Digital Asset Database Digital asset research & education
BTC$77,901+1.70% ETH$2,407+1.28% USDT$0.9996+0.00% BNB$712.37+4.29% XRP$1.37+3.79% USDC$0.9998+0.01% SOL$100.84+2.96% TRX$0.3278+1.56% FIGR_HELOC$1.01-2.01% HYPE$82.00+1.46% ZEC$844.20+6.34% DOGE$0.0831+2.56% RAIN$0.0166-2.27% USDS$0.9998+0.01% XMR$513.32+0.98% LEO$9.44+2.10% LINK$11.29+2.55% WBT$71.36+1.56% ADA$0.2069+6.35% XLM$0.1777+3.18% BCH$250.42+2.43% DAI$0.9998+0.01% CC$0.1099-1.85% USDE$0.9994+0.00% USD1$0.9993+0.00% LTC$50.71+3.95% UNI$6.21+7.40% GRAM$1.34+1.43% HBAR$0.0768+4.83% USDG$1.00+0.03% AVAX$7.29+2.55% SUI$0.7671+7.88%
Menu
Home
Assets All assetsSectorsRankingsHeat mapScreenerCompare assets★ Saved
Fundamentals Fees & revenueValue lockedExchange volumeNetwork activityStablecoinsStaking & yield
Valuation Valuation ratiosSupply & issuanceMetric definitions
Institutional Exchange-traded productsCorporate treasuries
Research Research notesEvents calendarRisk frameworkSecurity incidents
Learn Learn libraryGlossaryCalculatorsMethodologyData sourcesData freshnessAI agentsPublic API
News Ask the data Global market About us
Reading options
Photography CryptoStudio
Guided view

New to markets — prices, yields, market cap? We explain every term as you browse, in plain English. Same data, with the help built in.

Expert view

You already know the market. Just the data — clean, fast and compact, with no extra explanations. This is the default view.

Light or dark
Language
Public API

Every figure on this site is available as JSON, with its period and source attached.

Read the API docs
Definition signature phishingwallet drainerapproval phishingsocial engineering

Phishing

Tricking someone into revealing a secret or approving a transaction by impersonating a trusted person, app, or website.

The classic form asks for a recovery phrase directly, through a fake wallet website, a look-alike domain bought through search advertising, or a support account that messages first in a chat app. The more expensive modern form asks for nothing secret at all: the victim connects a wallet to a malicious site and signs a token approval or an off-chain permit message, granting an address permission to move a token from the wallet later, without any further prompt. Because approvals persist until revoked, a signature made once can be used weeks afterward. Practical defenses are bookmarking the real site rather than searching for it, reading what a signature actually authorizes rather than the site's description of it, confirming details on a hardware device screen, and periodically reviewing and revoking outstanding approvals.

In practice

A wallet drainer site typically requests an approval for the maximum possible amount of a token, so a single signature is enough to move the entire balance of that token whenever the attacker chooses.

The common misunderstanding

That you are safe as long as you never share your recovery phrase, when one approval signature can grant an attacker standing permission to move tokens from your wallet.

02

Related terms

Address Poisoning A scam that plants a look-alike address in your transaction history so you copy it by mistake when…
Custody Risk The risk of losing access to digital assets because of how they are stored, whether by you or by a…
Key Loss Permanently losing the secret needed to move your assets, which no company, network, or court can…
Smart Contract Risk The risk that the code running a blockchain application behaves differently from what users expect,…
03

Lessons that use it

Assets

All assetsSectorsRankingsHeat mapScreenerCompareSaved

Fundamentals

Fees & revenueValue lockedExchange volumeNetwork activityStablecoinsStaking & yield

Valuation & risk

Valuation ratiosSupply & issuanceMetric definitionsRisk frameworkSecurity incidents

Institutional

Exchange-traded productsCorporate treasuriesEventsResearch notesNews

Learn

Learn libraryGlossaryCalculatorsAsk the dataAI agentsPublic API

About

About usContactMethodologyData sourcesEditorial policyData freshness

Legal

DisclaimersTerms of usePrivacy policy