<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Education - PhishFort | AI-Powered Brand Protection</title><link>https://phishfort.com/resources/blog/tag/education/</link><description>PhishFort delivers agentic brand protection: detecting and eliminating phishing sites, fake apps, and impersonations across every digital channel.</description><generator>Hugo -- gohugo.io</generator><language>en-US</language><lastBuildDate>Mon, 08 Jun 2026 13:22:04 +0000</lastBuildDate><atom:link href="https://phishfort.com/resources/blog/tag/education/index.xml" rel="self" type="application/rss+xml"/><item><title>Phishing Attacks: 10 Powerful Ways to Spot them in Crypto -and Stay Safe Online</title><link>https://phishfort.com/how-to-spot-phishing-attacks-crypto-edition/</link><pubDate>Tue, 19 Dec 2023 12:34:00 +0000</pubDate><dc:creator>Matt Marx</dc:creator><guid>https://phishfort.com/how-to-spot-phishing-attacks-crypto-edition/</guid><description><![CDATA[<h2 id="1-know-your-senders">1. Know Your Senders</h2>
<p>Phishing attacks as emails often impersonate trusted organizations like banks or cryptocurrency exchanges. These emails can range from poorly written scams to near-perfect replicas of legitimate communications.</p>
<p>Be cautious with any <strong>unexpected email that asks you to log in or transfer crypto</strong>. Genuine financial institutions rarely send emails demanding urgent action. Always check the sender’s email address carefully and watch for subtle misspellings (like <em><code>noreply@citiibank.com</code></em> instead of <em><code>noreply@citibank.com</code></em>).</p>]]></description><content:encoded><![CDATA[<h2 id="1-know-your-senders">1. Know Your Senders</h2>
<p>Phishing attacks as emails often impersonate trusted organizations like banks or cryptocurrency exchanges. These emails can range from poorly written scams to near-perfect replicas of legitimate communications.</p>
<p>Be cautious with any <strong>unexpected email that asks you to log in or transfer crypto</strong>. Genuine financial institutions rarely send emails demanding urgent action. Always check the sender’s email address carefully and watch for subtle misspellings (like <em><code>noreply@citiibank.com</code></em> instead of <em><code>noreply@citibank.com</code></em>).</p>
<p><strong>Tip:</strong> Never share passwords or recovery phrases through email. No legitimate service will ask for this information.</p>
<h3 id="2-dont-click-suspicious-links">2. Don’t Click Suspicious Links</h3>
<p>Avoid clicking links in emails whenever possible. Instead of following a link to your exchange or wallet provider, <strong>manually type the URL into your browser</strong> or use a saved bookmark. This small step eliminates one of the most common phishing entry points.</p>
<p>If you must click a link, <strong>hover over it first</strong> to inspect the real URL. Watch for misspellings, unfamiliar domains, or hidden redirects.</p>
<h3 id="3-know-your-sites">3. Know Your Sites</h3>
<p>Phishing websites often mimic real crypto exchanges to steal your login credentials. They might even use HTTPS (the padlock icon), which only means the connection is encrypted — not that the site is safe.</p>
<p>Always check the <strong>domain name carefully</strong>. For example:</p>
<p>Fake sites often use subdomains, typos (<em><code>bitrrex.com</code></em>), or alternative domain endings (<em><code>bittrex.cash</code></em>) to trick users.</p>
<p><strong>Tip:</strong> Bookmark legitimate URLs of your crypto services to avoid typing mistakes or following malicious links.</p>
<p>














  
  
  
    
    
    

    
    

    
      
      
      
        
          
          
        
      
        
          
          
        
      
        
          
          
        
      
        
      
        
      
      

      <img src="/img/2025-08-image-112.webp"
        srcset="/img/2025-08-image-112_hu_95e2175465f11ffe.webp 480w, /img/2025-08-image-112_hu_7747ce5d210b5178.webp 768w, /img/2025-08-image-112_hu_c677fcfc64a27a27.webp 1200w, /img/2025-08-image-112.webp 1600w"
        sizes="(max-width: 768px) 100vw, 700px"
        alt="Fake Bittrex Login Page"
        
        width="1600" height="1190"
        
        loading="lazy"
        >
    
  



