104 · The long haul · lesson 1 of 5
Phishing and everyday safety — the attack that actually gets people
Attackers almost never break the cryptography. They impersonate someone you trust and ask you to hand it over. Phishing is the number-one real-world way Bitcoin is stolen, and a handful of calm habits defeat nearly all of it.
Here is the reassuring truth that gets buried under scary headlines: the cryptography protecting your Bitcoin is extremely strong, and attackers essentially never break it. Instead they go around it — they trick you into typing your words somewhere, clicking something, or approving a payment you shouldn’t. That means your day-to-day habits, not your gear, are what actually keep you safe.
This page covers the digital side of that. The physical side — not being identified as a holder in the first place — is its own lesson later in this level.
Phishing is the number-one threat, so treat every unexpected message as a trap
Phishing is when someone pretends to be a company you trust (an exchange, your hardware wallet maker, "support") to trick you into giving up your secrets or approving a bad payment. It is by far the most common way Bitcoin is stolen — the large majority of thefts trace back to some version of it. (The most common way it's lost is still you — but theft is this lesson's business.)
The stakes are worth one reminder: your seed phrase can restore your entire wallet, so anyone who gets those words can take everything.
Four rules defeat almost all phishing:
- Never type your seed phrase into a website, app, or chat box. Ever. The only place those words ever go is into your hardware wallet during setup or recovery, and onto your paper or metal backup. No real company will ever ask you to type them anywhere else. If something asks, it is an attack.
- Never trust a link in an email or text. Type the address yourself, or use a bookmark you saved earlier. A fake site at "ledqer.com" looks just like "ledger.com" to a tired human.
- Check surprises through a separate channel. If your exchange "emails" you about urgent action, do not click. Open a fresh browser and go to the site directly. If "support" calls you, hang up and call back using the number on the official website.
- Let a password manager do the checking for you. A password manager (like Bitwarden or 1Password) will refuse to fill in your login on a fake copycat site. When it won't autofill, that is your warning sign, not a glitch.
No legitimate company ever contacts you first asking for your password or seed phrase. If someone reaches out to you that way, treat it as a scam.
Why it works — the three parts every one of these has
Every scam on this page is the same three parts wearing different clothes. Learn the parts and you can classify a message you have never seen before, which is worth far more than a list of scams to memorise:
- A pretext you already trust. Not a stranger — your exchange, your wallet maker, a support agent, a friend's account. The whole attack rests on borrowing credibility that already exists, because building it from scratch is the hard part.
- A reason it has to be now. An account closing, a suspicious login, a recall on your device, a deadline to claim something. Urgency is not decoration; it is the working part. It exists to stop you doing the one thing that defeats the whole attack — checking through a channel they don't control.
- A request that only makes sense if the first two are true. Type your words here. Approve this. Install that. Move your coins to a safe address.
So the four rules above are not arbitrary — they are what falls out of that shape. The pretext is defeated by contacting the company yourself, at an address you already had. The urgency is defeated by waiting. And the request is defeated by one fact that never has an exception: no real company, ever, for any reason, needs your seed phrase. A message asking for it has identified itself, whatever else it got right.
Which is also why the defences people expect to save them don't:
- Checking the sender's address catches a lazy attacker and nothing else — addresses are trivially forged and lookalike domains are cheap.
- The padlock in the address bar means the connection is encrypted, not that the site is who it claims.
- Antivirus does not read your mind about a payment you approved yourself.
- Text-message codes protect an account login, not a wallet you control.
- Owning a hardware wallet protects you only up to the moment you type your words into something — which is precisely what you are being asked to do.
None of these are useless; they simply defend a different door from the one being knocked on.
Fake apps, fake sites, fake “support”
The same impersonation trick works on software. A fake wallet app sits in an app store looking exactly like the real thing, waits for you to type your recovery words in to “restore” your wallet, and empties it. Fake websites do the same job: a search-engine ad for “ledger wallet” can sit above the real result and send you to a copy.
