Definition
Social engineering targets human decisions rather than relying only on a software vulnerability. An attacker may impersonate support staff, a colleague or an investment contact to create trust, urgency or fear. In crypto, the desired result may be a recovery phrase, an authentication approval or a transfer to an address controlled by the attacker.
How It Works
The interaction may unfold through messages, calls, social media or a seemingly helpful relationship. A request can sound routine, such as confirming an account or installing a support tool, while actually bypassing a security boundary. Phishing is one delivery pattern within the broader category. The presence of accurate personal information does not prove a caller is authorized; that information may come from public records or earlier breaches.
Key Considerations
Slow down unexpected requests involving credentials, software installation or money. Verify the person through a contact route obtained independently, not the one supplied in the suspicious message. A legitimate-sounding explanation does not justify sharing a wallet backup or approving an unexplained signature. Organizations can reduce exposure through clear approval procedures and separation of duties. If a suspicious interaction succeeds, protect affected accounts and preserve relevant records; do not assume changing one password resolves leaked wallet keys or already granted permissions.