Crypto Phishing After a Data Breach: The Warning Signs in a Fake Exchange Email
After every major data breach, the number of phishing emails sent in the name of crypto exchanges and wallet manufacturers rises. This article shows you how to recognise such a message, which data a reputable provider never requests by email, and what to do in the first hour after a click.

Table of Contents
Table of Contents



Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
Crypto phishing gives itself away at almost the same point every time: in what the message wants from you. A genuine crypto exchange never asks for your seed phrase, never for your private key and never for the code in your authenticator app. Any email, text message or social media message that asks for one of those three is an attempted fraud, however authentic the sender and the design may look. Everything that follows is the craft of applying that one sentence reliably in daily use.
The occasion for this guide is the situation in late summer 2026. Large data losses at financial and wallet providers mean criminals no longer have to scatter their attempts blindly. They know their targets' names, addresses, phone numbers and in some cases even account balances. A crude mass mailing thereby becomes a personally tailored message that convinces at first glance. The 2026 cybersecurity monitor published by Germany's Federal Office for Information Security puts a figure on how widespread this has become: eleven percent of internet users were affected by an online crime in the previous year alone, phishing accounted for twelve percent of those cases, and one in three of all those affected reports a financial loss.
What separates crypto phishing from ordinary spam
Phishing is the attempt to move you, by means of a forged message, into handing over access credentials or making a payment. The term comes from fishing: the message is the bait and your account is the catch. Spam wants to sell you something and costs you time. Phishing wants your access and costs you money.
In crypto the problem sharpens for a technical reason. A bank transfer can sometimes be recalled, and a direct debit can be reversed as a matter of course. A transaction on a public blockchain is final once it has been confirmed. No institution exists that can take it back, neither at Bitcoin nor at Ethereum. Anyone who has signed the wrong thing once is no longer negotiating, only counting the damage. That is what makes phishing so profitable for criminals in crypto and so expensive for you.
There is a second peculiarity. At a bank, fraudsters need your login credentials. At a self-custodied wallet, your signature on an innocuous-looking approval is often enough. These two routes call for different defences, and this article treats them separately.
Why a data breach at one provider triggers phishing emails in the name of entirely different crypto exchanges
A data breach is the unintended escape of customer data from a provider's systems. What matters to you as a user is which data escaped. If it is copies of identity documents, addresses, phone numbers and transaction histories, then your coins are safe for the moment, because none of that opens a wallet. Such records become dangerous only as raw material for the next step.
Anyone who knows that you are a customer of a crypto provider, what your name is and where you live, can approach you credibly. And they are not limited to the provider where the breach occurred. A list of German crypto customers can be used for any scheme: for a forged security warning from a completely different exchange, for a supposed product recall from a wallet manufacturer, for a call from an invented fraud department. This is the mechanism many people underestimate. A breach at one provider funds the phishing wave carried out in the name of all the others.
An example from our own reporting: on 12 September 2026 we described how customers can check whether they were caught up in the Revolut data breach. According to the information available at the time, the exposed records covered copies of identity documents, verification selfies, IBANs and complete transaction histories. Not one of those fields is a password. That data set was nevertheless the basis for the personally addressed emails that circulated in the weeks that followed. We saw the same sequence in the summer of 2026 at several hardware wallet providers whose customer addresses escaped through a shipping contractor.

