Fake exchange / wallet phishing
Fake-exchange and phishing scams impersonate a real platform or wallet, capturing seed phrases, login credentials, or token approvals that let the attacker move funds at will.
Reviewed by the AssetTrace investigations team
How does Fake exchange / wallet phishing work?
- 1
A lookalike site or app is promoted via search ads, messages, or fake support channels.
- 2
The victim enters credentials or a seed phrase, or signs a malicious token approval.
- 3
The attacker drains the wallet, often in seconds, via a drainer contract.
- 4
Follow-up 'support' may attempt a second theft under the guise of recovery.
How does AssetTrace trace Fake exchange / wallet phishing losses?
We reconstruct the malicious approval or transfer, attribute the drainer and downstream addresses, and prepare evidence for counterparties and counsel.
Drained funds are frequently routed through mixers or chains of fresh wallets before reaching an off-ramp.
