“Your account will be blocked in ten minutes. Connect your wallet to secure it.” This message uses urgency before discussing technology. Many scams try to make you approve the wrong action rather than break the blockchain.
The Web3 application guide separated different requests. Here is how to retain that judgement when a screen or person puts you under pressure.
A polished interface does not establish identity
A fake website can copy a logo, name and support button. A message can come from a compromised account. An advertisement at the top of search results is not a certification.
Reach a service through a previously verified address and inspect the complete domain. HTTPS indicates an encrypted connection with that domain, not an honest owner. Ethereum’s security guidance describes phishing scenarios.
Protect secrets and read permissions
Nobody needs your recovery phrase or private key to send you a payment. Someone asking for it is requesting access you should not provide.
A signature can also create exposure without revealing a secret. Reject a request whose domain, authorised program or effect differs from your intention. A hardware wallet does not replace reading the request.
Before transferring, verify the network and address through a reliable source. Do not blindly copy an address from transaction history: attackers can insert similar-looking addresses. MetaMask documents address poisoning.
Three practice scenarios
The unexpected gift. An unfamiliar token appears in your wallet and promises a reward through a website. Its appearance creates no obligation. Do not follow its links or approve actions to unlock the gift.
The unexplained return. A group promises high fixed income, stresses recruitment and avoids questions about customers. Ask where the money comes from. Screenshots of gains prove neither real revenue nor available withdrawals.
The fake recovery. After a loss, a stranger offers to recover the funds for an upfront fee. That payment may be another scam. The FTC explains refund and recovery scams.
If you already approved a suspicious request
Stop further signatures and preserve useful information: the domain, conversations, addresses and transaction identifiers. Contact support through an official channel found independently of the suspicious message.
The response depends on what was exposed. An excessive permission and a disclosed recovery phrase are different incidents. Revoking permission does not repair a compromised key. If a secret was shared, treat the account as compromised; trustworthy assistance should recognise this without asking you to share the secret again.
Closing a tab does not undo an executed transaction. Be wary of anyone guaranteeing recovery. The FTC’s cryptocurrency fraud guidance helps identify such promises.
Check your understanding
A message from a familiar account asks for an urgent payment to restore access. What comes first? Verify the request through an independent channel, before paying or signing. Familiarity is not enough.
Remember: slowing down, identifying the other party and understanding permissions can prevent errors the network will not fix for you.
You have completed the Web3 foundations. Continue with tokenised real-world assets or explore DePIN.
