Social engineering is a collection of techniques in which an attacker uses psychological or social manipulation to persuade a person to disclose information, grant access, or perform an unsafe action.

Social engineering is particularly dangerous in cryptocurrency because many blockchain transactions cannot be reversed. If a user voluntarily reveals a private key or seed phrase, the blockchain itself generally cannot restore control to the legitimate owner.

An attacker may impersonate an exchange employee, developer, moderator, technical-support agent, or acquaintance. They may create artificial urgency, promise compensation, threaten account suspension, or claim that suspicious activity has been detected.

Common scenarios

  • fake technical support;
  • impersonation of project administrators;
  • fraudulent token or investment offers;
  • requests for authentication codes or seed phrases;
  • persuading users to install remote-access software.

Protection depends heavily on verification procedures. A person should not be considered legitimate merely because their username, profile picture, or message appears official. Critical actions should be verified through an independent communication channel.

Social engineering is closely related to phishing, but the concept is broader. Phishing is one specific form of deception, while social engineering includes many different methods of manipulating human behavior.