Encyclopedia Ethereum · Entry 230
Fake wallet websites: how phishing reaches a real Ethereum account
In this article
At a glance
Key facts
| Fact | Detail | Source |
|---|---|---|
| Secrets | Recovery phrases and private keys can give an attacker account control. | [1] |
| Imitation | Phishing sites can copy familiar wallet branding. | [1] |
| Authorization | A connection prompt and an asset-spending approval are different requests. | [3][4] |
Check how you arrived
A malicious site may appear through an advertisement, direct message, compromised social post or misspelled address. A page can reproduce legitimate branding while changing the domain or the transaction it asks you to approve.
Compare the complete domain with a trusted source you reached independently. Check the destination itself rather than relying on copied branding or the page’s reassurance that it is official.
A fake synchronization screen asks for the wrong thing
Suppose a page says a wallet balance requires “synchronization” and asks for the recovery phrase. Public balance queries do not require that secret. Giving it to the page would expose the accounts derived from it, rather than repair their display.
Close the page and verify the account on the correct chain through a separate trusted route. Do not paste secrets into a support chat or an online checker to test whether the first page was legitimate.
A genuine wallet can display a malicious request
A phishing application may connect to your genuine wallet and then request a broad token approval. Seeing the request in real wallet software proves where approval is being collected, not that the requested action is sensible.
Check the destination, token contract, operator and scope. Refuse an unexpected request; address a real access problem through the provider’s documented support route.
Direct answers
Questions people ask
Can a genuine wallet extension protect me from every fake site?
No. It can still present a request initiated by a malicious application. You must evaluate the permission or transaction being requested.
Does connecting a wallet reveal the recovery phrase?
A standard provider connection exposes authorized public accounts, not their recovery phrase. A separate form asking for the phrase is a different and dangerous request.
Inspect the evidence
The answer and key facts have stable claim links. These records retain the scope and qualification when reused.
Wallet phishing imitates a trusted application or support service to obtain secrets or signatures. A familiar logo, search placement or wallet connection button does not establish authenticity. Reach the service through an independently checked domain, never give a site your recovery phrase, and inspect the actual wallet request even on a site you recognize.
Scope: Ethereum · data through 2026-10-02. Verification: verified · 2026-10-02T19:27:58.939Z.
Link to this claimSecrets: Recovery phrases and private keys can give an attacker account control.
Scope: Ethereum · data through 2026-10-02. Verification: verified · 2026-10-02T19:27:58.939Z.
Link to this claimImitation: Phishing sites can copy familiar wallet branding.
Scope: Ethereum · data through 2026-10-02. Verification: verified · 2026-10-02T19:27:58.939Z.
Link to this claimRevision history
- — First publication after primary-source research and separate automated verification.
On the Understand an Ethereum wallet problem path · You have reached the final entry in this path.
Source register
Sources and references
Retrieval dates and locators are recorded individually.- Ethereum security and scam preventionethereum.org contributors
Primary community guidance on wallet secrets, phishing, malicious sites and transaction checking.
Locator: Wallet security; common scams; hardware wallets · Version / scope: Documentation snapshot retrieved 2 October 2026; response hash recorded separately · Retrieved: 2026-10-02T18:55:24.140ZOpen source - Airdrop phishing scamsMetaMask
Unsolicited-token links and permissions create risks distinct from passive receipt.
Locator: Airdrop scams; unsolicited tokens · Version / scope: Documentation snapshot retrieved 2 October 2026; response hash recorded separately · Retrieved: 2026-10-02T18:55:24.143ZOpen source - Ethereum Provider JavaScript APIEthereum Improvement Proposals
Wallet connection and authorization error categories do not prove an onchain transaction occurred.
Locator: Provider errors; connectivity; request · Version / scope: EIP-1193 · Retrieved: 2026-10-02T18:55:24.986ZOpen source - ERC-721 NFT standardEthereum Improvement Proposals
Ownership, receiver checks, token-level and operator approvals, mint/burn event semantics.
Locator: safeTransferFrom; approve; setApprovalForAll; Transfer; metadata · Version / scope: ERC-721 · Retrieved: 2026-10-02T18:55:25.399ZOpen source - How passwords work in MetaMaskMetaMask
Device password versus SRP restoration, with separately described social-login behavior.
Locator: SRP access; social account access · Version / scope: Documentation snapshot retrieved 2 October 2026; response hash recorded separately · Retrieved: 2026-10-02T18:55:24.135ZOpen source
Research and drafting use AI assistance. A separate automated review checks claims against primary sources; no external expert or named human review is implied. Publication, substantive editing, source retrieval and verification are recorded separately. This version was independently checked by an automated reviewer on 2 October 2026.
Editorial method and correctionsDegrees of Satoshi editorial project. “Fake wallet websites: how phishing reaches a real Ethereum account.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/wallet-phishing-websites/