How to report a crypto wallet phishing site
Crypto wallet phishing sites imitate trusted wallets, exchanges, and Web3 login screens to steal seed phrases, private keys, and two-factor codes.
This guide explains how to report them quickly and correctly so the site can be taken down and other users can be protected.
The process is more effective when you capture evidence first, report to the right organizations, and avoid interacting with the site beyond what is necessary for documentation.
What counts as a crypto wallet phishing site?
A crypto wallet phishing site is a fake page designed to look like a legitimate wallet or blockchain service.
Its purpose is to trick users into entering sensitive information or approving malicious transactions.
Common examples include:
- Fake MetaMask, Trust Wallet, Phantom, or Coinbase Wallet login pages
- Replica exchange sign-in pages that request seed phrases or recovery phrases
- Web3 dApp prompts that imitate token approvals or wallet connections
- Cloned support portals that ask users to “verify” wallet ownership
- Malicious airdrop or NFT claim pages that trigger harmful signature requests
Many phishing pages use typosquatted domains, lookalike branding, and urgent language such as “wallet suspended” or “verify immediately.”
What to do before you report the site
Before filing any report, collect evidence in a safe, minimal way.
Do not enter a recovery phrase, private key, password, or one-time code on the page.
Capture the following:
- The full URL, including the exact domain and path
- Screenshots of the page, especially branding and form fields
- The date and time you found it
- Any wallet name or brand being impersonated
- Email addresses, contact forms, or Telegram handles shown on the page
- Transaction hashes if you were tricked into signing or sending funds
If the site asked you to connect a wallet, review the permissions you granted and disconnect from the wallet app if needed.
If you signed a malicious approval, revoke token permissions as soon as possible through your wallet’s security tools or a trusted blockchain approval checker.
How to report crypto wallet phishing site to the browser and search engine?
Browser vendors and search engines can remove dangerous pages from search results and block access warnings for future visitors.
Reporting to them is one of the fastest ways to reduce exposure.
Report to Google Safe Browsing
Google uses Safe Browsing to flag harmful sites in Chrome and Search.
Submit the phishing URL through Google’s phishing report and the Safe Browsing reporting flow.
Include the exact URL and a short note that the page impersonates a crypto wallet or exchange.
Report to Microsoft
If the site appears in Edge or Bing, report it through Microsoft’s security reporting tools.
This helps trigger browser warnings and search result filtering.
Report to Mozilla Firefox
Firefox relies on phishing and malware blocklists.
Use Mozilla’s phishing report options when the site targets Firefox users or is being distributed through links in browser-based scams.
Report to other browsers and blocklist services
If the scam is widespread, submit it to additional reputation and abuse systems that feed into security products and URL scanners.
The broader the reporting, the harder it becomes for the site to stay visible.
How to report to the wallet provider?
If the phishing site impersonates a known wallet brand, report it directly to the official support or abuse channel for that wallet provider.
Wallet companies often maintain dedicated anti-phishing teams and can issue user warnings, social posts, or domain takedown requests.
When submitting the report, include:
- The phishing URL
- Brand names and logos used by the fake site
- Evidence of impersonation, such as copied UI text or cloned support language
- Any wallet addresses or transaction IDs tied to the scam
Examples of providers that are often impersonated include MetaMask, Trust Wallet, Phantom, Ledger, Trezor, Coinbase Wallet, and Binance-related services.
Use only the official support pages published by the vendor.
How to report the site to the hosting provider or domain registrar?
Hosting providers and registrars can suspend domains, servers, or DNS configurations when phishing is confirmed.
This can be one of the most effective takedown paths because many phishing operations rely on inexpensive infrastructure.
To find the right abuse contact, check the site’s WHOIS records, DNS records, or hosting details using reputable lookup tools.
Then send a concise abuse report that includes:
- The malicious URL and domain
- Proof that the site is impersonating a crypto service
- Screenshots of the phishing content
- The affected brand or wallet name
- A request for prompt suspension or removal
Keep your message factual.
Avoid speculation and explain why the page is deceptive, such as copied logos, fake login forms, or prompts for seed phrases.
How to report to law enforcement and cybercrime agencies?
If you lost funds, received threats, or believe the phishing campaign is part of a larger fraud network, report it to law enforcement and relevant cybercrime portals.
These reports help investigators connect infrastructure, payment flows, and victim accounts.
Possible reporting channels include:
- The FBI Internet Crime Complaint Center (IC3) in the United States
- Action Fraud in the United Kingdom
- National cybercrime reporting portals in your country
- Local police or financial crimes units for immediate loss incidents
Provide wallet addresses, transaction hashes, timestamps, screenshots, and any communication history.
If the scam involved an exchange account, also notify the exchange’s fraud team so they can flag linked addresses or accounts.
How to document evidence correctly?
Good evidence increases the chance of takedown and helps investigators trace the phishing campaign.
Use a clean folder or incident log to organize materials.
Include these items:
- Original URL and any redirect chain
- Screen recordings, if the site changes dynamically
- Source code snippets only if they show malicious intent, such as form submissions to unknown endpoints
- Wallet addresses involved in the scam
- Network indicators, such as suspicious IPs or file names, if visible in your security tools
Do not alter the page, and do not use developer tools unless you know how to do so safely.
Preserving the original state makes your report more credible.
What information should go into the report?
Whether you are reporting to a browser vendor, wallet provider, registrar, or police agency, a strong report should be short, specific, and evidence-based.
- Subject line: “Phishing site impersonating [wallet name]”
- Exact URL or domain
- Brief description of the scam behavior
- Screenshots or attachments
- Impact, such as attempted theft or actual loss
- Your contact information if follow-up is needed
If the platform allows categories, choose phishing, impersonation, fraud, or malware abuse.
These labels help route the report to the right response team.
What if you already interacted with the site?
If you entered a seed phrase, private key, or recovery phrase, assume the wallet is compromised.
Move remaining assets to a new, secure wallet immediately, using a trusted device and official wallet software.
If you approved token spending or signed a malicious transaction, revoke permissions where possible and monitor the wallet address for follow-up attacks.
Change any linked email passwords and enable security alerts for exchange accounts tied to the wallet.
If funds were stolen, save every transaction hash and address involved.
Fast reporting improves the chance of tracing transfers before assets are swapped or moved through mixers or bridges.
How to protect others while the report is pending?
While takedown requests are being processed, warn others through trusted channels.
Share only the phishing domain and a short explanation so people can avoid the page without amplifying the scam content.
- Post a caution in relevant community forums or official support spaces
- Notify your team or organization if the link was shared internally
- Update bookmark lists and browser protections for users who may have visited the site
- Use reputation and security tools that block known malicious domains
Timely reporting, precise evidence, and the right abuse channels make a major difference when dealing with wallet phishing.
The faster the site is documented and escalated, the sooner browsers, providers, and registrars can act.