NFT & Web3 Scams
A single approved transaction on a malicious contract can drain an entire wallet. Fake mint sites and compromised Discord servers are the main vectors. NFT collectors and DeFi users face constant attacks.
How it worksThe anatomy of the scam
Every case follows roughly the same playbook. Recognize the pattern, stop it early.
1. The hook
A compromised Discord announcement, a Twitter DM about a 'secret mint', or a phishing link in a project's official channel.
2. The 'mint' site
A clone of a legitimate project's mint page, hosted on a lookalike domain.
3. The wallet connection
You connect your wallet and are asked to sign a transaction.
4. The drain contract
The signature approves unlimited spending of your tokens. Or it's a setApprovalForAll that hands over your NFTs.
5. Instant loss
Within seconds your ETH, tokens, and NFTs are moved out. Irreversible.
Warning signsRed flags to watch for
If you're seeing two or more of these, assume it's a scam until proven otherwise.
Urgency around a 'surprise mint'
Real projects announce mints days or weeks in advance.
Link from a DM
Treat every Web3 DM as hostile by default.
Transaction asks for 'Approve all'
That's a blank check for your entire wallet.
Seed phrase requested
Nobody ever needs your seed phrase. Ever.
Protect yourselfDo this. Not that.
✓ Do
Use a separate 'burner' wallet for new mints with only enough ETH for the transaction.
✗ Don't
Never share your seed phrase, even with 'support'.
✓ Do
Revoke token approvals regularly with revoke.cash.
✗ Don't
Don't click Web3 links from Discord DMs or Twitter replies.
RelatedIf this happened to you, also check
Has this happened to you?
Your story could stop the next person from losing their savings. Submit anonymously in about two minutes.