Back to Blog
Phishing Playbook

Phishing Playbook

NetworkGuru
GuidePhishingDefense

I build this guide from the thousands of phishing reports I review for Web3 operators. Modern campaigns use lookalike domains, urgent token claims, and fake on-chain notifications.

What I watch for

  • Suspicious subdomains and duplicated brand names.
  • Paths containing verify, claim, or wallet
  • URLs that ask for private keys, seed phrases, or wallet approval links.

Incident response

When a team submits a suspicious link, I verify the domain and isolate the affected communication channel. We treat every unexpected URL as high priority.

Defense advice

I recommend a small, hardened browser environment and a shared checklist for verifying domains, official portals, and signing requests. If something feels off, stop the action and call it out.