Avoid phishing and scams
How wallet scams work, the five habits that stop almost all of them, and what Morsel does to help.
Almost every lost wallet comes down to one of two things: someone got the recovery phrase, or the owner signed something they didn't understand. Both are preventable.
Five habits
- Never share your recovery phrase or private key. Not with support, not with a site, not to "verify" or "sync" anything. See What Morsel will never ask.
- Check the domain in the address bar and on every request. Phishing sites copy logos and layouts, not domains.
- Read the preview. If You send shows anything you didn't expect, cancel. See Approve and sign safely.
- Open apps from Apps or your bookmarks, not from links in DMs, replies, ads or token names.
- Pay from your contacts, never from an address copied out of your history.
How a typical scam works
- You get a link: in a DM, a reply, an email, an ad, or the name of a token or NFT that appeared in your wallet.
- The site looks exactly like a real app.
- Its domain is slightly off: an extra letter, a swapped character, a different ending.
- You connect and approve a transaction.
- The transaction hands over your tokens, or the right to spend them.
Common scams
- Free claims. "You're eligible! Claim your airdrop." If you didn't expect it, it's a trap.
- Fake urgency. "Your wallet is compromised, verify now." Morsel never sends messages like this.
- Fake support. Someone DMs you offering help. Real support never DMs first and never asks for your phrase.
- Fake "fix" or "revoke" sites that ask you to sign something to "secure" your wallet.
- Address poisoning. Tiny payments from addresses that look like ones you've used, so you copy the wrong one next time.
- Scam NFTs and tokens with a link or QR code in the image or name. See Scam tokens and NFTs.
- Fake apps in app stores or ads. Install Morsel only from morselwallet.app/install.
What Morsel does
- Blocks known phishing sites in the browser: Dangerous site blocked.
- Flags lookalike domains of well-known apps and suspicious URLs on connect and signing requests.
- Warns about unknown sites: This site isn’t in Morsel Apps. Only continue if you trust it.
- Simulates every transaction and blocks the most dangerous patterns.
- Refuses transactions disguised as messages.
- Hides spam NFTs and dust from strangers.
- Warns in Send about lookalike addresses: This looks like a saved address, but isn’t.
- Warns about links in chats and in notes.
If you think you were scammed
Act fast. See If your wallet is compromised.