Typical signs of phishing: seven warning signals in the message itself
The warning signals below come from the cases that we and Germany's consumer advice centres encountered during 2026. None of them is proof on its own. Where two or more apply, treat the message as fraud.
- Time pressure. A deadline of a few hours, a suspension said to be imminent, a payout that will otherwise lapse. Reputable providers allow weeks and send reminders.
- An action that works only through the link supplied. Genuine matters can always be dealt with by typing in the exchange's address yourself and logging in there.
- A request for secrets. Seed phrase, private key, password or the six digits from the authenticator app. More on this below.
- A withdrawal address you did not register yourself. If the email contains a wallet address to which you are supposed to transfer funds "for safekeeping", the matter is settled.
- An attachment. Crypto exchanges deliver tax reports and account statements through your logged-in account, not as a file in your inbox.
- The wrong email address in the recipient field. If the message arrives at an address under which you hold no account with that provider, it was sent from a purchased data set.
- An offer that is too good. Compensation for market losses, guaranteed returns, an airdrop for which you only have to sign one approval.
What you can no longer use as a warning signal are spelling mistakes and a crooked layout. The messages of 2026 are linguistically clean and pixel-perfect in appearance. Anyone hunting for typos is looking in the wrong place. How far this now goes we described using a forged security warning that travelled through the manufacturer's genuine sending route and passed every technical authenticity check.
How to check a link for phishing without clicking it
The most reliable test costs you ten seconds and consists of not using the link at all. Open the exchange or the wallet app the way you always do, through your own bookmark or the installed app. If the same notice appears there, the email was genuine. If it does not, you have your answer without having risked anything.
If you still want to judge the link itself, look at the part immediately before the first single slash. That is the actual domain. Everything in front of it can be freely invented. An address of the form exchangename.security-login.example belongs to the operator of security-login.example, not to the exchange. Criminals also rely on similar-looking characters and on additional hyphens. On a phone, a long press on the link displays the destination address without opening it.
Two additions for everyday crypto use. First, a certificate and the padlock symbol in the browser say only that the connection is encrypted. Fraudulent websites have both. Second, if you are offered a wallet connection before you have read anything at all, close the page. Reputable providers request the connection only once you have triggered a specific action.
Which data a crypto exchange never requests by email
Three items are absolute. A reputable provider will not ask for them under any circumstances, neither by email, nor by telephone, nor in a support chat.
The seed phrase is your wallet's recovery phrase, usually twelve or twenty-four words in a fixed order. Every private key in your wallet can be recalculated from it. Whoever holds it holds your coins, immediately and without any further step. No manufacturer, no support desk and no public authority ever needs it. The private key is the cryptographic value with which a single address signs transactions; the same applies to it. The two-factor code from your authenticator app is valid for thirty seconds and exists precisely so that nobody but you knows it. Anyone asking you for it is sitting in front of your exchange's login form at that very moment.
A fourth item is trickier because it looks harmless: the screenshot as proof. A supposed support agent asks you to send a screenshot of your account or your wallet interface. From it, criminals read off balances, the networks you use and sometimes parts of addresses, and they build the next, still more credible message on that basis. Send no screenshots to anyone who contacted you first.
Fake support and wallet drainers: the schemes that turn leaked data into money
In practice, four fraud schemes grow out of a single data set, and you should keep them apart because each calls for a different defence.
The fake support desk. You receive a call or a message from your exchange's supposed security department. They know your name and your last deposit, and they cite a suspicious withdrawal that never happened. The remedy they offer is always the same: a code you are meant to read out, or a transfer to a "secure custody account". Hang up and call back on the number given on the provider's website.
The forged login page. The classic among phishing attacks. The link leads to a copy of the exchange, your input lands with the criminals, and they use it to log into the real account in real time. The only reliable protection is a second factor that cannot be passed on: a passkey or a security key tied to the genuine domain, which simply does not work on a copy.
The wallet drainer. This scheme targets your signature rather than your password. You land on a page, connect your wallet and confirm an approval. Smart contracts can be written so that this one approval permits an external contract to debit your tokens at any time. The wallet shows you no amount in the process, only a technical permission, and that is exactly what the criminals count on. Read which permission is being granted at every signature, and abort if you do not understand it.
The forged recall or replacement. Particularly popular after breaches at hardware providers. You are offered a free replacement for your device, and the new device arrives with a recovery phrase already prepared. A device that supplies you with a ready-made seed phrase has always been tampered with. A genuine wallet generates the phrase during setup, in front of you.
Crypto scams beyond phishing: what not to confuse the scheme with
Anyone who wants to spot crypto fraud should keep the common crypto scams apart, because each demands different countermeasures. Phishing takes away access you already hold. The other widespread schemes rely on you voluntarily paying in fresh money.
In investment fraud, crypto scammers build a relationship over weeks, usually through messengers or dating platforms, and lead the investor to an invented trading platform showing rising numbers. The first small payout works and creates trust; after that the sums demanded grow, and in the end the supposed provider asks for a fee before anything is paid out at all. In a rug pull, the team behind a freshly launched token disappears along with the funds collected. In the forged giveaway, a hijacked profile advertises a doubling of your money if you first send something to a named address.
The boundary between the two worlds is fluid, because the same tactics build on the same leaked data sets. Caution therefore includes one simple rule of thumb: in phishing, somebody wants something from you that you already have. In investment fraud, somebody promises you something that does not exist. Both methods end on the same blockchain, and in both cases the risk of total loss is real.

