October has carried the cybersecurity label since 2004. SimpleSwap has been writing the crypto edition since the summer, under Know the Scam. Here is where the official month and the series meet, and what the series publishes next.
A month with four habits
Every October since 2004, the National Cybersecurity Alliance and CISA have asked the public to do four things: use strong passwords with a password manager, turn on multi-factor authentication, install software updates, and recognize and report phishing. This year the Alliance's line is "Don't Make It Easy for Them," and CISA's is "Securing the Next 250," a nod to the country's 250th anniversary. Europe's Cybersecurity Month, coordinated by ENISA, has kept one motto since 2020: "Think Before U Click."
The advice was written for email accounts and office laptops. Inside a self-custodial wallet, the same four habits carry more weight, because there is no password reset and no chargeback. In January, according to the security firm Scam Sniffer, one person lost $12.25 million by copying an address out of their own transaction history. The first characters matched. So did the last. An attacker had planted the look-alike earlier with a transfer the size of dust, a technique called address poisoning, and a month before that someone else had lost $50 million the same way. Nothing was hacked. Something was pasted.
SimpleSwap, a self-custodial swap aggregator that has run wallet-to-wallet swaps since 2018 and holds no long-term user balances, is marking the month with a campaign called Check Before You Swap (#CheckBeforeYouSwap). The starting point is that most of what October asks for has already been written down, in a series that began before the month did.
We did not wait for October
Since the summer, SimpleSwap's Know the Scam series has been taking the attacks that reach a swap window one pattern at a time. It opened with a map of eight of them and where each meets a swap. Approval phishing and wallet drainers explained how one signature empties a wallet without a seed phrase changing hands. MEV and sandwich attacks covered the loss with no villain in it, when bots skim a trade inside the block. Honeypot tokens and rug pulls separate a contract that will not let you sell from a pool that empties while you hold. Fake airdrops and drainer dApps put a price on the word "free." Alongside the articles came a tool: Address Check, inside the SimpleSwap Customer Account, screens a wallet address through third-party services and returns a risk level with the connections found, with a monthly allowance set by Loyalty Program tier. The longer guides live in the Safety Academy, including one on what phishing looks like in 2026.
Set against the official list, the series has covered the third habit in depth (updates, and the stale token approvals that updates never touch) and much of the fourth (phishing in its on-chain forms). It has said less about the first two: the seed phrase itself, and the hardware and second factors around it. October is where the gaps close.
Four habits, read from a swap window
Strong passwords become seed-phrase hygiene. The phrase goes on paper and stays offline, never photographed, never saved to a notes app, never typed into a site that promises to "validate" or "sync" a wallet, and never read aloud to anyone who says they are support.
Multi-factor authentication becomes a hardware wallet for balances that matter, plus app-based 2FA on the email and exchange accounts connected to your crypto. The wallet signs; the phone confirms. Neither trusts the other by default.
Software updates become wallet and firmware updates from the vendor's own channel, including the prompt that has sat unopened for weeks, and a periodic review of token approvals. A drainer does not need your seed phrase; it needs one signature. Scam Sniffer's 2025 report put wallet-drainer losses on EVM chains at $83.85 million across 106,106 victims, an 83% fall from 2024 that the firm still calls a lower bound, with Permit-style signatures behind 38% of losses in incidents above $1 million. CertiK's mid-year report shows the attackers getting choosier: phishing incidents in the first half of 2026 fell 52.3%, to 63, while losses fell only 10.8%, to about $366 million. Fewer attempts, larger wallets.
Recognizing and reporting phishing means spotting clone domains, poisoned addresses, fake support messages, and look-alike apps, then reporting them to the authorities (the FBI's IC3 in the United States, the national contacts on ENISA's Cyber First Aid page in Europe) and to the brand being impersonated. The FBI's 2025 Internet Crime Report logged 181,565 cryptocurrency-related complaints with more than $11 billion in reported losses, the highest of any category.
Before you press send
Four jobs a user hires a swap service for, and what each one actually gets done.
When I open a swap link, I want to know I am on the real site so I don't pay a clone. SimpleSwap's only official domain is simpleswap.io, and copies keep reappearing. People type "is SimpleSwap legit" and "is SimpleSwap safe," and some type "Simple Swap" with a space; a clone needs only one of those searches to land, which is why a SimpleSwap review or the Trustpilot page (a 4.1 TrustScore from more than 2,600 reviews as of September 28) is worth reading before the first swap rather than after. Type the domain once and bookmark it; from then on, use the bookmark. The real SimpleSwap app is listed on the App Store and on Google Play under Simple Swap LTD. Real support is the live chat on the site, never an account that messaged you first.
When I paste a destination address, I want to know it is the one I meant so that I can send without regret. Read it in chunks, the way you would read back a phone number, and choose the network on purpose. Address Check adds context about who is on the other end. It does not replace your own checks, and no service can reverse a confirmed transaction.
When I buy a token someone is promoting, I want to know I can sell it so I don't get trapped. A swap service can move you into a token and cannot move you out of one whose contract blocks the sell. The company says it declines listing requests for tokens its internal review identifies as scams, which narrows exposure on its own platform and says nothing about contracts you meet elsewhere.
When a swap stalls, I want a person and a record, so I can find out where my funds are. Save the order ID before you send. Every swap has one, with real-time tracking, and support runs 24/7 via live chat and email, with an average response time of about four minutes. A fixed rate locks the price for 20 minutes; a floating rate settles at execution. Fees start at 0.2% and vary by pair, liquidity, market conditions, and loyalty level.
What no swap service can undo
SimpleSwap does not hold your seed phrase and cannot recover it. It cannot reverse a confirmed transaction or undo a transfer to a poisoned address. It cannot sell a token whose contract forbids selling. Its screening reduces exposure to known bad actors, and no screening sees everything. Every article in the series is written on the far side of those four sentences.
October in Know the Scam
"The loss data has a shape. The largest thefts come from compromised infrastructure, and awareness campaigns can't fix those. Many individual victims lose to a signature or a pasted address. That second group is the one October can reach, and it is why a month like this is worth the effort," said Rick Cramer, Head of Analytics at SimpleSwap.

This article was written by SimpleSwap — a self-custodial multi-source swap aggregator. 2,800+ assets, 20+ liquidity providers across CEX and DEX sources, 20M+ swaps since 2018. Wallet-to-wallet by design, with routing handled under the hood.
The information in this article is not a piece of financial advice or any other advice of any kind. The reader should be aware of the risks involved in trading cryptocurrencies and make their own informed decisions. SimpleSwap is not responsible for any losses incurred due to such risks. SimpleSwap’s only official domain is simpleswap.io.