{
  "$schema": "https://degreesofsatoshi.com/encyclopedia/schemas/article-v1.json",
  "schemaVersion": "1.0.0",
  "id": "wallet-phishing-websites",
  "canonical": "https://degreesofsatoshi.com/encyclopedia/wallet-phishing-websites/",
  "collection": "ethereum",
  "title": "Fake wallet websites: how phishing reaches a real Ethereum account",
  "description": "Recognize fake wallet and support websites before recovery phrases, private keys or dangerous authorizations are exposed.",
  "aliases": [
    "fake MetaMask website",
    "wallet support asking seed phrase"
  ],
  "dates": {
    "published": "2026-10-02",
    "modified": "2026-10-02",
    "verified": "2026-10-02T19:27:58.939Z",
    "dataAsOf": "2026-10-02"
  },
  "authorship": {
    "publisher": "Degrees of Satoshi editorial project",
    "process": "AI-assisted research and drafting with a separate automated source-verification pass; no external expert or named human review is implied."
  },
  "quickAnswer": {
    "text": "Wallet phishing imitates a trusted application or support service to obtain secrets or signatures. A familiar logo, search placement or wallet connection button does not establish authenticity. Reach the service through an independently checked domain, never give a site your recovery phrase, and inspect the actual wallet request even on a site you recognize.",
    "claimId": "wallet-phishing-websites-quick-answer",
    "sourceIds": [
      "x425-eth-eth-security",
      "x425-eth-mm-airdrops"
    ]
  },
  "keyFacts": [
    {
      "label": "Secrets",
      "value": "Recovery phrases and private keys can give an attacker account control.",
      "sourceIds": [
        "x425-eth-eth-security"
      ],
      "id": "secrets",
      "claimId": "wallet-phishing-websites-fact-secrets"
    },
    {
      "label": "Imitation",
      "value": "Phishing sites can copy familiar wallet branding.",
      "sourceIds": [
        "x425-eth-eth-security"
      ],
      "id": "imitation",
      "claimId": "wallet-phishing-websites-fact-imitation"
    },
    {
      "label": "Authorization",
      "value": "A connection prompt and an asset-spending approval are different requests.",
      "sourceIds": [
        "x425-eth-eip1193",
        "x425-eth-erc721"
      ],
      "id": "authorization",
      "claimId": "wallet-phishing-websites-fact-authorization"
    }
  ],
  "prerequisites": [
    "ethereum-wallet-requests"
  ],
  "sections": [
    {
      "id": "entry",
      "heading": "Check how you arrived",
      "sourceIds": [
        "x425-eth-eth-security"
      ],
      "paragraphs": [
        "A malicious site may appear through an advertisement, direct message, compromised social post or misspelled address. A page can reproduce legitimate branding while changing the domain or the transaction it asks you to approve.",
        "Compare the complete domain with a trusted source you reached independently. Check the destination itself rather than relying on copied branding or the page’s reassurance that it is official."
      ]
    },
    {
      "id": "example",
      "heading": "A fake synchronization screen asks for the wrong thing",
      "sourceIds": [
        "x425-eth-eth-security",
        "x425-eth-mm-password"
      ],
      "paragraphs": [
        "Suppose a page says a wallet balance requires “synchronization” and asks for the recovery phrase. Public balance queries do not require that secret. Giving it to the page would expose the accounts derived from it, rather than repair their display.",
        "Close the page and verify the account on the correct chain through a separate trusted route. Do not paste secrets into a support chat or an online checker to test whether the first page was legitimate."
      ]
    },
    {
      "id": "requests",
      "heading": "A genuine wallet can display a malicious request",
      "sourceIds": [
        "x425-eth-eth-security",
        "x425-eth-erc721",
        "x425-eth-eip1193"
      ],
      "paragraphs": [
        "A phishing application may connect to your genuine wallet and then request a broad token approval. Seeing the request in real wallet software proves where approval is being collected, not that the requested action is sensible.",
        "Check the destination, token contract, operator and scope. Refuse an unexpected request; address a real access problem through the provider’s documented support route."
