Skip to main content

Recognizing and avoiding phishing: how to protect yourself

Learn how to spot phishing: fake support, fraudulent messages and scam calls, and protect your 21bitcoin account with clear warning signs and steps

Phishing is one of the most common forms of digital crime. Attackers use fake messages, calls or websites to push you into taking an action. For example, sharing confidential data, installing software or sending bitcoin.

These attacks often look professional and deliberately create time pressure. That makes it all the more important to know the typical warning signs and, when in doubt, always check back through an official channel.

🔐 The most important rules: No legitimate support team will ever ask you to send bitcoin or money, to reveal your seed phrase, your password or a 2FA code, or to install remote access or “security” software.

What is phishing?

In a phishing attack, criminals pose as trustworthy companies, authorities or individuals. Their goal is to obtain login credentials, security codes or other sensitive information, or to trick you into making a payment or transaction.

Phishing can happen across several channels:

  • Email phishing: Fake emails link to cloned login pages or contain malicious attachments.

  • Smishing: Fraud attempts via SMS or messenger, often with a link and an urgent call to action.

  • Vishing: Fraudulent phone calls in which the caller pretends to be a support agent, for example.

  • Fake websites and apps: Copies of official services designed to make you enter login or payment details.

  • Social media fraud: Fake profiles promising help, giveaways or unusually attractive offers.

What tricks do attackers use?

Phishing is usually a form of social engineering. Instead of attacking a technical system directly, criminals manipulate people. Typical methods are:

  • Time pressure: “Act now”, “Your account will be blocked” or “Confirm the new wallet within 30 minutes”.

  • Fear: There has supposedly been unauthorized access, a suspicious transaction or a security issue.

  • Authority: The message appears to come from a well-known company, from support or from a public authority.

  • Reward: A prize, bonus or exclusive offer is meant to make you click.

  • Building trust: Attackers mention personal details they previously collected from social networks, data breaches or public sources.

How do you recognize a phishing attempt?

Watch out for these warning signs in particular:

  • The contact is unexpected or comes through an unusual channel.

  • You are asked to act immediately and barely get time to think.

  • Someone asks for passwords, 2FA codes, verification links or your seed phrase.

  • You are told to transfer bitcoin to a supposed “security address”.

  • A link leads to an unknown domain or one that only looks similar.

  • You are asked to install an app, a file or remote access software.

  • The caller wants you to carry out a transaction during the call.

  • Sender name, phone number or logo look genuine, but the content and the request are unusual.

💡 A professional design, a familiar sender ID or personal data in the message are not proof of authenticity. Email addresses and phone numbers can be forged or technically manipulated.

How 21bitcoin communicates with you

To make it easier for you to identify genuine messages, 21bitcoin follows clear principles:

  • We communicate about account-related topics by email and via the chat in the 21bitcoin app.

  • We never send SMS about account status, blocks, activations or newly added wallets.

  • We will never ask you to send bitcoin or money to a “security address”.

  • We will never ask for your password, your 2FA codes or your seed phrase.

  • We will never require you to install remote access software or a “security app”.

  • Genuine automated emails from us contain your personal anti-phishing code.

  • You can verify support requests at any time directly in the support area of the app.

Checking your anti-phishing code

You can find your personal anti-phishing code in the app under “Your account” → “Security” → “Anti-phishing code”.

For automated emails, check whether the code is included correctly. If it is missing or does not match the code stored in your app, do not interact with the message and contact us directly via the app chat.

How to react correctly

  1. Stay calm and do not act under pressure. Legitimate security checks never require a rushed decision.

  2. Do not click any links. Open the 21bitcoin app yourself instead of using a link from a message.

  3. Do not share confidential data. Never share your password, 2FA code, verification link or seed phrase — not even over the phone.

  4. End suspicious calls. Do not call back any number given in the message; only use the official contact channels.

  5. Do not install any software. Never allow remote access or screen sharing on your device.

  6. Check your account directly in the app. Review your account status and the wallets stored there.

  7. Report and block the contact. Then delete the message and block the contact.

What to do if you have already responded?

Stay calm, but act quickly. Contact us immediately via the chat in the 21bitcoin app if you have shared data, installed software or confirmed a transaction.

Depending on what happened, additional steps make sense:

  • Entered login credentials: Change the affected password immediately via the official app or website. Use a new, unique password and secure your email account as well.

  • Shared a 2FA code: Contact support immediately and review your security settings.

  • Allowed software or remote access: Disconnect the device from the internet and have it checked by an expert before accessing financial accounts or wallets again.

  • Disclosed your seed phrase: Consider the corresponding wallet compromised. Move any remaining bitcoin to a newly created wallet using a trusted, clean device and get expert support if needed.

  • Confirmed a transaction: Contact us without delay. Bitcoin transactions usually cannot be reversed, so every minute counts.

How to protect yourself long term

  • Check your personal anti-phishing code.

  • Use a unique, strong password for every account, ideally with a password manager.

  • Enable secure two-factor authentication.

  • Keep your operating system, browser and apps up to date.

  • Only download apps from official app stores and check the publisher.

  • Bookmark official websites instead of using links from messages.

  • Store your seed phrase offline and never share it with anyone. Do not photograph it and do not save it in a cloud.

  • Publish as little personal information as possible that could be used for credible fraud attempts.

Three questions before you act ✅

  1. Was I expecting this contact?

  2. Does the message use an official channel and can I verify it independently

  3. Would I take the same action without time pressure?

Conclusion

Phishing works mainly through trust, fear and time pressure. The best protection is therefore a short pause: don't click, don't share any data and verify every request independently in the official app.

If you are unsure, end the communication and message us directly via the chat in the 21bitcoin app. Better to ask one time too many than to act one time too quickly.

Did this answer your question?