Straight after the click: what counts in the first hour
Suppose it has happened. You clicked the link, entered data or signed an approval. The order of your steps then decides the outcome, not speed alone.
- Cut off access. If you entered login credentials, change the exchange password from a different device and log out all active sessions. Depending on the provider, this function is called "manage devices" or "active sessions".
- Move the balance if a wallet is affected. If you signed an approval, changing a password will not help. Transfer the remaining holdings to a newly set up wallet with a fresh seed phrase. The old wallet counts as burned from that moment on.
- Revoke the permissions you granted. On networks with smart contracts you can withdraw existing approvals. That does not replace step two, but it prevents further outflows while you are still moving.
- Secure the evidence. Take screenshots of the message including the full headers, and note the transactions with times and addresses. Without those records a criminal complaint will not get far.
- File a complaint and inform the provider. The complaint goes to any police station, or online to the cybercrime reporting portal of your federal state. The provider can flag recipient addresses if the funds arrive at a regulated exchange.
Part of setting expectations is the uncomfortable truth that the road to recovery is narrow. In practice it exists only where the stolen amounts arrive on a regulated platform with identity verification and are frozen there quickly enough. The longer you wait, the less likely that becomes.
Hardware wallet, passkeys and withdrawal allowlists: what devalues phishing for good
The most effective measures are those that render a successful fraud attempt inconsequential, instead of requiring you to spot it. Three of them are worthwhile for anyone holding more than a few hundred euros in cryptocurrencies.
A hardware wallet keeps the private key inside a device that never talks to the internet. Every transaction has to be confirmed on the device itself at the press of a button, and the display shows the recipient and the amount while you do so. A forged website can put on quite a show, yet it cannot press that button. Which devices differ in what respects, and what to look for when buying, we have set out in our hardware wallet comparison. Buy such a device exclusively from the manufacturer directly.
A passkey or a security key replaces the code from the authenticator app with a procedure tied to the genuine domain. On a rebuilt login page, no valid response is produced at all. That removes the most common scheme used against exchange accounts. Check your exchange's security settings to see whether it is offered, and set it up before you need it.
An allowlist of approved withdrawal addresses is the most underrated setting of all. Many crypto exchanges let you restrict withdrawals to addresses registered in advance, with a waiting period of one or two days for each new address. Even someone who takes over your account can then no longer reach your money immediately, and you have time to react.
For everyday use, some additions apply: a separate email address used only for crypto accounts, a password manager with its own password for each provider, and no crypto holdings mentioned in open social media profiles. Anyone not identifiable as a holder appears on fewer lists.
How to recognise a licensed provider, and why that helps against phishing
Since the European crypto regulation MiCA came into force, providers addressing retail customers in the EU require authorisation, granted and supervised in Germany by BaFin. For you this amounts to phishing protection for two reasons. First, the supervisor publishes the list of authorised firms; anyone absent from it is no candidate for your money. Second, authorised providers follow fixed rules for customer communication, which makes the number of permitted channels smaller and therefore easier to verify. Which obligations apply here we classify on an ongoing basis in our overview of the MiCA licence.
The scheme that attaches itself to this is already familiar from 2025: fraudsters pose as an unauthorised provider that supposedly has to tell its EU customers to withdraw their holdings. How such a demand can be checked we described in a separate guide to withdrawal demands after the MiCA deadline. The verification route is the same as in this article: never through the link in the message, always through access you have opened yourself.
Reporting phishing: consumer advice centres, providers and law enforcement
A report does little for you and a great deal for everyone else, because identified waves are blocked faster. Three addresses are worth the effort.
Germany's consumer advice centres operate a collective inbox for suspicious messages and publish the schemes they identify on an ongoing basis in their phishing radar. Looking there is worthwhile as a precaution too, whenever a message strikes you as odd. The provider in whose name the email was sent almost always has its own abuse reporting address; it is given in the help section. And the police accept complaints online through the federal states' cybercrime portals, including where no damage has yet occurred.
Crypto phishing: what to take away
- Check your security settings today, not after the next breach. Switch the second factor to a passkey, activate the withdrawal allowlist, log out old sessions. Whether your provider offers any of this at all can be seen in our comparison of regulated crypto exchanges.
- Get the key out of the browser. Anyone holding positions over the long term should keep them on a device with physical confirmation. The differences and the prices are in the hardware wallet comparison.
- Separate everyday use from storage. A small software wallet for purchases and approvals, a separate address with no contract approvals whatsoever for your holdings. Which software wallets are suited to this is set out in the software wallet comparison.
(As of September 20, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Related articles
- Crypto Wallet Phishing by Letter: Why the QR Code From Your Postbox Wants Your Recovery Phrase
- Waltio Confirms Brevo Breach Touched Its User Emails: Here Is What To Do Now
- SafePal Data Breach: 39,798 Customers Exposed With Names, Addresses and Phone Numbers
- Crypto Wallet Provider Ledger Hacked: Data Leak Results in Phishing Scams
- Phishing Email From the Real Sender Address: How to Check a Wallet Security Warning
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
January 22, 2025 11:31 AM