      ]
    }
  ],
  "faq": [
    {
      "question": "Can a genuine wallet extension protect me from every fake site?",
      "answer": "No. It can still present a request initiated by a malicious application. You must evaluate the permission or transaction being requested.",
      "sourceIds": [
        "x425-eth-eth-security",
        "x425-eth-erc721"
      ]
    },
    {
      "question": "Does connecting a wallet reveal the recovery phrase?",
      "answer": "A standard provider connection exposes authorized public accounts, not their recovery phrase. A separate form asking for the phrase is a different and dangerous request.",
      "sourceIds": [
        "x425-eth-eip1193",
        "x425-eth-eth-security"
      ]
    }
  ],
  "claims": [
    {
      "id": "wallet-phishing-websites-quick-answer",
      "articleSlug": "wallet-phishing-websites",
      "statement": "Wallet phishing imitates a trusted application or support service to obtain secrets or signatures. A familiar logo, search placement or wallet connection button does not establish authenticity. Reach the service through an independently checked domain, never give a site your recovery phrase, and inspect the actual wallet request even on a site you recognize.",
      "sourceIds": [
        "source-83ec2d5a18d94ce1",
        "source-de5bad1c1751e718"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-83ec2d5a18d94ce1",
          "locator": "Wallet security; common scams; hardware wallets"
        },
        {
          "sourceId": "source-de5bad1c1751e718",
          "locator": "Airdrop scams; unsolicited tokens"
        }
      ],
      "scope": {
        "collection": "ethereum",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T19:27:58.939Z",
        "reviewer": "Independent automated verification agent verify_bitcoin_stablecoins_100",
        "notes": [
          "Fresh security source supports impersonation, seed disclosure and destination checks; EIP1193 defines provider/wallet boundary and public account exposure. Draft distinguishes broad token authority from secret disclosure, avoiding the source's inaccurate approval sentence."
        ]
      }
    },
    {
      "id": "wallet-phishing-websites-fact-secrets",
      "articleSlug": "wallet-phishing-websites",
      "statement": "Secrets: Recovery phrases and private keys can give an attacker account control.",
      "sourceIds": [
        "source-83ec2d5a18d94ce1"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-83ec2d5a18d94ce1",
          "locator": "Wallet security; common scams; hardware wallets"
        }
      ],
      "scope": {
        "collection": "ethereum",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T19:27:58.939Z",
        "reviewer": "Independent automated verification agent verify_bitcoin_stablecoins_100",
        "notes": [
          "Fresh security source supports impersonation, seed disclosure and destination checks; EIP1193 defines provider/wallet boundary and public account exposure. Draft distinguishes broad token authority from secret disclosure, avoiding the source's inaccurate approval sentence."
        ]
      }
    },
    {
      "id": "wallet-phishing-websites-fact-imitation",
      "articleSlug": "wallet-phishing-websites",
      "statement": "Imitation: Phishing sites can copy familiar wallet branding.",
      "sourceIds": [
        "source-83ec2d5a18d94ce1"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-83ec2d5a18d94ce1",
          "locator": "Wallet security; common scams; hardware wallets"
        }
      ],
      "scope": {
        "collection": "ethereum",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T19:27:58.939Z",
        "reviewer": "Independent automated verification agent verify_bitcoin_stablecoins_100",
        "notes": [
          "Fresh security source supports impersonation, seed disclosure and destination checks; EIP1193 defines provider/wallet boundary and public account exposure. Draft distinguishes broad token authority from secret disclosure, avoiding the source's inaccurate approval sentence."
        ]
      }
    },
    {
      "id": "wallet-phishing-websites-fact-authorization",
      "articleSlug": "wallet-phishing-websites",
      "statement": "Authorization: A connection prompt and an asset-spending approval are different requests.",
      "sourceIds": [
        "source-b0746cbddfc23325",
        "source-b08b9aae11ea4085"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-b0746cbddfc23325",
          "locator": "Provider errors; connectivity; request"
        },
        {
          "sourceId": "source-b08b9aae11ea4085",
          "locator": "safeTransferFrom; approve; setApprovalForAll; Transfer; metadata"
        }
      ],
      "scope": {
        "collection": "ethereum",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T19:27:58.939Z",
        "reviewer": "Independent automated verification agent verify_bitcoin_stablecoins_100",
        "notes": [
          "Fresh security source supports impersonation, seed disclosure and destination checks; EIP1193 defines provider/wallet boundary and public account exposure. Draft distinguishes broad token authority from secret disclosure, avoiding the source's inaccurate approval sentence."
