Phishing in crypto is the theft of keys, seed phrases or token approvals through impersonation — a cloned site, a fake wallet prompt, a support account that messaged first. Unlike bank phishing, there is no chargeback: once the signature is made, the transfer is final, and the proceeds land in collector addresses that screening can attribute. The label on a check therefore serves two audiences: someone about to sign, and someone about to accept a payment that came from one of those collectors.
The mechanics differ from the password phishing most people know. An attacker does not need your login; they need a signature. That can be a seed phrase typed into a convincing form, a transaction approved in a wallet popup, or a token allowance granted to a contract that then empties the balance at its leisure. Wallets have added warnings for exactly this: MetaMask's security alerts flag transactions and signatures as "Malicious" or "Warning" and are on by default, though a warning does not block the action — the user still confirms. Trust Wallet's Security Scanner works on the same principle, showing low, medium or high risk on destination addresses and dApps and leaving the decision with the user (source below).
Because the decision is yours in both directions. Wallet warnings cover the transaction you are signing; an address check covers the counterparty you are paying, which is a different question and often the earlier one. If someone sends you an address, screening it is the only independent fact you have about them before the money moves.
On the receiving side, phishing proceeds are consolidated and cashed out through retail channels, so a P2P seller can end up holding them. That is a deposit review waiting to happen. Screen the counterparty first — the Telegram bot gives three free checks a day and answers in seconds.
Phishing appears as a named category in the result, in plain words, next to the verdict — CLEAN, LOW, MEDIUM, HIGH or CRITICAL — a recommendation of Proceed, Caution, Review or Reject, and the decision drivers behind them. The result distinguishes an address that is itself a reported collector from one that merely received value from a collector, because those two mean different things for whoever is reading.
Desks and support teams handle these in the workspace, where the category filters the case queue and results export as signed reports for a bank or a case file. Plans are on the pricing page.
The target is a key or a signature rather than a password, and there is no reversal afterwards. A bank can claw back a fraudulent transfer; a settled on-chain transfer stays settled.
It matters for what to do next, not for blame. MetaMask's security alerts and Trust Wallet's scanner both flag rather than block, by design — the confirmation is always the user's. Move remaining funds and revoke approvals now.
A check tells you about an address, not a domain. If the site asked you to send funds somewhere, that destination address is the thing to check, and it is often the same one used across many victims.
Also available in: · · ·
Leave the funds where they are, save the transaction record and your counterparty's details, and expect your exchange to ask. Moving the balance around before you can explain it is what turns a question into a problem.
Send any wallet to the Telegram bot and get a verdict in seconds. Three checks a day, free, no signup. Desks that screen every deposit run it on plans from $199/mo.