Digital Asset Database Digital asset research & education
BTC$77,361+0.35% ETH$2,392-0.77% USDT$0.9998+0.01% BNB$687.31+1.15% XRP$1.35+0.37% USDC$0.9998+0.01% SOL$99.73+0.34% TRX$0.3246+0.51% FIGR_HELOC$1.01-0.12% HYPE$81.84-0.29% ZEC$816.37-0.68% DOGE$0.0818+0.34% RAIN$0.0167+2.44% USDS$1.0000+0.02% XMR$500.56+0.80% LEO$9.24-1.40% WBT$70.88-0.18% LINK$11.12-0.39% ADA$0.1992+1.95% XLM$0.1747-0.35% BCH$244.50-0.27% DAI$1.0000+0.00% CC$0.1101-2.93% USDE$0.9996+0.01% USD1$0.9994+0.00% LTC$49.85+0.49% GRAM$1.33+1.08% UNI$5.88+2.73% HBAR$0.0740-0.05% USDG$1.00+0.04% AVAX$7.18-0.20% SHIB$0.00000516+0.81%
Menu
Home
Assets All assetsSectorsRankingsHeat mapScreenerCompare assets★ Saved
Fundamentals Fees & revenueValue lockedExchange volumeNetwork activityStablecoinsStaking & yield
Valuation Valuation ratiosSupply & issuanceMetric definitions
Institutional Exchange-traded productsCorporate treasuries
Research Research notesEvents calendarRisk frameworkSecurity incidents
Learn Learn libraryGlossaryCalculatorsMethodologyData sourcesData freshnessAI agentsPublic API
News Ask the data Global market About us
Reading options
Photography CryptoStudio
Guided view

New to markets — prices, yields, market cap? We explain every term as you browse, in plain English. Same data, with the help built in.

Expert view

You already know the market. Just the data — clean, fast and compact, with no extra explanations. This is the default view.

Light or dark
Language
Public API

Every figure on this site is available as JSON, with its period and source attached.

Read the API docs
Counterparty risk all

Phishing and Social Engineering

Attackers take assets by persuading holders to sign a transaction or reveal a secret, without breaking any cryptography or contract.

How it happens

The most common losses require no technical exploit at all. Token approval drainers ask a user to sign a message granting a contract permission to move their balances, which looks routine and is often signed blind because wallets display raw calldata rather than an outcome. Delivery methods are ordinary: a hijacked domain or a paid search result pointing at a cloned front end, a compromised front-end dependency serving malicious code from a legitimate address, a support impersonator in a chat channel, an airdropped token whose sale requires an approval, or an address-poisoning transfer designed to plant a lookalike address in the transaction history. Where accounts are protected by text-message codes, a carrier account takeover defeats the second factor entirely.

What you can actually observe

Review outstanding token approvals with an allowance viewer, since standing approvals are the main mechanism and are visible on-chain. Check whether the wallet decodes calldata into a plain-language action and whether the project pins its front end to a content hash or serves it from a decentralized host. Domain hijacks, dependency compromises, and support-impersonation waves are usually documented publicly by the projects affected.

Precedent

A 2020 breach of customer records at hardware wallet maker Ledger was followed by a sustained phishing campaign against the exposed customers, and separate domain and front-end hijacks have redirected users of several protocols to malicious sites while the underlying contracts were untouched.

What makes it more or less material

Consider how many standing approvals exist and how broad they are, whether signing requests are human-readable, whether the front end is pinned or hosted conventionally, and whether any account still relies on text-message codes.

01

Related factors

Smart Contract Defect Technical A flaw in deployed contract code lets funds be moved, locked, or destroyed in ways the designers never…
Admin Keys and Multisig Control Governance A small set of keys can pause, upgrade, mint, or move assets, so the system's safety depends on those…
Custodian Single Point of Failure Counterparty One custodian, one signing arrangement, or one operations team stands between holders and their assets, so a…
Key Management and Personal Loss Counterparty Self-custody puts the holder in charge of a secret that cannot be reset, so losing it or destroying the only…

Assets

All assetsSectorsRankingsHeat mapScreenerCompareSaved

Fundamentals

Fees & revenueValue lockedExchange volumeNetwork activityStablecoinsStaking & yield

Valuation & risk

Valuation ratiosSupply & issuanceMetric definitionsRisk frameworkSecurity incidents

Institutional

Exchange-traded productsCorporate treasuriesEventsResearch notesNews

Learn

Learn libraryGlossaryCalculatorsAsk the dataAI agentsPublic API

About

About usContactMethodologyData sourcesEditorial policyData freshness

Legal

DisclaimersTerms of usePrivacy policy