        ]
      }
    }
  ],
  "sources": [
    {
      "id": "x425-eth-eth-security",
      "label": "Ethereum security and scam prevention",
      "publisher": "ethereum.org contributors",
      "url": "https://ethereum.org/en/security/",
      "locator": "Wallet security; common scams; hardware wallets",
      "note": "Primary community guidance on wallet secrets, phishing, malicious sites and transaction checking.",
      "version": "Documentation snapshot retrieved 2 October 2026; response hash recorded separately",
      "checkedAt": "2026-10-02T18:55:24.140Z",
      "contentSha256": "1372ff086ae3f53ded99c8dfe308346a457574d41c04dc587de119a64080b448",
      "recordId": "source-83ec2d5a18d94ce1"
    },
    {
      "id": "x425-eth-mm-airdrops",
      "label": "Airdrop phishing scams",
      "publisher": "MetaMask",
      "url": "https://support.metamask.io/stay-safe/protect-yourself/nfts/nft-airdrop-scams/",
      "locator": "Airdrop scams; unsolicited tokens",
      "note": "Unsolicited-token links and permissions create risks distinct from passive receipt.",
      "version": "Documentation snapshot retrieved 2 October 2026; response hash recorded separately",
      "checkedAt": "2026-10-02T18:55:24.143Z",
      "contentSha256": "711a15a9407a15296269b55e24910af7c9f6732a693ae3dcfcad4a1446941997",
      "recordId": "source-de5bad1c1751e718"
    },
    {
      "id": "x425-eth-eip1193",
      "label": "Ethereum Provider JavaScript API",
      "publisher": "Ethereum Improvement Proposals",
      "url": "https://eips.ethereum.org/EIPS/eip-1193",
      "locator": "Provider errors; connectivity; request",
      "note": "Wallet connection and authorization error categories do not prove an onchain transaction occurred.",
      "version": "EIP-1193",
      "checkedAt": "2026-10-02T18:55:24.986Z",
      "contentSha256": "7a29e3f43c262ad3f663b8f419257132c127e1580c91cbe837d59f86a5bd7ab4",
      "recordId": "source-b0746cbddfc23325"
    },
    {
      "id": "x425-eth-erc721",
      "label": "ERC-721 NFT standard",
      "publisher": "Ethereum Improvement Proposals",
      "url": "https://eips.ethereum.org/EIPS/eip-721",
      "locator": "safeTransferFrom; approve; setApprovalForAll; Transfer; metadata",
      "note": "Ownership, receiver checks, token-level and operator approvals, mint/burn event semantics.",
      "version": "ERC-721",
      "checkedAt": "2026-10-02T18:55:25.399Z",
      "contentSha256": "bedd672103f3ebb6803ce2bddb33a9ff3d23b08e8e3ae3173b6a5b016f65e2a1",
      "recordId": "source-b08b9aae11ea4085"
    },
    {
      "id": "x425-eth-mm-password",
      "label": "How passwords work in MetaMask",
      "publisher": "MetaMask",
      "url": "https://support.metamask.io/configure/wallet/passwords-and-metamask",
      "locator": "SRP access; social account access",
      "note": "Device password versus SRP restoration, with separately described social-login behavior.",
      "version": "Documentation snapshot retrieved 2 October 2026; response hash recorded separately",
      "checkedAt": "2026-10-02T18:55:24.135Z",
      "contentSha256": "7a525828ab868f369b2cded406465c3be6edfab20abbee242a47820f65280abc",
      "recordId": "source-3bd1032dd7f4b2ef"
    }
  ],
  "related": {
    "articles": [
      "ethereum-wallet-requests",
      "ethereum-token-approvals",
      "unsolicited-tokens-and-nfts",
      "hardware-wallets-for-ethereum"
    ],
    "dossiers": [],
    "wallets": []
  },
  "revisionHistory": [
    {
      "date": "2026-10-02",
      "kind": "published",
      "summary": "First publication after primary-source research and separate automated verification."
    }
  ],
  "citation": "Degrees of Satoshi editorial project. “Fake wallet websites: how phishing reaches a real Ethereum account.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/wallet-phishing-websites/"
}
