Search

Results for “Front-end hijack vs Phishing”

Front-end hijack and Phishing, side by side

Front-end hijack

A front-end hijack is an attack on the website of a crypto app rather than its smart contracts. The attacker takes over the domain, the hosting or a code library the site loads, so people visiting the real address see a normal-looking page that asks them to sign transactions sending funds to the attacker.

What it means for you. Typing the correct address is not enough here, because the address itself is serving the attack. What protects you is reading each request in your wallet: the contract you are calling, the spender of any approval and the amount. A request for an unlimited approval or a transfer you did not intend is a reason to reject it, even on a site you have used for years.

Sources: CISA: DNS infrastructure hijacking campaign, Monperrus, Software Supply Chain Security of Web3 (arXiv) · checked 4 October 2026

Phishing

Phishing is a scam in which someone pretends to be a company, service or person you know, usually by email, text or a fake website, to trick you into handing over information. In crypto the target is often your seed phrase, your login, or a signature from your wallet.

What it means for you. A real wallet app or exchange never asks for your seed phrase; anyone who has it can empty the wallet. Phishing sites copy real ones, so check the exact web address before connecting a wallet or typing a password. Crypto sent or signed away on a fake site usually cannot be reversed.

Sources: FTC: How to recognize and avoid phishing scams, ethereum.org: Scam help and reporting · checked 4 October 2026

Every word

On Cryptominium

Compare coins Any two coins, side by side