Skip to content

Lesson 2 · 1 min · Intermediate

Who's after your coins, and how they try

On this page

Who's after your coins, and how they try

  • Phishing — fake sites, emails, and DMs that trick you into entering your seed phrase or signing a malicious transaction.
  • Seed-phrase theft — the catastrophic one. Anyone with your 12/24 words owns your funds.
  • Rug pulls — project creators abandon the project and drain liquidity, leaving tokens worthless.
  • 51% attacks — an attacker controls majority hash power and can reorganize blocks or double-spend (rare on major chains).
  • SIM swaps — attackers hijack your phone number to bypass SMS-based 2FA and reset account passwords.
  • Address poisoning — tiny payments from look-alike addresses to trick future copy-paste sends.
  • Social engineering — manipulating people (not code) to gain access or trust.

How address poisoning works

1 · You pay a real address2 · An attacker sends a tiny paymentfrom a look-alike3 · Both now sit in your historysame startdifferent middlesame end0x7a3F9c21E84b0D56a1C3e9F02B7d4416c8E5a9D00x7a3F5e07B19dC2a84F06d3E7b1290Ac53f1Ca9D04 · Copy the wrong one, and your next payment goes to the attacker
The look-alike shares the real address’s first and last characters, so checking only the ends lets it through. Verify the full address before every send. The addresses are made up.
Educational only, not financial or legal advice.