Phishing
Plain English
Scam where someone impersonates a legitimate website or person to steal your private keys or seed phrase. They might send fake emails, create fake websites, or DM you pretending to be support. Golden rule: legitimate companies will NEVER ask for your seed phrase.
Technical
Social engineering attack attempting to obtain sensitive information (private keys, seed phrases, wallet credentials) by impersonating trusted entities. Common vectors: fake websites (typosquatting), email/Discord/Telegram scams, malicious smart contract approvals, fake token airdrops. Defense: verify URLs, bookmark sites, use hardware wallets, revoke token approvals regularly.