The 5 Most Common Self-Custody Wallet Scams — Close the Tab the Moment You See Them
Nine times out of ten, people who get burned by a self-custody wallet scam aren't dumb — they were just "in a hurry" at the time: rushing to claim that airdrop that looked about to expire, rushing to deal with that warning that popped up, rushing to reply to that message from someone calling themselves support. Scams are designed to push you into a decision in three seconds, so you don't have time to stop and think. This guide lays out the five most common playbooks; the point isn't to memorize the tricks, but to train a reflex: the instant the screen tells you to "sign / claim / provide it right now," close it and touch nothing. By the end you'll see these all look much alike — recognize the skeleton, and new variants can't fool you either.
One iron rule to memorize first
Before we get into the five playbooks, burn one sentence into your head — it blocks the entire worst-loss category:
There is no legitimate reason for anyone to need you to type your seed phrase into a website, send it to anyone, or hand it to any "support agent." The moment someone asks for your seed phrase, don't even think about it — it's a scam.
The whole essence of a self-custody wallet is "the keys are in your hands alone," which we cover in detail in a complete intro to self-custody wallets. Precisely because the keys are yours alone, the official team, support, and the platform won't — and don't need to — know your seed phrase. Any scenario asking you to hand it over, however official the dressing, is after that key of yours. The official sources put it more bluntly than I can: MetaMask's official Web3 safety notes and ethereum.org's security page both list "never expose your seed phrase" as the first principle — worth reading side by side.
1. Fake support, fake official sites
How it works: you're stuck on your wallet and go online for help, or post a question in a community, and before long someone DMs you, the avatar and name looking like official support, eagerly asking "mind sharing your seed phrase so I can look into it for you?" Another variant is the fake official site — you click in from search results, the domain off from the real one by only a letter or two, the page nearly identical, telling you to "verify your wallet" and enter your seed phrase.
Signals to close the tab on: "support" that DMs you first, asks you to provide your seed phrase or private key, or sends you to a web page that wants your seed phrase typed in. A self-custody wallet simply doesn't have support that comes looking for you.
How to defend: always find official support yourself, from the official site or the help entry inside the app — don't let someone lead you by the hand. Read the domain character by character, don't just go by "it looks like it" — scam domains often use similar letters, an extra hyphen, or a different ending to slip past your first glance. When you need to look up an official feature, go for a genuine official source like MetaMask's official support docs, not a link some DM-er pasted.
One blind spot worth flagging: this kind of scam tends to strike when you're "stuck and asking for help," because that's the moment you're most anxious, most wanting someone to fix it fast, and your guard is at its lowest. So remember — the more urgently you're seeking help, the more wary you should be of the "kind soul" who pops up unbidden. A real official team won't DM you for your seed phrase minutes after you ask in public; only someone watching your wallet does that.
2. Fake approvals: the signature you don't understand
How it works: this is currently the most poisonous and most-fallen-for one. You connect to a phishing site — maybe a fake campaign page, fake prize page, or fake dApp — and it pops up a signing request, telling you "just sign to claim" or "approve to use the feature." You don't understand the content, figure signing is no big deal, sign — and that's you authorizing the other side to spend a certain token in your wallet, after which the money is quietly moved out. The key part: through the whole process you "didn't transfer anything," you just "signed" — which is why so many people drop their guard.
Signals to close the tab on: a signing or approval request you don't understand, a page rushing you to "sign now to claim," a source that's a site you're not sure about. An approval grants "the right to move your assets," not a harmless check-in.
How to defend: never sign a signature you don't understand — no exceptions. Before using a dApp, confirm the site is really the one you mean to visit; don't click in from a link someone pasted or a search ad. The safer habit: each time a signing request pops up, first read which token it's asking you to authorize, to whom, and for how much; if the fields are a string you can't make sense of and there's no clearly shown counterparty, just cancel. For how approvals work, and how to regularly check and revoke ones you've already granted, we've written a separate piece: read before claiming: how to avoid malicious signature / approval scams, strongly recommended before you get into on-chain activity.
One easily missed point: approvals "accumulate." You sign an approval on site A today, another on site B tomorrow, and those permissions don't vanish on their own — they stay attached to your wallet. So beyond "don't sign carelessly in the moment," build the habit of going back every so often to review and revoke the ones you no longer use, clearing out the long-term exposure. To understand what "token approval" really is and why it can be abused, see Investopedia's explanation of smart contracts for grounding.
3. Clipboard address-swap trojans
How it works: this one's sneakier. Your device has caught a piece of malware that normally lies dormant, watching only your clipboard. When you copy a wallet address to paste into a transfer field, in the instant you paste, it quietly swaps the address for the scammer's. Wallet addresses are long and messy, and nobody memorizes them character by character, so after pasting you usually won't notice anything wrong, hit send, and the money goes straight into the other side's pocket.
Signals to close the tab on: there's no obvious pop-up to "see" with this one — it exploits the fact that you won't check. So defending against it relies on an active move, not on waiting for it to show itself.