Three habits close this off:
- Only download wallet software from the maker’s official site, typed in yourself or reached from a bookmark you saved earlier — never from a search ad, and never from a link someone sent you.
- Never type your seed phrase into software to “restore” unless you deliberately started that recovery yourself, on a device you chose, at a moment you planned. Recovery is something you initiate. It is never something that gets asked of you.
- Be suspicious of urgency. Every version of this attack needs you to move fast. Nothing about your Bitcoin is ever so urgent that it can’t wait an hour while you check through a channel you trust.
The physical version of this — a tampered device bought from the wrong place — is covered back in Choosing a hardware wallet, where you bought it.
Keep your Bitcoin machine boring
The computer or phone you use for Bitcoin should be the most boring device you own. Few apps, no random browser add-ons, no pirated software, and kept up to date. You are not trying to build a fortress — you are trying to avoid installing the thing that watches your clipboard.
Two small habits that pay for themselves:
- Move addresses by QR code when you can. Scanning is harder to tamper with than copy-and-paste, which is exactly what clipboard malware attacks.
- Let a password manager do your checking. Bitwarden or 1Password will refuse to autofill your login on a copycat site. When it won’t fill, that is not a glitch — that is the warning.
The biggest risk is a rushed you
Across every expert source, the most common cause of lost Bitcoin is not an attacker at all — it is the owner making an avoidable mistake while hurried. Every scam on this page is built to manufacture that hurry: the urgent email, the account that will be closed today, the support agent waiting on the line.
So the last habit is the simplest one. Never operate your wallet when you are tired, stressed, upset, or being rushed. A legitimate payment can always wait an hour, or until the morning. Nothing that is genuinely yours disappears because you slept on it — and Bitcoin payments cannot be undone, so the hour costs you nothing and can save you everything.
If someone requires your seed words for any reason, they’re trying to steal your Bitcoin. Not your wallet maker, not your exchange, not support, not a “migration,” not a security check. No legitimate service ever needs them, so you never have to weigh up how convincing the story is — the demand itself is the answer. The only time those words are typed anywhere is a recovery you started, on a device you chose.
- Never type your seed phrase into any website, app, or chat — and treat anything that requires it as theft in progress, however convincing the reason sounds.
- Treat every unexpected email, text, or call as a scam; verify by typing the address yourself or calling back on the official number.
- Download wallet software only from the maker’s official site, reached by a bookmark or typed by hand — never a search ad or a sent link.
- Let a password manager autofill your logins; when it refuses, you’re on a fake site.
- Keep the device you use for Bitcoin boring: few apps, no random extensions, kept updated.
- Move addresses by QR code rather than copy-and-paste where you can.
- Only operate your wallet when calm and unhurried — every version of this attack needs you rushed.
Check yourself
2 questions on what this lesson just covered. Nothing is scored, recorded or saved — it isn’t sent anywhere and it’s gone when you close the tab.
1An email from your hardware wallet’s maker warns of a firmware flaw and asks you to enter your recovery words on their site to move to a safe wallet. The sender’s address is correct and the site shows a padlock. What do you do?
No legitimate service ever needs your seed words, for any reason — so there is no story to weigh up and no judgement call to make. The demand itself is the answer, whatever else the message got right. The padlock only means the connection is encrypted, not that the site is who it claims to be; a sender address is trivially forged, and lookalike domains are cheap; and a phone number printed inside the message reaches whoever wrote it. The only time those words are typed anywhere is a recovery you started, on a device you chose, at a moment you picked.
2Nearly every version of this attack includes a reason it has to happen right now. Why is the urgency there?
Urgency is not decoration; it is the working part. The attack borrows credibility you already extend to a company you trust, then needs you to act before you do the one thing that defeats it — contacting them yourself, at an address you already had. So the defence is simply to wait. Nothing about your Bitcoin is ever so urgent that it cannot wait an hour, and the same rule covers more than scams: never operate your wallet while tired, stressed, upset or being rushed. A hurried owner is the most common cause of loss there is.
✓ Last verified: August 4, 2026