Why you should know this
Scams often borrow real logos, names and transaction details. The defense is not “be smarter than every criminal.” It is a routine that makes urgency wait for independent verification.
Experienced people are targeted too. Familiarity can create speed, and speed is exactly what impersonators try to control.
The scammer tries to control the frame
Most social engineering combines a believable role with emotional pressure. Fear says an account will be frozen. Greed says a reward will disappear. Authority says a manager, regulator or police officer must be obeyed. Affection says a trusted friend needs help. Curiosity says an unexpected token or document must be opened.
The story can change while the requested authority stays the same. That is why we focus on the action: disclose a secret, approve a login, install software, sign a wallet message or send value. Naming the authority breaks the spell of the story.
Public profiles, leaked data and previous transactions can make a message feel personal. Correct information proves that the sender researched you; it does not prove the sender is genuine.
What phishing is trying to steal

A phishing message or page may seek:
- a password, passkey approval or one-time code;
- a private key or recovery phrase;
- an identity document or selfie;
- remote access to a phone or computer;
- a wallet connection, signature or token approval;
- a direct crypto payment to a scammer’s address.
The message is only the delivery vehicle. The dangerous moment is the secret, installation, signature or transfer it requests.
Wallet connections and signatures need their own pause
A decentralized application may ask a wallet to connect, sign a message or approve a token. These are not identical actions. A connection can expose addresses; a signature may prove control or authorize a defined action; a token approval can let a contract move assets within its permission.
Read the wallet’s transaction preview and the application’s official documentation. If the prompt is unreadable, unlimited, unrelated to the task or triggered by an unsolicited link, reject it. A “free mint,” refund or account check does not earn the right to broad wallet authority.
Disconnecting a site in the wallet interface may end a session without cancelling an existing on-chain approval. Use the network’s established tools and official wallet guidance to inspect approvals, and be cautious of fake “revoke” websites advertised after a scam.
Common stories

- “Your account will close today unless you verify.”
- “I am support; send the code so I can cancel the withdrawal.”
- “Your wallet must synchronize after an upgrade.”
- “You won a token; connect and approve to claim.”
- “I am your manager, friend or government officer—pay immediately in crypto.”
- “Download this updated wallet from the attached file.”
Real events can also be urgent. Urgency never removes the need to use an independently verified channel.
Impersonators also pose as recruiters, romantic partners, investment mentors, community administrators, law-enforcement officers and recovery specialists. Their scripts may last weeks. A long relationship is not independent verification, and a small successful withdrawal does not prove an investment platform is real; it may be part of the persuasion.
The PAUSE check
P — Pause the requested action. Do not click, install, sign or send while the message controls the clock.
A — Ask what authority is being requested. Is it a public address, secret, login, remote access, wallet signature or payment?
U — Use an independent route. Open the bookmarked app or type the known domain. Contact the person or provider through a number already on record.
S — Study the full destination. Check the entire domain, app publisher, wallet address, asset, network and transaction preview.
E — Escalate and preserve evidence. Report through official channels and retain the message, URL, account, time and transaction ID without forwarding dangerous links casually.
Try PAUSE as a two-minute drill. Imagine a message says a ₱25,000 withdrawal is pending and asks for an OTP. Pause the reply; name the requested authority; open the provider from your bookmark; inspect account activity; report the message. The same routine works even if the grammar, logo and caller ID look perfect.
Fake app warning signs

An app-store listing reduces some risk but does not replace verification. Compare the publisher, official website link, permissions, update history and spelling. Avoid installation files sent through chat. A fake wallet may work normally until a seed phrase is entered.
For browser wallets, bookmark the official site. Review extension permissions and remove duplicate or unknown wallet extensions.
Verify domains, apps and people independently
For a domain, read from the final registered name outward rather than trusting the first familiar word. A padlock means the connection is encrypted to that domain, including a fraudulent one. Avoid sponsored search results for account recovery; use a bookmark, typed address or regulator/provider directory.
For an app, start with the link published on the provider’s verified website where possible. Match the developer or publisher, app history and requested permissions. An impressive review count is supporting context, not identity proof.
For a person, call back through a number already stored or published on an official site. If a friend asks for money from a new account, use a second channel and a fact not supplied in the message. If a community administrator posts a new rule, confirm it with another authorized moderator.
Philippine community scenario
A community captain posts that everyone must “re-KYC” through a new link to keep access. The account has the correct name and profile photo.
Marites pauses. She opens the provider’s official app separately and contacts the administrator using an existing number. The real captain’s social account was compromised. No one in the group needs to prove bravery by testing the link.
Common crypto impersonation patterns
| Claimed role | Typical request | Safer verification |
|---|---|---|
| Provider support | OTP, password, seed phrase or remote access | Open the official app and create a case there |
| Project team | Connect wallet for migration or airdrop | Check independently published project channels and contract details |
| Government or police | Immediate crypto payment to avoid arrest | Contact the agency through its official public number |
| Employer or recruiter | Pay equipment, training or release fee in crypto | Verify the employer and written hiring process independently |
| Friend or family | Urgent transfer to a new wallet | Call a known number and confirm the request |
| Recovery expert | Upfront fee or wallet secret to recover losses | Treat guaranteed recovery as a red flag and use official reporting routes |
If you already clicked or responded
Stop further interaction. From a clean device, secure the affected email or account, review sessions and contact the genuine provider. If a wallet secret was exposed, treat that wallet as compromised and use official security guidance. Preserve evidence before deleting messages. Do not pay a “recovery expert” who promises guaranteed return.
If a token approval or wallet signature may be involved, stop using the suspected site and review official wallet/network security guidance from a clean device. If a seed phrase or private key was disclosed, changing an app password does not make that secret private again. Preserve enough funds for legitimate network fees, but do not let an unknown helper direct the rescue transaction.
Report the account, domain or app through the platform and provider’s genuine channels. When warning a community, share a screenshot or neutral description rather than a live clickable link. Avoid publishing the victim’s phone number, address, identity document or transaction details beyond what is necessary.
Scam or Legit?

Ask one question: Could this person complete the claimed support task using public transaction information and the provider’s normal authenticated process? If they insist on a seed phrase, password, code, remote control or payment, the answer is no.
Build a community verification culture
Groups are safer when “pause and verify” is normal rather than embarrassing. Administrators can publish one permanent notice: staff never ask for seed phrases, passwords or OTPs; urgent changes are confirmed in at least two established channels; support begins only from the official app or site.
When a member reports a suspicious link, thank them for stopping. Verify it without clicking from a production wallet, preserve evidence and remove the live link where appropriate. Do not shame the person or demand that they demonstrate the scam with a real transaction.
For announcements that could move money, use a second authorized reviewer and a previously known channel. This small governance habit protects beginners and experienced members from a single compromised administrator account.
How this connects to market mastery
Phishing defense is source verification under pressure. The same habit improves market research: separate identity from evidence, confirm through independent sources and inspect what an action actually authorizes.
Key takeaways and check
- Logos, names and personal details can be copied.
- Identify the requested authority, not only the story.
- Verify through a channel the sender did not provide.
- Never share a seed phrase, private key, password or one-time code.
Security check: A caller says they can stop a withdrawal if you read the current OTP. Apply PAUSE and explain why the code must remain private.
This lesson teaches domain, destination and message checks without asking readers to inspect malicious pages directly.
*Cryptocurrency and virtual asset transactions are highly volatile and irreversible, may result in significant losses, and do not guarantee returns; customers should trade only after understanding the risks involved.