Crypto Phishing in 2026: The Tells You Were Taught Are Gone

Bad grammar and a suspicious link used to give phishing away. Both signals are gone now. Here's what actually works today – and the one thing attackers still can't forge: how you arrived at the site.

Two ways it reaches you now

Search ads

Fake ads impersonating Uniswap, PancakeSwap and others, routed through a Google-owned domain to pass automated review. The ad gets checked. The destination doesn't.

AI-written messages

No typos, correct branding, a believable tone. Phishing kits with credential-harvesting pages sell for under $100 – no technical skill required.

For fifteen years the advice was to read the message. That test no longer detects anything.

$1.27M

stolen via fake search ads in a single 17-day window, March 2026 (SEAL)

54%

click-through rate for AI-automated spear phishing, vs 12% for generic phishing

94%

of Microsoft-tracked email attacks were credential phishing by March 2026, up from 89%

You'll also see a claim that 82.6% of phishing emails now contain AI-generated content. Treat it as a directional signal, not a measurement – the source report doesn't publish full methodology.

The technique that beats two-factor authentication

Adversary-in-the-middle phishing runs a live proxy between you and the real service. You type your real password into what is functionally the genuine login flow, and your 2FA code works – because it's being relayed in real time. What the attacker takes is your session token, not your password.

SMS or app codes

Anything you can read and retype can be relayed. Not protection against this attack.

Passkeys & FIDO2 keys

Cryptographically bound to the real domain. They stay silent against a proxy.

Where it arrives from now

Email is still the volume channel. The growth is elsewhere.

Physical letters

Printed mail on branded letterhead, impersonating hardware wallet companies, with a QR code leading to a cloned setup page asking for your recovery phrase.

Calendar and cloud invites

Fake renewal notices injected directly into calendar invites, or phishing pages hidden inside cloud documents to dodge reputation-based filters.

Voice

AI voice cloning needs a few seconds of audio. A call from “support” asking you to read back a code is now cheap to produce at scale.

Fake security prompts

A “mandatory” 2FA upgrade or wallet migration that leads to a cloned interface asking for the recovery phrase, in the name of protecting it.

What phishing is actually after

Your recovery phrase

Cloned wallets prompt you to “restore” or “re-sync.” The screen looks legitimate because a real version of it exists – what matters is who started the process, not what it asks for.

Your login and session

A live proxy relays your password and 2FA code to the real site in real time, then steals the session token that proves you're already logged in.

Your signature

Not a credential at all – an approval that lets a contract move your tokens later. Covered in its own entry on wallet drainers. Read more →

Attackers can clone the interface, buy the top search result, and relay your login. What they can't control is how you arrived.

What actually holds up

  • Reach every crypto service through a bookmark you created once from a hand-typed address – it defeats search ads, SEO poisoning and typosquatting in one habit.
  • Never act on inbound contact – email, call, letter, calendar invite, DM. Go to the service through your own bookmark and check there instead.
  • Treat urgent security warnings as the likeliest bait. Real providers don't announce mandatory upgrades that begin with your recovery phrase.
  • Use a second factor that can't be relayed. Passkeys and FIDO2 keys are bound to the real domain; SMS and app codes are not protection against this.
  • Type a seed phrase only into a restore you started yourself, in wallet software you installed – never into a screen that found you.
  • Distrust QR codes on paper. A code in a letter is a link you can't inspect before you follow it.

Phishing is the pattern most likely to use our name without involving us

SimpleSwap will never message you first, never ask for your recovery phrase, and never announce a mandatory security upgrade by email, letter or calendar invite. A standard exchange doesn't require connecting a wallet or signing anything.

Our only official domain is simpleswap.io. Type it by hand once, bookmark it, and use the bookmark from then on – that habit is worth more than anything else on this page.

Want the full breakdown?

Read the full guide for the SEAL and Microsoft research in detail, the adversary-in-the-middle mechanics, and the complete list of what still holds up.

Key takeaways

  • Bad grammar and suspicious links no longer give phishing away.
  • How you arrived at a page matters more than how it looks – attackers can't control your route.
  • Passkeys and FIDO2 keys resist adversary-in-the-middle phishing; SMS and app codes don't.
  • SimpleSwap never messages you first and never asks for your recovery phrase.

Crypto Phishing FAQ

Because AI-written phishing has no typos, uses correct branding, and search ads can route through a reputable-looking domain before redirecting. The message itself is no longer the obvious giveaway – how you arrived at the site is.

Not the newer attacks. Adversary-in-the-middle phishing relays your password and your SMS or app code to the real site in real time, then steals the session token instead. Passkeys and FIDO2 security keys resist this because they're bound to the real domain; six-digit codes are not.

How you arrived at the site. Attackers can clone the interface, buy the top search result and relay your login – but a service reached through a bookmark you created yourself was never intercepted in transit.

No exchange can be, and phishing is the pattern most likely to use our name without involving us at all. We will never message you first, never ask for your recovery phrase, and never announce a mandatory security upgrade by email, letter or calendar invite. A standard exchange also doesn't require connecting a wallet or signing anything.