</p>
<p>














  
  
  
    
    
    

    
    

    
      
      
      
        
          
          
        
      
        
          
          
        
      
        
      
        
      
        
      
      

      <img src="/img/2025-08-image-113.webp"
        srcset="/img/2025-08-image-113_hu_77e30e9f39519ea8.webp 480w, /img/2025-08-image-113_hu_e9f2035f8ed37ce1.webp 768w, /img/2025-08-image-113.webp 872w"
        sizes="(max-width: 768px) 100vw, 700px"
        alt="Real Bittrex Login Page"
        
        width="872" height="600"
        
        loading="lazy"
        >
    
  



</p>
<p>This fake site will be hosted on a domain set up to resemble that of the legitimate site, but the sophistication of this varies. The fake site will most likely also be configured to use HTTPS, i.e. the green padlock. HTTPS on its own is not a signifier that a site is trusted — it just means that your connection to the site is encrypted and can’t be intercepted.</p>
<p>So you can catch out some phishing sites, such as the one in the screenshot above, by checking the domain name in the URL. Bittrex’s legitimate domain is bittrex.com, whereas this phishing site is hosted at bittrex.asset2fa-exchange.com. It’s easy to see how the latter could be mistaken for the former, but a bit of careful inspection shows the trick. Some browsers even help you determine whether you’re on this kind of phishing site or not by graying out secondary parts of the URL.</p>
<p><code>hxxps://bittrex[.]asset2fa-exchange[.]com/bittrex-login</code></p>
<p><a href="https://bittrex.com/account/login" target="_blank" rel="noopener">https://bittrex.com/account/login</a>
</p>
<p>But before we get too comfortable with our ability to determine phishing from a quick glance at the URL bar, let’s remember that this is a low effort, low sophistication attack — our attacker didn’t even buy a new domain to target Bittrex users with, they just used a subdomain of something else!</p>
<p>An unintended consequence of the <a href="https://en.wikipedia.org/wiki/Generic_top-level_domain#Expansion_of_gTLDs" target="_blank" rel="noopener">generic top-level domain expansion</a>
 that began in 2013 is that phishers now have many more choices when registering fake domains. Want to phish users of Poloniex.com? Why not register Poloniex.online, or Poloniex.website, or Poloniex.xyz? There are <a href="https://data.iana.org/TLD/tlds-alpha-by-domain.txt" target="_blank" rel="noopener">hundreds of options</a>
 to choose from. And while domain registrars do have dispute processes, and larger corporations with deeper pockets (such as Google) make an effort to buy up all or most alternative domains on these gTLDs, phishing sites can slip through the cracks for long enough to cause some damage.</p>
<p>Luckily, the generic TLD is an important part of the URL and will be displayed as such by most browsers. If you know the legitimate gTLD of a given site, you should be able to spot fakes pretty easily.</p>
<p><a href="https://bittrex.com/account/login" target="_blank" rel="noopener">https://bittrex.com/account/login</a>
</p>
<p><code>hxxps://bittrex[.]cash/account/login</code></p>
<p>This was also possible to a lesser extent before the release of these new TLDs — for example, a phisher could register bittrex.org.</p>
<p>An alternative to using a different gTLD is the practice of typo-squatting — buying up domains one or two letters off from popular websites: for example, fa<strong>cb</strong>ook.com or g<strong>ooo</strong>gle.com. What if our attacker had done this with Bittrex?</p>
<p><a href="https://bittrex.com/account/login" target="_blank" rel="noopener">https://bittrex.com/account/login</a>
</p>
<p><a href="https://bitrrex.com/account/login" target="_blank" rel="noopener">https://bitrrex.com/account/login</a>
</p>
<p>These two URLs look remarkably similar, but you’re probably still able to tell which is the real one because you have them side-by-side for comparison, and because you’ve just read a paragraph about typo-squatting and are primed to notice it. But you won’t always be in such a heightened state of vigilance. Consider the image below:</p>
<p>Noticed what’s wrong with it yet? Probably not, right? Here’s what you missed: in each of the triangles, the last word on the second line is repeated at the beginning of the third. “Once upon a a time”, “John loves to to dance”, “Summer in in the city”.</p>
<p>














