The seven methods, ranked by damage
Industry loss reports for the past two years agree on the shape: a small number of attack types account for nearly all individual losses, and none of them break cryptography. They break people and interfaces.
| # | Method | How it works | Tell | Countermeasure |
|---|---|---|---|---|
| 1 | Seed phrase phishing | A site, pop-up, email or "support agent" asks you to enter your seed to "verify", "sync", "claim" or "recover" | Any request for the seed, ever | Nothing legitimate ever needs your seed. Not the wallet vendor, not an exchange, not a swap. The seed goes into a new wallet install and nowhere else. |
| 2 | Malicious token approvals | A dApp or fake site asks you to sign an approval that lets a contract spend an unlimited amount of a token; the drain comes later | "Approve", "setApprovalForAll", "Permit" signatures on sites you did not intend to trade on | Read every signature request; approve only the amount needed; review and revoke approvals regularly with a tool like revoke.cash |
| 3 | Address poisoning | An attacker sends dust from an address whose first and last characters match one you often use; you later copy it from your history | An address in your history you do not remember interacting with; tiny incoming amounts | Never copy addresses from transaction history. Use the address book or the source app, and verify the full address, not just the ends. |
| 4 | Clipboard malware | Malware replaces the address you copied with the attacker's before you paste | The pasted address differs from the copied one | Compare first and last 6 characters after pasting, every time; verify on a hardware wallet screen when you have one |
| 5 | Fake wallet apps and extensions | A clone of a known wallet in an app store or search ad; it works normally until it exports your seed | Ads above search results; slightly wrong names; new publisher | Install only from the vendor's site link; check the publisher; never from a search ad |
| 6 | SIM swap | The attacker convinces your carrier to move your number; SMS 2FA and password resets now go to them | Sudden loss of mobile signal; unexpected reset emails | No SMS 2FA anywhere; a TOTP app or hardware key; a carrier PIN; no phone number on exchange accounts where avoidable |
| 7 | Fake support | A DM on Telegram, Discord or X from "support" after you post a question; they "help" by asking for the seed, remote access, or a "verification deposit" | Support that contacts you first; support in DMs | Real support never DMs first and never asks for a seed, a payment or screen control. Block and report. |
The checklist before every send
This is the routine that stops methods 3 and 4, which together drain more than anything except seed phishing:
- Get the destination address from the source — the recipient's app, the swap's status page, the exchange's deposit page. Not from your history.
- Paste it.
- Compare the first six and last six characters with the source. Read them; do not glance.
- On a hardware wallet, confirm the address on the device screen.
- For a new counterparty and a large amount, send a small test first.
- Check the network label matches — USDT on TRON to a TRON address, USDC on Solana to a Solana address.
Sixty seconds. It has prevented more losses than any piece of software.
Sending to an account-free swap safely
An instant swap adds one step to the routine: the deposit address is new every time, so there is no history to poison — but there is a status page to verify against.
- Open the pair page yourself — type the domain or use a bookmark; never follow a search ad or a link from a message. Fake clones of swap sites exist; they show a deposit address that belongs to the attacker.
- Check the browser shows the real domain before pasting a receiving address.
- Copy the deposit address from the status page with the copy button; verify first/last characters in your wallet; confirm on hardware if you have it.
- Send exactly the shown amount; save the status link.
The same discipline applies to BTC → USDT (TRC-20), ETH → USDT (TRC-20) or any pair.
Approvals: the slow-motion theft
Method 2 deserves its own section because the loss can come months after the mistake. When you use a DeFi protocol or a DEX, you sign an approval letting its contract move your tokens. Legitimate protocols ask for this; so do drainers, dressed up as an airdrop claim or a "verify wallet" step. An unlimited approval to a malicious contract means the attacker can empty that token from your wallet at any later time, without any further action from you.
Habits: read what you are signing (modern wallets show the contract and amount); approve the exact amount rather than unlimited where the interface allows; keep DeFi activity in a separate wallet from long-term holdings; and review approvals quarterly with a revocation tool, removing anything you do not recognise.
Structural defences
- Separate wallets by purpose. A hot wallet for daily use and DeFi; a hardware wallet for savings. A drained hot wallet is a bad day; a drained savings wallet is a catastrophe.
- Hardware for anything you cannot afford to lose. The hardware wallet guide covers choice and setup.
- Fewer accounts, fewer attack surfaces. Every exchange account is a login to phish, a 2FA to SIM-swap, and a KYC file to breach. For conversion, an account-free swap has none of those — there is no login to steal.
- A password manager and hardware 2FA keys for the accounts you must keep.
- Assume public posts are read by attackers. Asking for help in a forum with your wallet address or balance visible invites methods 3 and 7.
If it happens
Move remaining funds immediately to a new wallet with a new seed (not the same seed on a new device — the seed is what was compromised). Revoke approvals from the compromised wallet. Document transaction hashes. Report to the platform involved and, for large amounts, to police — recovery is rare but reports build cases against drainers. Do not pay "recovery services" that contact you; they are method 7 again.
Frequently asked questions
Is a mobile wallet safe? For everyday amounts, yes, if installed from the official source, with the seed backed up offline and the phone locked. For savings, use hardware.
Should I use a wallet that offers "cloud backup" of the seed? It moves the seed to a server protected by your cloud password. That is weaker than paper in a safe and stronger than nothing; know which you are choosing.
Are swaps a common phishing target? Clones of swap sites are. The defence is always the same: reach the site by typed domain or bookmark, never by ad or message link.
How do I check approvals? Tools such as revoke.cash read the approvals on your address and let you revoke each with a transaction. Do it for every EVM chain you have used.
What is the single most effective habit? Never entering the seed anywhere but a fresh wallet install. Everything else is second.
BTC → USDT (TRC-20)
USDT (TRC-20) → BTC
ETH → USDT (TRC-20)