# Fake wallet websites: how phishing reaches a real Ethereum account

Wallet phishing imitates a trusted application or support service to obtain secrets or signatures. A familiar logo, search placement or wallet connection button does not establish authenticity. Reach the service through an independently checked domain, never give a site your recovery phrase, and inspect the actual wallet request even on a site you recognize.

Evidence: [Ethereum security and scam prevention](https://ethereum.org/en/security/); [Airdrop phishing scams](https://support.metamask.io/stay-safe/protect-yourself/nfts/nft-airdrop-scams/)

Canonical: https://degreesofsatoshi.com/encyclopedia/wallet-phishing-websites/
Published: 2026-10-02
Substantively modified: 2026-10-02
Independently verified by an automated reviewer: 2026-10-02T19:27:58.939Z
Data current through: 2026-10-02

AI-assisted research and drafting with a separate automated source-verification pass; no external expert or named human review is implied.

## Key facts

- **Secrets:** Recovery phrases and private keys can give an attacker account control. ([Ethereum security and scam prevention](https://ethereum.org/en/security/))
- **Imitation:** Phishing sites can copy familiar wallet branding. ([Ethereum security and scam prevention](https://ethereum.org/en/security/))
- **Authorization:** A connection prompt and an asset-spending approval are different requests. ([Ethereum Provider JavaScript API](https://eips.ethereum.org/EIPS/eip-1193); [ERC-721 NFT standard](https://eips.ethereum.org/EIPS/eip-721))

## Check how you arrived

A malicious site may appear through an advertisement, direct message, compromised social post or misspelled address. A page can reproduce legitimate branding while changing the domain or the transaction it asks you to approve.

Compare the complete domain with a trusted source you reached independently. Check the destination itself rather than relying on copied branding or the page’s reassurance that it is official.

Evidence: [Ethereum security and scam prevention](https://ethereum.org/en/security/)

## A fake synchronization screen asks for the wrong thing

Suppose a page says a wallet balance requires “synchronization” and asks for the recovery phrase. Public balance queries do not require that secret. Giving it to the page would expose the accounts derived from it, rather than repair their display.

Close the page and verify the account on the correct chain through a separate trusted route. Do not paste secrets into a support chat or an online checker to test whether the first page was legitimate.

Evidence: [Ethereum security and scam prevention](https://ethereum.org/en/security/); [How passwords work in MetaMask](https://support.metamask.io/configure/wallet/passwords-and-metamask)

## A genuine wallet can display a malicious request

A phishing application may connect to your genuine wallet and then request a broad token approval. Seeing the request in real wallet software proves where approval is being collected, not that the requested action is sensible.

Check the destination, token contract, operator and scope. Refuse an unexpected request; address a real access problem through the provider’s documented support route.

Evidence: [Ethereum security and scam prevention](https://ethereum.org/en/security/); [ERC-721 NFT standard](https://eips.ethereum.org/EIPS/eip-721); [Ethereum Provider JavaScript API](https://eips.ethereum.org/EIPS/eip-1193)

## Questions

### Can a genuine wallet extension protect me from every fake site?

No. It can still present a request initiated by a malicious application. You must evaluate the permission or transaction being requested.

Evidence: [Ethereum security and scam prevention](https://ethereum.org/en/security/); [ERC-721 NFT standard](https://eips.ethereum.org/EIPS/eip-721)

### Does connecting a wallet reveal the recovery phrase?

A standard provider connection exposes authorized public accounts, not their recovery phrase. A separate form asking for the phrase is a different and dangerous request.

Evidence: [Ethereum Provider JavaScript API](https://eips.ethereum.org/EIPS/eip-1193); [Ethereum security and scam prevention](https://ethereum.org/en/security/)

## Claims and scope

### wallet-phishing-websites-quick-answer

Wallet phishing imitates a trusted application or support service to obtain secrets or signatures. A familiar logo, search placement or wallet connection button does not establish authenticity. Reach the service through an independently checked domain, never give a site your recovery phrase, and inspect the actual wallet request even on a site you recognize.

Scope: {"collection":"ethereum","dataAsOf":"2026-10-02","blockHeight":null}

### wallet-phishing-websites-fact-secrets

Secrets: Recovery phrases and private keys can give an attacker account control.

Scope: {"collection":"ethereum","dataAsOf":"2026-10-02","blockHeight":null}

### wallet-phishing-websites-fact-imitation

Imitation: Phishing sites can copy familiar wallet branding.

Scope: {"collection":"ethereum","dataAsOf":"2026-10-02","blockHeight":null}

### wallet-phishing-websites-fact-authorization

Authorization: A connection prompt and an asset-spending approval are different requests.

Scope: {"collection":"ethereum","dataAsOf":"2026-10-02","blockHeight":null}

## Sources

- [Ethereum security and scam prevention](https://ethereum.org/en/security/) — ethereum.org contributors. Primary community guidance on wallet secrets, phishing, malicious sites and transaction checking. Locator: Wallet security; common scams; hardware wallets. Retrieved: 2026-10-02T18:55:24.140Z.
- [Airdrop phishing scams](https://support.metamask.io/stay-safe/protect-yourself/nfts/nft-airdrop-scams/) — MetaMask. Unsolicited-token links and permissions create risks distinct from passive receipt. Locator: Airdrop scams; unsolicited tokens. Retrieved: 2026-10-02T18:55:24.143Z.
- [Ethereum Provider JavaScript API](https://eips.ethereum.org/EIPS/eip-1193) — Ethereum Improvement Proposals. Wallet connection and authorization error categories do not prove an onchain transaction occurred. Locator: Provider errors; connectivity; request. Retrieved: 2026-10-02T18:55:24.986Z.
- [ERC-721 NFT standard](https://eips.ethereum.org/EIPS/eip-721) — Ethereum Improvement Proposals. Ownership, receiver checks, token-level and operator approvals, mint/burn event semantics. Locator: safeTransferFrom; approve; setApprovalForAll; Transfer; metadata. Retrieved: 2026-10-02T18:55:25.399Z.
- [How passwords work in MetaMask](https://support.metamask.io/configure/wallet/passwords-and-metamask) — MetaMask. Device password versus SRP restoration, with separately described social-login behavior. Locator: SRP access; social account access. Retrieved: 2026-10-02T18:55:24.135Z.

## Revision history

- 2026-10-02: First publication after primary-source research and separate automated verification.

## Cite this entry

Degrees of Satoshi editorial project. “Fake wallet websites: how phishing reaches a real Ethereum account.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/wallet-phishing-websites/