How to defend: build the habit of "after pasting an address, always re-check the first few and last few characters" — ideally compare the address the other side gave you against the one you pasted, segment by segment. Just checking the first two or three characters isn't enough, because some trojans generate an address with a similar opening to fool you, so check the ending too. You can also paste the address into the address checker to see whether the format is right and check it once more yourself, making "verify" a fixed, un-skippable step in the transfer flow. For how to read an address and why you check it character by character, see What is a wallet address? The things to check before you paste one.
One sturdier little habit: for an address you transfer to often (say your own exchange deposit address), once it's confirmed correct the first time, save it to the wallet's address book and select it from there afterward — so you don't re-copy-paste each time, giving the clipboard trojan nothing to work with. Before a large transfer, it's also worth sending a small test amount first, confirming it arrives and the address wasn't swapped, before sending the rest. To check whether an on-chain transaction actually arrived, you can look it up yourself in a block explorer, such as Etherscan or BscScan — paste the address or transaction hash and you'll see it.
4. Fake-airdrop phishing
How it works: you open your wallet and find an unfamiliar token you've never seen, possibly with some website's name written on it. You go to look it up out of curiosity, or the token itself carries a message telling you to go to some site to "claim," "redeem," or "activate." Click through and it either asks you to enter your seed phrase or to sign a malicious approval — back to playbook two above. That extra token is itself the bait.
Signals to close the tab on: a token showing up in your wallet that you never bought or claimed; an unknown token bundled with a "go to some site" instruction; pressure to claim within a time limit.
How to defend: when you see an unknown token, the safest move is to not touch it, not tap it, not interact with it — just let it sit there. Don't tap it, don't try to swap it for another coin, and definitely don't follow its instructions to any site. A real airdrop usually comes because you "actively took part in some project, or met certain conditions," not out of nowhere on its own; a token that appears from thin air is 90% bait. For how to tell a real airdrop from a fake by its signals, we've compiled a piece: How to tell real airdrops from fake: 5 signs it's a scam, which anyone wanting to claim airdrops safely can check against. For a full, safe walk-through of the claiming flow, see the complete airdrop guide too.
5. Fake wallet apps
How it works: scammers make a wallet app nearly identical to the genuine one, put it on some non-official download channels, or lure you to download it via ads or DM links. You install it, follow the flow to "create a wallet" or "import a wallet," and the seed phrase you enter or generate is synced to the other side in that very instant. Once you actually store coins in it, they clear it out in one go.
Signals to close the tab on: downloading a wallet from an ad, a DM, or a link of unknown origin; a download page whose URL isn't the official domain; an app whose source has odd reviews or that just appeared.
How to defend: only download from the official site or the genuine link in an official app store, confirm the domain once more before downloading, and glance at the developer name, release date, and whether the reviews look reasonable while you're at it. Just released, very few reviews, or an odd developer name — don't install. If you're going to use an exchange anyway, starting with the exchange's built-in, clearly sourced Web3 wallet makes hitting a fake app far less likely — we've written up the opening and backup flow of that built-in wallet in the complete Binance Web3 Wallet guide.
One variant to watch: you're already on the genuine wallet but get an "update the app" message or pop-up whose link sends you to a non-official download page. Always update from the official app store, and don't update via a link in a message — that one step blocks most fake-update traps.
Almost every phishing page hits you with a countdown timer the second it opens — this was the same move we ran into over and over when we deliberately clicked through a few obviously sketchy pages with a test wallet holding a tiny amount. Countdown timers, limited spots, "claim now or it expires" — all of it uses time pressure to stop you thinking, and genuine official features never hound you like that. Look further down and the signing requests on those pages often had fields that were a long string of nonsense; a normal transfer signature, by contrast, clearly shows the counterparty and amount. Put those two together and it's plain: the moment what pops up leaves you "not understanding it and being rushed to sign," that's the moment to close the tab. The takeaway from the whole round: defending against scams isn't about memorizing every new gimmick, it's about building the reflex of "being rushed = stop."
Three lines of defense that cover them all
With the five playbooks covered, you'll notice their weak points overlap. Set up these three lines of defense and the vast majority of variants can't get in:
- Write the seed phrase only with pen and paper, store it only offline — never type it into any website, never send it to anyone. This one blocks fake support, fake sites, and fake apps, all three. For how to write it and where to keep it, see What is a seed phrase? How to write it down, where to keep it, and why you must never screenshot it.
- Never sign a signature you don't understand, and confirm the URL before entering any dApp. This blocks fake approvals and fake airdrops.
- Always verify the address character by character before transferring, building the habit of re-checking after pasting. This blocks the clipboard trojan and slips of the finger.
Ultimately, a self-custody wallet hands you the freedom and the responsibility both. What scammers bet on is that you'll "skip those three seconds of checking for the sake of convenience." Turn the three things above into muscle memory, slow down automatically when you're being rushed, and their most-used tricks stop working on you. To add one more layer before a transfer, use the address checker; to round out your whole self-custody safety picture, go back to a complete intro to self-custody wallets and read it from the top — it ties every line here together.