Social Engineering
Manipulating people rather than code, tricking them into handing over keys, codes, or access.
Social engineering attacks the human, not the software. The attacker builds trust or urgency—posing as support staff or a friend in trouble—and persuades the target to reveal a seed phrase, approve a transaction, or install malware. No exploit code required.
Crypto has lost staggering sums this way. The $600 million-plus Ronin bridge hack began with a fake job offer that planted malware on a developer's machine. The defenses are habits, not tools: treat unsolicited contact as hostile, and never share a seed phrase with anyone—support staff included.
Related terms
A scam that tricks you into revealing keys or signing a malicious transaction by posing as something you trust.
SIM SwapAn attack that transfers your phone number to the attacker's SIM card to intercept calls and SMS codes.
Wallet DrainerMalicious code that empties a wallet in one approval after tricking the owner into signing it.
Two-Factor Authentication (2FA)A second login check beyond your password, usually a one-time code, that blocks attackers who steal credentials.