Home
/
Glossary
/
Phishing scam

Phishing scam

Multi-Asset
Market Basics
Phishing scams impersonate brokers, exchanges, banks, or regulators to trick traders into revealing passwords, verification codes, seed phrases, or financial information. Learn the definition, common scenarios, warning signs, prevention steps, and what to do if you clicked a suspicious link.

Plain-English definition

A phishing scam is a type of fraud in which an attacker impersonates a trusted institution or person, such as a broker, exchange, bank, regulator, customer support agent, or someone you know. The attacker uses email, text messages, social media, phone calls, or fake websites to trick users into revealing sensitive information or transferring money.

For traders, the information commonly targeted includes login passwords, one-time verification codes, identity documents, bank card details, trading account permissions, API keys, crypto wallet seed phrases, and private keys. A phishing scam is not a trading strategy. It is an account security and funds security risk.

How phishing works

Phishing usually relies on “trust” and “urgency” to push the victim into acting quickly. A typical process looks like this:

  1. Impersonating a trusted source: The attacker uses a name, logo, email address, or website design that looks similar to a legitimate broker, exchange, or bank.
  2. Creating pressure: The message claims there is unusual account activity, insufficient margin, a frozen withdrawal, a need to re-verify identity, or a “time-sensitive” security issue.
  3. Prompting a click or contact: The user is asked to click a link, download an attachment, scan a QR code, join a chat group, or contact a supposed dedicated support agent.
  4. Stealing information or taking over the account: The attacker uses a fake login page, remote access software, malicious attachment, or similar method to obtain passwords, verification codes, or device access.
  5. Moving funds or extending the fraud: The attacker logs into the real account, changes payment details, initiates a withdrawal, or asks the user to pay additional “taxes,” “margin,” or “unfreezing fees.”

Common scenarios in trading

ScenarioCommon messageMain risk

Fake broker email

Your account will be suspended. Verify again immediately.

Login details stolen; account takeover

Fake exchange text message

Withdrawal issue detected. Click the link to confirm.

Redirect to a fake website; verification code theft

Fake customer support on social media

Private message offering fast withdrawal release or rebates

Induced transfer of funds or disclosure of identity information

Fake regulatory notice

A fee must be paid before account restrictions can be removed

Funds stolen; regulator’s name misused

Malicious attachment or software

Download a security plugin or remote assistance tool

Device infected with malware or controlled remotely

Simple examples

  • You receive an email that appears to come from your broker. The subject says, “Unusual login detected. Verify within 30 minutes.” The linked page looks almost identical to the real website, but the domain name has one extra letter. If you enter your username and verification code, the attacker may immediately try to log in to your real account.
  • Someone on a social platform claims to be exchange support and says they can speed up your withdrawal, but they ask for your wallet seed phrase. If a seed phrase is disclosed, wallet assets may be transferred out directly and are often difficult to recover.
  • A text message says your trading account requires an additional margin payment before it can be unfrozen, and it asks you to transfer money to a personal bank account or crypto wallet address. Treat this as highly suspicious, especially if you cannot verify it through the official app or website.

Warning signs

The following signals do not always prove that a message is fraudulent on their own. However, the more of them you see, the higher the risk:

  • The sender email, web address, or app name differs from the legitimate institution by only a small detail, such as an extra character, a substituted letter, or an unfamiliar domain suffix.
  • The message uses shortened links, QR codes, or compressed attachments and refuses to clearly explain the destination.
  • It asks for your password, one-time verification code, seed phrase, private key, API key, or full bank card information.
  • It pressures you to act immediately because of an account freeze, failed withdrawal, regulatory review, or limited-time offer.
  • It asks you to pay a personal account, third-party wallet, or address that cannot be independently verified.
  • It claims to guarantee recovery of losses, guarantee that an account will be unfrozen, or guarantee investment returns.
  • “Support” communicates only through private chat apps and refuses to let you verify their identity through the official website or official app.

Prevention tips for new traders

  • Log in through official entry points: Type the official website address manually or use an official app from a verified source. Do not log in to trading accounts through email or text message links.
  • Check the domain and certificate information: Look carefully at spelling, suffixes, and redirects. Do not rely only on logos or page design.
  • Enable multi-factor authentication: Use stronger authentication methods where available and store backup codes securely.
  • Do not share critical credentials: Legitimate institutions generally will not ask for your password, one-time verification code, seed phrase, private key, or remote control access.
  • Limit API permissions: If you use a trading API, grant only the permissions you need. Avoid enabling withdrawal permissions by default, and rotate keys regularly.
  • Verify through official channels: If you receive a notice about an account freeze, withdrawal issue, or identity verification request, confirm it first through the official website, official app, or publicly listed customer service number.
  • Keep devices secure: Update your operating system and browser promptly. Do not install unknown browser extensions, remote access tools, or trading software from unverified sources.

If you already clicked or entered information

If you suspect you have encountered a phishing scam, speed matters, but do not continue following the scammer’s instructions:

  1. Stop interacting immediately: Do not click more links, download files, or transfer funds.
  2. Change passwords: Log in through official entry points and change passwords for your trading account, email account, and related payment accounts.
  3. Revoke suspicious permissions: Check logged-in devices, API keys, linked email addresses, phone numbers, withdrawal addresses, and third-party authorizations.
  4. Contact official support and your bank: Explain that you may have been phished and ask whether the account can be frozen, transactions blocked, or additional verification added.
  5. Save evidence: Keep emails, text messages, chat records, links, payment receipts, transaction hashes, and other relevant information.
  6. Report it to relevant authorities: Depending on where you live, you may report it to financial regulators, consumer protection agencies, cybercrime reporting platforms, or the police.

These steps cannot guarantee that losses will be recovered, but they can help reduce further damage and provide useful material for an investigation.

How phishing differs from legitimate security notices

Legitimate financial institutions may send security alerts or ask you to complete identity verification. However, they typically direct you to use official channels, not to enter full credentials on an unfamiliar link or pay money to a private account. When in doubt, rely on the official app, official website notices, contract documents, and publicly listed customer service numbers. Do not make decisions based only on emails, text messages, or social media messages.

Related terms

  • Social engineering: An attack method that uses psychological manipulation to obtain information or induce action. Phishing is one common form.
  • Spoofed website: A website that imitates a legitimate site’s interface or domain to steal login or payment information.
  • Malware: Software designed to steal information, monitor a device, or remotely control a system.
  • Multi-factor authentication: An additional verification step beyond a password, used to reduce the risk of account theft.
  • Account takeover: A situation in which an attacker gains control of an account and changes information, places trades, or transfers funds.

References

Risk Warning and Disclaimer

The market carries risks, and investment should be cautious. This article does not constitute personal investment advice and has not taken into account individual users' specific investment goals, financial situations, or needs. Users should consider whether any opinions, viewpoints, or conclusions in this article are suitable for their particular circumstances. Investing based on this is at one's own responsibility.

The End
TraderKnows
Written byTraderKnows
Created date:2026-08-12 17:14
Last Updated:2026-08-12 17:19
Independent Analysis: Manually researched and fact-checked by the TraderKnows Compliance Team, based on public regulatory records.
Contact Us
Social Media
Region
Region

Copyright © 2023-2026 Traderknows Ltd. All rights reserved.

Revise
Contact