← Back to Glossary

Phishing Attack

A phishing attack uses fraudulent messages, websites or apps that impersonate trusted parties to trick victims into revealing credentials or signing malicious transactions. In bitcoin, the primary target is the seed phrase, since anyone holding those words controls the coins. The 2020 breach of hardware wallet maker Ledger's marketing database exposed contact details of roughly 270,000 customers, fueling years of targeted phishing campaigns.

Why it matters

Bitcoin transactions are irreversible and bearer-like, so phishing that succeeds is theft completed: there is no issuer to freeze the transfer and no chargeback path. Attacks have grown specialized, from fake wallet apps in official app stores to poisoned search ads, counterfeit security emails urging urgent seed verification, and address poisoning that seeds a victim's transaction history with lookalike addresses. The defense is procedural: a seed phrase is never typed into any website or app, hardware wallets confirm addresses on their own screens, and no legitimate company ever asks for the words.

In the gold vs bitcoin debate

Critics of self-custody point to phishing as the honest cost of bitcoin's model: the same finality that removes counterparty risk removes the safety nets. Gold's analogue is physical robbery, which requires presence and force; bitcoin theft scales remotely across oceans. Advocates respond that custody options now span a spectrum, from collaborative multisig to insured custodians, letting holders price their own trade-off between sovereignty and protection.

Ready to convert your gold to Bitcoin?

Get Your Free Kit →