How to Identify Fake TRUMP tokens: A Guide to Staying Safe in the Crypto World
The rise of fake TRUMP and MELANIA tokens is alarming crypto enthusiasts. Learn how to distinguish the official tokens from scams and protect your investments with this essential guide.
September 10, 2026 9:13 AM

Trezor Hack Scare: That STM32 Entropy Email Is a Phishing Attack
Trezor users received a fake STM32 entropy warning sent from a real Trezor address. Here is what happened and what to do if you clicked.
August 23, 2026 4:36 PM

Operation ASTERIX: How a Fake Support Call Delivers a Counterfeit Wallet App
Security researchers analysed an open server on which a phone system, phishing interfaces and cloned wallet programs all came together. The largest list of numbers was the German one.
August 13, 2026 4:59 PM

Trezor Data Breach: First 13,689 Customers, Then Roughly 67,000 More Exposed
A breach at Trezor shipping partner ShipMonk exposed names, phone numbers and home addresses of 13,689 customers in August; in September Trezor reported roughly 67,000 more in the US. Devices are safe, phishing risk is not.
September 4, 2026 10:15 PM

Trezor Data Breach: Am I Affected and What Should I Do Now?
Trezor widened the ShipMonk data breach on September 4, 2026: around 67,000 further people affected, just over 80,000 in total, from orders placed between November 2019 and August 2021. How to check in two minutes whether you are among them, and what an exposed home address means for self-custody.
August 11, 2026 1:32 PM

How to Store a Seed Phrase Safely: What Steel, a Passphrase and Multisig Do for Your Wallet Backup
The Coldcard case pushed the manufacturer question to the front, while barely touching on where the backup is kept. This guide places paper, steel, the passphrase and splitting methods against the BIP-39 and SLIP-0039 standards.
August 11, 2026 9:18 AM

Your Crypto Exchange Is Telling You to Withdraw: How to Spot Phishing After the MiCA Deadline
Unauthorised crypto providers now have to tell their EU customers to withdraw, which leaves fraudsters an easy run with faked requests. Here is how to check in two minutes whether the message is genuine.
September 23, 2026 4:12 AM

How to Set Up a Crypto Wallet: Securing Your Coins in Seven Steps
Your own crypto wallet is set up in twenty minutes, yet a single step decides everything that follows. This guide takes you through wallet type, recovery words and the test amount, and sets out what BaFin and the tax office expect.
September 5, 2026 10:24 PM

Fake German Finance Ministry Letters: Why Nobody May Demand 19 Percent VAT on Your Crypto Purchase
Since September 1, 2026, Germany's Federal Ministry of Finance has been warning about forged letters that demand 19 percent VAT on cryptocurrency purchases while citing real transactions. That tax does not exist, and this is how to spot the forgery.
August 31, 2026 7:20 AM

Browser Extensions as Wallet Thieves: How a Sports App Became a Seed Phrase Collector
In August 2026 the security firm Socket disclosed two separate campaigns: 40 confirmed malicious Firefox extensions and 19 for Chrome and Edge, all of them from the official marketplaces. Nine of them were harmless sports apps that only turned into wallet thieves through an update.
May 15, 2024 12:04 PM

Crypto Scams: How to Protect Your Cryptos?
With the rise of crypto scams, and while international efforts are still working to combat these threats and protect investors, some recent tactics have been identified, and here is your full guide.
August 31, 2026 10:12 AM

Fake AML Checks for Crypto Wallets: How to Spot the Scam Sites
Fraudulent websites pose as money-laundering screening services for crypto addresses and ask you to connect your wallet. A genuine check needs only the public address, and three of the domains named by Malwarebytes still respond twelve days later.
October 2, 2026 10:36 AM

Hot Wallet or Cold Wallet: the Private Key Decides How Safe Your Coins Are
Hot wallet or cold wallet: the difference rests solely on whether the private key is online. What separates the two forms, where the limits of hardware lie and why moving to your own device triggers no tax.
April 25, 2024 11:44 AM