  
  
  
    
    
    

    
    

    
      
      
      
        
      
        
      
        
      
        
      
        
      
      

      <img src="/img/2025-08-image-114.webp"
        srcset="/img/2025-08-image-114.webp 438w"
        sizes="(max-width: 768px) 100vw, 700px"
        alt=""
        
        width="438" height="91"
        
        loading="lazy"
        >
    
  



</p>
<p>It is incredibly easy to miss simple typos and repeated letters or words in common words, sentences, and, yes, domain names that we look at all the time.</p>
<h3 id="4-watch-out-for-idn-homograph-attacks">4. Watch Out for IDN Homograph Attacks</h3>
<p>Advanced phishing attacks replace characters in domain names with lookalikes from other alphabets (like Cyrillic). For example, <em>myеthеrwаllеt.com</em> may look identical to <em>myetherwallet.com</em> but leads to a malicious page.</p>
<p>Your browser might not always detect these fake domains. Use security extensions or plugins that can identify deceptive URLs.</p>
<h3 id="5-use-phishfort-nighthawk">5. Use PhishFort Nighthawk</h3>
<p>PhishFort&rsquo;s <strong><a href="/free-browser-extension-fighting-cryptocurrency-phishing-phishfort-protect/">Nighthawk browser extension</a>
</strong>, available for Chrome and Firefox, is designed to spot phishing attacks instantly. It displays:</p>
<ul>
<li>
<p>Blue for trusted sites</p>
</li>
<li>
<p>Red for known phishing sites</p>
</li>
<li>
<p>Grey for unknown ones</p>
</li>
</ul>
<p>It also allows you to <strong>report suspicious domains</strong>, helping to protect the entire crypto community. Learn more at <a href="/free-browser-extension-fighting-cryptocurrency-phishing-phishfort-protect/">PhishFort Nighthawk</a>
.</p>
<h3 id="6-recognize-common-crypto-scams">6. Recognize Common Crypto Scams</h3>
<p>Phishing isn’t limited to email — it also happens across social media, fake apps, and fraudulent ICOs. Some common scams include:</p>
<ul>
<li>
<p><strong>Fake ICOs</strong>: Impersonating real projects to collect investor funds.</p>
</li>
<li>
<p><strong>Giveaway scams</strong>: Asking you to send crypto in exchange for “double your money” rewards.</p>
</li>
<li>
<p><strong>Social media impersonations</strong>: Fake influencer accounts promising returns.</p>
</li>
</ul>
<p>If it sounds too good to be true — even in crypto — it probably is. Always verify projects through official websites and trusted communities.</p>
<h3 id="7-stay-vigilant-beyond-email">7. Stay Vigilant Beyond Email</h3>
<p>Phishing can appear anywhere online — Discord groups, Telegram chats, or X (Twitter). Stay alert, especially when interacting with new contacts, promotions, or investment “opportunities.”</p>
<p>When in doubt, <strong>contact the organization directly</strong> through verified channels before acting.</p>
<h3 id="8-protect-your-wallets">8. Protect Your Wallets</h3>
<p>For crypto investors, one mistake can be irreversible. If funds leave your wallet in a phishing attack, <strong>there’s no way to recover them</strong>. Use hardware wallets when possible, and keep your seed phrases offline and secure.</p>
<h3 id="9-keep-learning">9. Keep Learning</h3>
<p>Cybercriminals evolve constantly. Stay informed by reading trustworthy cybersecurity sources like <a href="/resources/blog/">PhishFort&rsquo;s blog</a>
 and other reputable industry updates.</p>
<h3 id="10-take-a-proactive-stand">10. Take a Proactive Stand</h3>
<p>Knowledge and vigilance are your best defences. Combine awareness with tools like PhishFort Nighthawk to protect your assets — and help build a safer crypto ecosystem.</p>
<p><strong>Outbound Reference:</strong> You can learn more about identifying phishing and scam sites at Google Safety Center.</p>
]]></content:encoded><category>Cybersecurity</category><category>phishing</category><category>crypto</category><category>security</category><category>education</category><category>nighthawk</category></item></channel></rss>