SaveSaveSaveSave
← Back to the scanner

Guides · Updated 17 September 2026

How the tricks actually work

Not a list of warnings. An explanation of the mechanism, so you can recognise it yourself.

Every guide here covers one technique the scanner looks for. Each explains how the trick is built, why it is convincing, how to check for it using more than one method — and, in every case, what a clean result still cannot tell you.

No affiliate links. No token recommendations. Nothing here is financial advice.

Published

In preparation

Listed so you know what's coming, not to pad the page. Each one ships when it is actually written.

Wallet risk · next

"Verify your wallet": how seed-phrase phishing works

The single most expensive message in crypto, taken apart line by line — including why the real giveaway is the request itself, not the spelling.

Link risk

Links that hide where they go

The @ trick, punycode domains that display as a different name entirely, shorteners, and brand names placed where they hold no authority. How to read a URL from the right end.

Wallet risk

What you actually sign when you approve a token

An approval is not a payment. It is a standing permission, often unlimited and often permanent until you revoke it — and it is the loss most people never see coming.

Address risk

Sanctioned addresses: what a match does and does not mean

Why a sanctions hit is a match against a specific list at a specific moment, why the lists lag reality, and why exposure to a flagged address is not the same claim as guilt.


Suggestions for what to cover next are welcome through the project's issue tracker.