Phishing sites copy the look of real services pixel for pixel. The difference is always in the details. Here is a checklist you can run in seconds before connecting your wallet.
Check the domain carefully
Look at the exact spelling of the domain. Attackers use look-alike letters, extra words like "claim" or "airdrop", and risky top-level domains. A single swapped character can turn a trusted name into a trap.
How you arrived matters
Be extra careful with links from Discord, Telegram, X, and email. Most drainer victims arrive through a link someone sent them, not through a search they did themselves. When in doubt, type the address yourself.
Never share your seed phrase
No legitimate site, wallet, or exchange will ever ask for your seed phrase. If a page asks you to "restore", "validate", or "sync" your wallet by entering your seed phrase, it is a scam. Leave immediately.
Read the signature request
Before you approve anything, read what the transaction actually does. If it grants broad access or an unlimited approval to a site you do not fully trust, reject it.