Wallets & Security

Ch 18 · Scams & Safety Habits

Wallets & Security progress: chapter 7 of 9
You chose: Wallets & Security

Scams & Safety Habits

Hook

Most Bitcoin theft against beginners is not a movie hack of “the blockchain.” It is someone tricking you into handing over keys, approving a bad send, or copying the wrong address. Patterns repeat. Once you see them, they lose their power.

One idea

Scammers win with urgency, fear, and look-alike details—seed phishing, fake support, giveaway bait, and address poisoning—so calm habits (verify destinations in your wallet, never share a seed) matter more than clever gadgets.

Plain walkthrough

What they actually steal. Bitcoin’s ledger does not have a “customer service undo.” Valid keys authorize spends. If an attacker gets your seed phrase (Chapter 7), or tricks you into signing a send to them, the network treats that spend as legitimate. Safety is mostly about not feeding them secrets or bad destinations.

Seed phishing. Fake wallet sites, malicious apps, and “verification” forms exist to harvest recovery words. The tell is simple: a screen wants your 12 or 24 words. Real wallets ask you to write the seed down at creation and enter it only when you restore into software you chose. They do not email you a link to “sync your seed.” Help With Bitcoin—and any honest lesson—never asks you to submit a real seed phrase. If a page here (or anywhere) demands those words, stop.

Fake support. Impersonators message you on social apps, email, or voice: “Your account is compromised—share your seed / screen-share / send a test amount to unlock it.” Urgency and fear are the product. Real self-custody support cannot move your coins without your keys, and never needs the seed. Hang up; use official help from a bookmark you trust—not the stranger’s link.

Giveaways and “double your bitcoin.” Posts promise that if you send coins to an address, a celebrity or exchange will send more back. The mechanism is one-way: you send; they keep. There is no protocol feature that multiplies deposits. Treat unsolicited “send to receive” offers as theft with marketing.

Address poisoning (deep dive). Chapter 8 warned briefly; here is the fuller beginner picture.

Bitcoin addresses are long. People often check only the start and end when copying from history. Attackers exploit that:

  1. They watch addresses you have used (the ledger is public).
  2. They create a look-alike address that shares a similar prefix and/or suffix.
  3. They send a tiny “dust” amount involving that look-alike so it appears in your wallet history.
  4. Later, when you mean to pay a familiar contact, you copy from history and grab the poisoned look-alike by mistake.

The network does exactly what you asked: it pays the address you pasted. The fix is procedural:

  • Copy the receive address from your wallet’s receive screen (or scan its QR) when someone should pay you.
  • When you send, paste or scan from a channel you already trust—or an address book entry you verified—not from a random tiny incoming tx.
  • Compare more than a few characters on each end; for larger amounts, compare the whole string or use the recipient’s current QR/invoice.
  • Slow down when anything feels rushed.

Urgency and fear patterns. “Act in 10 minutes or funds freeze.” “Law enforcement needs your seed.” “This airdrop expires tonight.” Pause. Legitimate Bitcoin use rarely requires instant panic. Scammers need you moving before thinking.

Habits that compound. Bookmark official download pages. Prefer fresh receive addresses (Chapter 8). Practice sends with tiny amounts (Chapter 9). Keep seeds offline only. Separate “I feel scared” from “I will type secrets into a chat.”

Watch-outs

  • Any request for your seed — Support, giveaway, “recovery specialist,” or educational form: refuse. Ours included—we never collect real seeds.
  • Screen-sharing a funded wallet — Remote viewers can guide you into approving spends or revealing backups.
  • Clipboard malware — Some malware swaps a copied address for the attacker’s. Glance at the destination on the send confirm screen before you approve.
  • Look-alike apps and URLs — One wrong letter in a domain is enough. Type or bookmark; do not trust ad links for wallet installs.
  • “Prove ownership” by sending — Sending coins does not prove innocence to a stranger; it often is the scam.

You now can…

  • Name the big four: seed phishing, fake support, giveaways, address poisoning.
  • Spot urgency/fear scripts and refuse seed entry on principle.
  • Use a concrete anti-poisoning habit: destinations from your wallet or a verified invoice—not from dusty history alone.

What next?

Ebook: continue to Ch 19

Back one stepReturn to map