Security and scams

What is crypto phishing?

Crypto phishing is any fake site, message, ad or app that imitates a real one to make you reveal your recovery phrase or sign a harmful transaction. Look-alike domains, fake support accounts and sponsored search results are common routes.

Why it matters

A phishing page can be a pixel-perfect copy of a real dApp. The only differences may be one character in the domain and what the signature request actually does, both easy to miss.

How Locker Protocol Wallet handles it

Locker Protocol Wallet warns you when you connect to a site on its bundled phishing list, or to a domain written with unusual characters (punycode). The warning is advisory and the decision stays yours; every request is then decoded again on the Vault.

Get the extension

Questions

Will a real wallet ever ask for my seed phrase?

No. No support team, dApp or update needs your recovery phrase. Anyone who asks for it is trying to take your funds.

How do I spot a phishing site?

Type the address yourself or use a bookmark, check the domain letter by letter, and distrust urgency: a mint ending in minutes, a claim about to expire, a security alert.