Beware of New Ethereum Node Scam: USDT Fraud Exposed
Crypto Scammers exploit Ethereum nodes and USDT to deceive crypto users. How are they pulling it off and what essential tips can help you protect yourself against these crypto scams?
September 30, 2026 7:16 AM

Tangem Wallet: The Card Without a Seed Phrase vs the Classic Hardware Wallet
The Tangem Wallet secures crypto with two or three identical cards instead of 24 words. What the sets cost, what the EAL6+ chip delivers and why losing every card is final.
September 15, 2026 10:14 PM

AI Crypto Crime: How Scams Are Getting More Convincing
AI is sharpening fake support, deepfakes and phishing across the crypto space. Why the data still needs a careful reading and which security routines protect a wallet.
September 19, 2026 10:11 PM

North Korean Hackers Drain 7,000 Crypto Wallets: What to Check on Job Offers and Coding Tests
Seven agencies, among them Germany's BND and BfV, warn about the WaterPlum group: 30,000 infected machines, more than 7,000 drained wallets. The bait is a job offer, the trap a coding test.
August 24, 2026 1:22 PM

Phantom Wallet Ends Sui and Monad Support: What to Do Before the Deadlines
Phantom Wallet removes Monad from its app on August 26 and Sui on September 24. The balances are not lost, but only one of the two ways out leaves your tax position untouched.
September 17, 2026 4:14 PM

D'CENT App Wallet: How to Tell If Your Recovery Phrase Has to Move Now
Manufacturer IoTrust reports suspicious asset transfers in the D'CENT app wallet and asks users to move their holdings. One question decides the matter: has your recovery phrase ever been entered into the app?
September 4, 2026 10:26 PM

Pocket Bitcoin Data Breach: When Name, Home Address and Bitcoin Address Circulate Together
The Swiss Bitcoin service Pocket Bitcoin closed its investigation on September 3, 2026: 5,411 people affected, and for 291 of them the Bitcoin addresses they used along with copies of identity documents. Why this one data pairing has lasting effect, and what you should check with your own provider.
September 28, 2026 10:26 AM

Phantom Wallet and Solscan: What a Solana Transfer Really Costs and Where It Fails
A transfer on Solana costs 0.000005 SOL, a new token account ties up 0.00148844 SOL once — both values measured on-chain by us today. This practical guide shows how to set up Phantom, how to get there from the exchange, how to read Solscan and what applies for tax in Germany.
September 4, 2026 10:17 AM

Cypher Shutdown on September 6: What Users Should Know Now the Withdrawal Deadline Has Passed
Recap as of September 27, 2026: Cypher had announced it would take its app, dApp and withdrawal window offline on September 6, 2026 and end the token protocol. This article describes the situation before the deadline, how the payout worked and what our own measurement showed at the time about what was left of the CYPR token.
May 4, 2019 5:44 PM

Microsoft Hackers Stole Crypto Using Victims Emails
Another batch of crypto users have lost money recently through an unlikely breach. Recently, Microsoft services such as Hotmail, MSN, and Outlook have been hit by a breach. It was later learned that the breach was due to an employee’s […]
September 25, 2026 4:11 AM

Bitget Hack of $351 Million: What to Check at Your Crypto Exchange Now
Bitget reports unauthorised outflows of around $351.6 million and has suspended withdrawals. For existing customers in Europe, that closes the one route MiCA had left them.
August 23, 2026 1:16 PM

Address Poisoning: Why Seven of Forty Characters Were Enough to Divert $2 Million
A fake wallet address matched the real one in just seven of forty characters and still intercepted 2 million USDC. Our own count of the affected wallet shows that a third of all counterparties in its history belong to such look-alikes.
September 19, 2026 1:23 AM

Hardware wallet lost: how to rescue your coins and what the tax office accepts
Your hardware wallet is gone, your coins are still on the blockchain: all that matters is whether you still have your recovery phrase. What goes wrong during a restore, and why the tax office as a rule does not recognise permanently lost access as a loss under Section 23 of the Income Tax Act.
August 22, 2026 10:29 AM

Bitcoin Fork: What Happens to Your Coins When the Chain Splits
On October 31, 2026 a new chain called ECX splits off from Bitcoin, and every holder is credited automatically. Who actually receives the coins depends on the private keys, on voluntary replay protection and on a tax rule many overlook.
More from CryptoTicker


