UNDERSTAND BEFORE USING
Crypto scams: signatures and fake transfers
THE SHORT ANSWER
A scam can target your recovery phrase or just a signature. A gas-free message can authorize a later action. Check the domain, network, recipient and permission scope; disconnecting a website does not revoke previously granted permissions.
A site promises an airdrop and asks for no payment. Your wallet only says “Sign”. That can sometimes be enough to authorize someone to move tokens later. Read the actual action, not just the website’s message.
Fake support asks for secrets or creates urgency
An account copying a logo may claim it can unlock a wallet. Requests for a recovery phrase, private key or remote access are warning signs.
Return to support through the official website you know, without following the message’s link. A search advertisement or visible social account does not authenticate support.
A signature can have a delayed effect
Some off-chain signatures provide authorization that can be used in a later transaction. They do not necessarily incur a fee when you sign.
Check the recipient contract, token, amount, network and expiry where applicable. If the wallet does not let you understand the action’s scope, do not confirm just to see what comes next.
Connection, approval and revocation
Connecting a wallet generally lets a site see an address and prepare requests. A spending approval lets a contract move tokens within its limits. These actions are different.
Disconnecting the site does not remove an on-chain approval. Revocation must target the correct permission on the correct network and can cost gas. Some signed messages or permission mechanisms require a specific procedure.
History can contain a lookalike address
In an address-poisoning attack, a scammer makes an address resembling a contact’s appear in history, for example through a fake transfer. Comparing only the first and last characters is insufficient.
Use an address independently confirmed with the recipient and check it in full. Also verify support for the chosen network; a familiar token name does not guarantee the correct asset.
If you think you signed something harmful
Stop further interactions with the site and keep links, messages and transaction identifiers. Consult official wallet instructions through a verified domain.
- Suspicious approval: identify the permission and appropriate revocation procedure; disconnecting alone is insufficient.
- Disclosed key or phrase: treat derived accounts as compromised. A new local password does not fix this.
- Do not send money to “unlock” or “recover” lost funds; fraudulent recovery services target victims.
- Report the incident to the relevant provider and authorities. Recovery is not guaranteed.
Sources and further reading
- MetaMask — Signature phishing · in English
- MetaMask — Address poisoning · in English
- MetaMask — Revoke token approvals · in English
- MetaMask — Unauthorized transactions · in English
- Ethereum.org — Security and scam prevention · in English
Page updated on
Documentation checked on · WhyTheBlockchain · Editorial approach