←Back to Signals and risks

Phishing

Phishing describes attempts to obtain sensitive data through misleading messages, emails or imitation pages, such as login details, keys or a seed phrase. The message often presents itself as coming from a familiar party. Whether a message really is phishing cannot always be established at a glance.

What it may indicate

An unexpected message asking for data or access can be an indication of phishing, but it need not be. Sometimes it is legitimate, sometimes not. What it really is only emerges once the sender and the requested action are calmly checked.

Someone receives a message that appears to come from a familiar platform, asking them to log in quickly through an enclosed link. The page looks real but asks for data that is normally not needed. Such a request can be a reason to be extra careful.

What is phishing in crypto?

Attempts to obtain login details, keys or a seed phrase through misleading messages or imitation pages that appear to come from a familiar party.

How can you recognise a phishing attempt?

Unexpected requests for data or access, links to look alike pages and pressure to act quickly are common signs. Whether it really is phishing emerges from calmly checking the sender and the request.

What do you do immediately after phishing involving crypto?

Disconnect from the application, move any remaining balance to a new wallet with new recovery words where possible, and keep all messages and transaction details. Then report it.

Can a phishing payment be reversed?

No. A confirmed transaction on the blockchain is final. What can be done is recording the route, so that an authorised body can base further steps on it.

Is phishing always an email?

No. It also happens through text messages, chat apps, phone calls and advertisements with a copied page. The form varies, the purpose stays the same.

What phishing looks like in a crypto file

In crypto cases the decisive moment is almost never the transfer itself but the message that preceded it. Someone receives a warning about a locked account, a support chat that appears to come from a platform, or an invitation to validate a wallet, and acts within minutes. Because the resulting transaction is authorised by the holder, it looks entirely normal on the chain, which is why the file has to combine the on-chain record with the message, the link and the timestamps that show how the instruction arrived.

That combination is what makes a report usable. We fix the transaction data, the destination and the moment, and we describe the sequence of contact that led to it, including the domain that was used and the moment it appeared. Keeping the original message, the full address of the sender and any screenshots is more useful than a summary written afterwards, because those details can be checked. Where the same domain or address turns up in other reports, an institution can connect cases that would otherwise stay separate.

External sourceThe FCA sets out how consumers can protect themselves from scams and describes the pressure techniques that come first, such as unexpected contact, urgency and a request to act through an unfamiliar channel. It also stresses checking a firm through official channels rather than through the details supplied in a message. That advice is close to what a file usually shows in hindsight. See FCA: protect yourself from scams.

See also

Seed phrase (category Transactions), Fake crypto platform (category Transactions), Pig butchering (category Fraud). Phishing can be part of a larger set-up.

Your own situation

If you are reading this, you probably have a question about your own situation. That is exactly what Paucitas does.

The first step is contact by phone. We prefer to schedule that call through WhatsApp, so you do not have to wait. In the call we look together at what can factually be established in your case and what Paucitas can examine for you.

Go to the contact form

Warning: Scammers are posing as Paucitas! Click here for more information

We are available 24/7 at: