Bitcoin phishing: spot scams and respond after a click

Learn how Bitcoin phishing works, which warning signs matter, why recovery phrases must stay private, and what to do after a suspicious click or message.
Direct answer
Bitcoin phishing tries to obtain a recovery phrase, private key, password or code, or to pressure someone into sending bitcoin, through an untrusted message, call or site.
Phishing can arrive through email, text message, social media, search results, a phone call or a website that resembles a familiar service. The goal is often to capture credentials or redirect a payment.
What is Bitcoin phishing?
Bitcoin phishing is an attempt to obtain a recovery phrase, private key, password or code, or to pressure someone into sending bitcoin, through an untrusted message, call or site.
It can arrive through email, text message, social media, search results, a phone call or a website that resembles a familiar service.
Which warning signs matter most?
Warning signs include urgency, threats of account action, requests for a recovery phrase or code, payment requests to “protect” an account, unsolicited support messages, near-match domains, unknown software and screen-sharing requests.
A polished design, a padlock icon or HTTPS does not prove a site is legitimate. HTTPS protects the connection to the domain reached; it does not establish who operates that domain. CISA recommends checking the URL and certificate information.[4]
Why must recovery phrases and private keys stay private?
A recovery phrase or private key can allow access to bitcoin associated with the relevant wallet. Do not enter either into a website, share either with a caller, or send either in a message. A recovery phrase is for the wallet’s intended recovery process, not routine support or identity checks.[5]
How do you verify a support route?
Use a known-good route, such as a bookmarked official page or an address typed carefully from a trusted record. Do not rely on contact details supplied by the suspicious message.
What should you do after a suspicious click or secret exposure?
Stop interacting with the message, site or caller. From a known-good device and independently verified official route, review the affected account, change exposed passwords, preserve relevant details and report fraud through the applicable official channel.
If a recovery phrase or private key was disclosed, treat the wallet as potentially compromised and follow the wallet or service’s documented, security-reviewed recovery guidance. Do not publish or rely on an unapproved support address, recovery process or response-time promise.
A suspicious click does not always mean an account is compromised. A disclosed recovery phrase or private key is more serious because it can permit spending.
Frequently asked questions
Will legitimate support ask for a recovery phrase or private key?
No. A recovery phrase or private key is not needed for a normal support question. Treat any request for either as a serious warning sign. Bitcoin.org wallet security guidance
Does HTTPS prove that a Bitcoin website is legitimate?
No. HTTPS helps protect the connection to the domain reached, but it does not prove who operates that domain. Check the URL and use a known-good route. CISA guidance
Related reading
Everything about Secured Lending
Download the brochure and learn more about our offering.
Blockrise needs the contact information you provide to us to contact you about our products and services. You may unsubscribe from these communications at any time. For information on how to unsubscribe, as well as our privacy practices and commitment to protecting your privacy, please review our Privacy Policy.