
Phishing Playbook
GuidePhishingDefense
I build this guide from the thousands of phishing reports I review for Web3 operators. Modern campaigns use lookalike domains, urgent token claims, and fake on-chain notifications.
What I watch for
- Suspicious subdomains and duplicated brand names.
- Paths containing
verify,claim, orwallet - URLs that ask for private keys, seed phrases, or wallet approval links.
Incident response
When a team submits a suspicious link, I verify the domain and isolate the affected communication channel. We treat every unexpected URL as high priority.
Defense advice
I recommend a small, hardened browser environment and a shared checklist for verifying domains, official portals, and signing requests. If something feels off, stop the action and call it out.