On this page
Back to: Crypto Fundamentals from Zero
Most crypto losses aren’t hacks — they’re social engineering. Scammers don’t break your wallet; they convince you to hand over your seed phrase, approve a malicious contract, or send crypto to a “support agent.” This lesson is the defense playbook.
The top scams (2026 edition)
– Phishing sites — a look-alike exchange dApp page. You “login,” you get drained. *Check the exact domain.* – Fake support / DMs — “you’ve won / you owe a fee / verify your account,” always on a fake deadline. Real teams never DM you first. – Fake airdrops — “connect your wallet to claim” (airdrop traps). Real airdrops never ask for access. – Rug pulls & honeypots — tokens you can buy but never sell (rug pull, honeypot). – Social-media impersonation — celebrity/CEO accounts telling you to send crypto or a bonus. They never do this.
The 3 rules that stop 90% of attacks
1. Nobody legit ever asks for your seed phrase, ever. Not support, not a dApp, not “verification.” If something asks, it’s a scam — close it. 2. Slow down when money moves. Scams manufacture urgency. The five-minute pause before sending to an “urgent” address has saved more crypto than all the security tools combined. 3. Verify identities out of band. Is this actually the exchange’s official site? Their official handle? Confirm on a second source before acting.
Self-custody best practices
– Keep medium/large amounts in a cold wallet. – Keep a small hot wallet balance for daily use. – Split your keys/backups across locations; use multisig for big holdings or teams. – Update wallet software, don’t use public Wi-Fi for transfers, and never store your seed phrase digitally.
The best “security tool” is a skeptical, unhurried human. Practice being
> that human.
Next lesson: how networks actually run — Proof of Work vs Proof of Stake.
Course: Crypto Fundamentals from Zero Lesson 14 of 18