Phishing: where you never type a seed phrase

Nobody “hacks the blockchain”. They steal the seed and the signature. The scheme has been the same for five years. Only the scenery changes.

Where they hide it

  • Google ads for “Uniswap” / “MetaMask download”.
  • Discord / Telegram “support”, “your wallet will be drained, verify”.
  • An airdrop site that does Connect and then Restore.
  • A fake extension with the same icon.
  • A “signature” in the wallet that is not a swap but set-owner / approve-everything.

What to do instead of panicking

  1. Close the tab. Do not “cancel, but type it first”.
  2. If you did not type the seed — you are probably fine. Do not sign anything weird.
  3. If you did — it is no longer your wallet. New seed on a clean install, move leftovers (if you still can) to the new address. Treat the old one as burned.
  4. Do not DM anyone “help me recover” — that is the second phishing loop.

Read the signature. Destination and approve — in the wallet's language, not on the site banner. Hardware helps because it shows the truth on its own screen: hardware wallets.