On this page
Who's after your coins, and how they try
- Phishing — fake sites, emails, and DMs that trick you into entering your seed phrase or signing a malicious transaction.
- Seed-phrase theft — the catastrophic one. Anyone with your 12/24 words owns your funds.
- Rug pulls — project creators abandon the project and drain liquidity, leaving tokens worthless.
- 51% attacks — an attacker controls majority hash power and can reorganize blocks or double-spend (rare on major chains).
- SIM swaps — attackers hijack your phone number to bypass SMS-based 2FA and reset account passwords.
- Address poisoning — tiny payments from look-alike addresses to trick future copy-paste sends.
- Social engineering — manipulating people (not code) to gain access or trust.
How address poisoning works