Dear BlockFin Users,
Phishing scams are a widespread form of online fraud in which attackers replicate legitimate websites to steal sensitive information, such as bank details, passwords, and personal data. These fake links are often distributed via SMS, email, and social media to deceive users. Here, we will explore common phishing techniques and offer practical tips to safeguard your assets. Stay vigilant and take proactive measures to protect yourself from these phishing email scams.
Common Phishing Techniques
Phishing attacks often involve tactics like email phishing and pharming:
Email Phishing: Attackers send deceptive emails with links to fake websites or malware downloads. Emails may appear to come from the official website but often use slight misspellings or unofficial domains. If users click these links or download malicious files, sensitive information like passwords and financial details may be stolen.
Pharming: By exploiting system vulnerabilities, attackers modify DNS files on users' devices, redirecting legitimate web addresses to phishing sites. Users may unknowingly enter personal data on these fake sites.
Crypto-Specific Scams
In the crypto space, scammers often impersonate platform staff, using SMS, email, or social media to spread fake messages about account upgrades, crypto refunds, suspicious asset inflows, or withdrawal closures. These messages contain phishing links or QR codes that trick users into providing sensitive account details, enabling scammers to steal funds. Please stay alert and verify all messages to protect your assets.
Tips to Prevent Phishing Scams
- Be Wary of Unsolicited Emails: Treat unexpected emails with caution, especially those urging immediate action. Scammers often create urgency to pressure you into hasty decisions.
- Verify Sender Email Addresses: Phishing emails may appear genuine, but the sender's email address often reveals the truth. Be cautious of slight variations or misspellings that mimic official exchange addresses.
- Don't Click on Suspicious Links: Always navigate to the exchange's website by typing the URL directly into your browser instead of clicking on links in emails. If you suspect a link is malicious, visit the official BlockFin site (https://blockfin.com) to change your login and fund passwords, and contact our official service (support@blockfin.com) immediately.
- Enable Two-Factor Authentication (2FA) and Passkeys: Strengthen your account security by requiring a second form of verification. This makes unauthorized access significantly harder.
- Protect Your Personal Information: BlockFin will never ask for your passwords, private keys, or sensitive account details via email.
- Stay Updated: Phishing tactics constantly evolve. Keep informed about the latest scams to better safeguard your assets.
- Set Up an Anti-Phishing Code on BlockFin: Setting up an anti-phishing code ensures that all legitimate emails from the BlockFin exchange include a specific identifier. This helps you distinguish genuine communications from fraudulent ones.
Here is a guide on how to set up anti-phishing code on BlockFin:
-
Click the avatar in the upper right corner and select [Account & Security].
-
Scroll down the page, find the Anti-Phishing Code, and click [Set up] to set up your anti-phishing code.
-
After the anti-phishing code is set successfully, the code will be present in all official emails from BlockFin. Kindly verify its presence whenever you receive emails from BlockFin.
If You’ve Been Scammed
-
Report the Scam: Contact our support team at support@blockfin.com.
-
If you’ve fallen victim to a scam, be cautious of further attempts by the same fraudsters. Avoid processing any withdrawals or transfers initiated by strangers.
We recommend seeking assistance from local authorities if you’ve been scammed by someone impersonating BlockFin. Additionally, we encourage all users, both new and experienced, to review more anti-scam resources to protect themselves from common crypto scams.
Thanks for your attention and support!
BlockFin Team
April 10, 2025