Web3 Security — Top Threats
Most common ways to lose crypto — phishing, drainer, rug, fake app, approval scam.
Web3 security requires a new mindset — no "call customer support," no chargeback, mistakes are permanent.
Top threats in 2024-2025:
1. Wallet drainer • Malicious smart contract asking for "approve all" • You sign transaction → everything drained at once • Medium: fake mint, fake airdrop, fake Uniswap
2. Approval phishing • Request token approve on "legit" protocol • Attacker waits years, then drains when value is high • Revoke.cash — check and revoke approvals
3. Fake token airdrop • Free token appears in wallet • "Claim" → phishing site → drainer • Rule: don't interact with unknown tokens
4. Seed phrase phishing • "MetaMask support" asks for seed phrase • Fake MetaMask site • RULE: No one legitimate ever asks for seed phrase
5. Fake mobile app • Fake Ledger Live, MetaMask, Trust Wallet in app store • Steals seed when entered • Always check developer, reviews, download count
6. Clipboard hijacking • Malware changes crypto address in clipboard • You think you're sending to friend, you're sending to attacker • Always verify first and last 4 characters of address
7. Rugpull/EXIT SCAM • Team abandons project, withdraws liquidity
Protection tools: