendor's leaked customer file put 272,853 home delivery addresses into circulation as a targeting list. Anything that asks for your twelve or twenty-four recovery words is theft, without exception.

How it works

Phishing against bitcoin holders comes in four shapes, and they call for different defenses.

Credential phishing copies an exchange login page onto a lookalike domain, usually reached through a search advertisement, a fake "unusual login detected" email, or a mistyped URL. The modern version is a live relay: whatever you type, including your authenticator app code, is forwarded to the real site within seconds, so the six-digit code being correct proves nothing. Only a hardware security key survives this, because the key signs the domain it is actually talking to and simply refuses to produce anything usable for a lookalike.

Seed phrase phishing skips the account and goes for the wallet. It arrives as a "wallet validation" form, a fake firmware update, a support agent who needs to "sync your device", or a browser popup claiming your funds are at risk. The recovery words are the wallet: BIP39 turns those twelve or twenty-four words into every private key you will ever hold, so anyone who reads them can rebuild your entire wallet on their own machine and empty it at leisure. No manufacturer, exchange, or support team has any legitimate reason to see them, ever.

Signature phishing asks you to approve something you cannot read. This is mostly an Ethereum problem, where a single signature can grant unlimited spending permission on a token, but bitcoin users meet a version of it when asked to sign an unfamiliar partially signed transaction or an arbitrary message.

Impersonated support blends into social engineering: a reply on X or Telegram from an account with the right logo, appearing within minutes of you posting a problem publicly. Genuine support never contacts you first.

Why this matters when you buy bitcoin

The defenses that actually stop phishing are configuration choices you make once, not vigilance you sustain forever.

Reach your exchange the same way every time. Bookmark the domain and use only that bookmark, never a search result and never a link in an email. Our review pages list the official website for each of the 24 exchanges we cover, which gives you a second place to check a URL against.

Put a hardware security key on the account. Kraken and Coinbase both support FIDO2 keys, and they are the one factor that a real-time relay attack cannot forward. If a key is not an option, an authenticator app still beats text messages.

Turn on a withdrawal address whitelist, so that a stolen session cannot invent a destination.

Treat the recovery words as write-once. They go onto paper or metal during setup and are never typed into a phone, a computer, a photo, a password manager, or a form. A hardware wallet asks for them on its own screen during setup or recovery, and at no other time. If any software asks, the software is hostile no matter how convincing the logo.

Finally, slow down on anything that arrives with a deadline. Urgency is the one ingredient every phishing message shares, because a person who has time to check the address bar stops being a victim.

The Ledger customer list, still being mined years later

In July 2020 Ledger disclosed that its e-commerce and marketing database had been breached, exposing roughly one million email addresses along with a smaller set of detailed customer records.

In December 2020 the full dump was published openly: 272,853 order records containing names, phone numbers, and physical shipping addresses of people who had bought a hardware wallet. That is a list of households known to hold cryptocurrency, complete with where they live.

What followed is the reason this page names the incident. Victims received phishing emails and texts styled as Ledger security notices for years afterward. In 2021, some received parcels containing counterfeit Ledger devices with a note claiming the original was being replaced for security reasons, and instructions to enter the existing recovery phrase into the new hardware. Others received extortion messages referencing their home address.

The lesson generalizes beyond one company. Data taken from a vendor's marketing systems is enough to make phishing personal and credible, and it does not expire. Assume that a company you bought bitcoin hardware or services from will leak your details at some point, and build a setup where that leak is embarrassing rather than expensive.

Phishing vs social engineering

Phishing is a technique inside the wider practice of social engineering. Social engineering names any attack that persuades a human to act against their own interest; phishing is the mass-produced, message-based version of it, sent to thousands of people in the hope that a fraction respond. The distinction matters when choosing defenses. Phishing is largely solvable with technology, since security keys, bookmarks, and whitelists work whether or not you are paying attention. Broader social engineering, especially a live phone call tailored to you, needs procedural rules instead: never move funds because an inbound contact asked you to.

Phishing vs pig butchering

Phishing wants a credential in the next sixty seconds; pig butchering wants a relationship over the next six months. A phishing message impersonates a service you already use and is designed to be acted on immediately, before you think. Pig butchering builds trust through weeks of ordinary conversation, then introduces an investment platform that shows fake profits and permits an early withdrawal to prove it works. Losses from the second are typically far larger, because the victim funds them voluntarily, repeatedly, and with money they went out and raised.

Not to be confused with

Frequently asked questions

Will a real exchange or wallet company ever ask for my seed phrase?

Never, under any circumstances. Support cannot use it, does not need it, and is not permitted to ask. A request for your recovery words identifies the sender as an attacker faster than any other signal, regardless of how official the branding looks.

My authenticator code was correct, so how did the fake site get in?

Modern phishing sites relay your input to the real service in real time, so a valid code is simply passed through within its 30 second window. A FIDO2 security key blocks this because it signs the domain name, which the fake site cannot match.

I entered my details on a fake exchange page. What now?

Act in this order: change the password from a device you trust, revoke all active sessions and API keys, re-enroll two-factor authentication with a new secret, and withdraw funds to a wallet you control if the account still responds.

Why do I get phishing emails about a hardware wallet I bought years ago?

Because vendor customer lists have leaked and circulate indefinitely. The 2020 Ledger e-commerce breach alone published 272,853 order records with names and home addresses, and that data still drives targeted emails, texts, and physical extortion attempts.

Read next

Related terms

More in Privacy & security