Recognising Solana Phishing: Five Patterns We See Repeatedly

Computer screen showing a suspicious website with warning symbols, illuminated by red and purple ambient light

22 September 2025

Phishing remains the leading cause of voluntary fund loss among Solana holders. Attackers do not need to break cryptography — they need you to approve a transaction that drains your wallet. Here are the patterns we encounter most often in client consultations.

1. Fake Airdrop Claim Pages

A social media post or direct message announces an exclusive token airdrop. The linked site asks you to connect your wallet and sign a transaction to “claim” tokens. The transaction actually grants the attacker’s program unlimited spending authority over your tokens.

What to do: Verify airdrops through official project channels and block explorers. Legitimate claims rarely require signing unknown smart contracts.

2. Spoofed Transaction Previews

Some malicious sites display a fake preview showing a small transfer while the actual signed instruction transfers your entire balance. Wallet software has improved preview accuracy, but blind signing on unfamiliar programs remains dangerous.

What to do: Expand every transaction detail before approving. If you cannot identify each instruction, reject the signature.

3. Urgent Support Impersonation

Attackers posing as wallet support staff contact you on Discord or Telegram, claiming your account is compromised and requesting your seed phrase to “secure” it. No legitimate support team will ever ask for your recovery phrase.

What to do: Block and report the account. Contact wallet support only through official websites.

4. Cloned dApp Interfaces

Fake copies of popular DeFi interfaces appear at slightly misspelled URLs. The interface looks identical, but the connected program is malicious.

What to do: Bookmark official dApp URLs. Never follow links from unsolicited messages.

5. Malicious Browser Extensions

Extensions promising portfolio tracking or gas optimisation sometimes request broad permissions and intercept transaction data.

What to do: Install extensions only from official browser stores with verified publisher status. Review permissions and remove anything unused.

Building Awareness in Groups

These patterns are covered in depth during our Group Wallet Safety Workshop, where participants practise identifying red flags in simulated scenarios.

If you suspect you have already signed a malicious transaction, book a consultation immediately — speed matters when revoking approvals.