One quarter of this series, condensed into eight questions. None require technical knowledge, and together they catch almost every pattern we have written up. Save it, send it to someone, or run it in your head before the next transfer. Part of Know the Scam by SimpleSwap.
Every crypto scam in this series ends at the same place: a confirmed transfer that cannot be reversed by anyone. Which means every useful defense happens in the minutes beforehand, and almost all of them come down to asking the right question at the right moment.
Here are the eight, in the order they tend to matter.
1. Did they contact me first?
The single highest-value question, because it filters an enormous share of what follows.
Support desks answer in the channel where you asked. Companies do not DM you about problems. Nobody legitimate arrives unannounced with an opportunity or an offer of help. If the conversation started because someone reached out to you, treat everything in it as unverified, no matter how much they know about you or how correct their branding looks.
That includes the reply that arrives within a minute of your public complaint. Speed is not proof of employment.
2. How did I get to this page?
Attackers can copy an interface pixel-for-pixel, write flawless English, and buy the top search result. What they cannot control is the route you took.
If you arrived via a bookmark you made yourself, from an address you typed by hand, you are almost certainly where you think you are. If you arrived via a search result, an ad, a link in a message, or a QR code on a letter, you have no such guarantee. The padlock does not help here, since most phishing pages have one.
3. Am I being asked to send in order to receive?
This kills giveaways, doublers, recovery services, and release fees in one line.
One distinction matters before the rest. Sending an asset and receiving a different one back is an exchange, and both sides of it are in the quote before you confirm. What this question catches is a payment demanded to release money you were already told is yours: winnings to unlock, recovered funds to free up, a balance waiting behind a fee. In an exchange the money you send is the transaction. In the pattern above it is a condition attached to money that does not exist.
Nobody who is genuinely giving you money needs yours first. A “giveaway” that requires payment is a purchase, and you are buying nothing. A recovery service that charges upfront is the second scam after the first.
4. Am I receiving something or granting something?
The question that separates a real airdrop from a drainer.
A legitimate claim moves tokens toward you. A drainer asks for permission over tokens you already hold, which is not a payment and therefore does not feel like one. If a page promising free tokens asks you to approve or sign something, that request is the product.
5. Does this require my recovery phrase?
If the answer is yes, stop. There is no exception anywhere.
No exchange, wallet provider, support agent, recovery service, auditor or government agency needs a seed phrase to do anything. It is the wallet itself. Anyone who needs it is not helping you use it, and the request is the attack regardless of the pretext, including verification, syncing, migration, and security upgrades.
6. Have I checked the address that is actually in the field?
Not the one you copied. The one sitting in the recipient box right now.
Two different attacks target this moment. Address poisoning inserts a lookalike into your transaction history, hoping you copy from it. Clipboard malware swaps the address after you copy it, so even a correct source ends up at the wrong destination. Both defeat a glance at the first and last four characters, because those are exactly what gets matched.
Compare the middle of the string against a source you control, and if you use a hardware wallet, read it from the device screen rather than your computer.
Once the string matches, there is a second thing to know about it: who it belongs to. Some wallets and services now let you screen a destination address for known risk connections before you send. That is a separate check from the one above, and it only makes sense after you are sure the string is the one you meant.
7. Can I get out?
Ask this before you get in, especially for anything new.
For a token: can independent wallets actually sell it, and is liquidity locked? A chart that only goes up can mean nobody is permitted to exit. For a platform: can you withdraw a small amount, today, without a fee to unlock it? Profits displayed inside an app nobody else can audit are set dressing, and a withdrawal fee is the oldest signature in fraud.
8. What is the hurry?
Urgency is the one ingredient present in nearly every scam on this map, because the countdown exists to stop you doing the other seven checks.
A limited window, a closing allocation, an account about to be frozen, an emergency that needs a decision now. Real opportunities and real support are worth your time. If something cannot, that is the finding.
The short version
If receiving requires sending, it is theft with extra steps. If they contacted you, you cannot verify them by talking to them. If it needs your seed phrase, it is over. If you cannot exit, you never owned it. If it cannot wait an hour, that is your answer.
Where we fit
Since the eighth question is about pressure, here is ours removed: nothing about a swap is urgent, and we will never contact you to say otherwise.
We do not message first. We never ask for a recovery phrase. We do not charge fees to release transfers. Every swap has an Exchange ID , and that is what real support works from. Anyone asking whether SimpleSwap is safe can test any message against those four rules rather than taking our word for it.
Question six also has a tool on our side. Address Check, in the Customer Account, screens a wallet address through third-party services and returns a risk level with the connections it found. Run it on a destination before you send, and it tells you something the string itself cannot: whether the address has a history worth knowing about. It does not confirm you pasted the right one and will not flag every problem, so it adds a step rather than replacing one.
Our only official domain is simpleswap.io. Type it once, bookmark it, and question two answers itself from then on.
What comes next
Every question above traces back to a scam with its own mechanics, and each one gets a full breakdown in “Know the Scam by SimpleSwap“. The whole series is in our Safety Academy, so the way to stay ahead of a pattern is to read it before it reaches you, not after.