Phishing Protection
How Morsel detects phishing sites, how to spot fakes, and how to stay safe.
Phishing is the leading cause of crypto wallet losses. Morsel includes several layers of protection, but understanding how attacks work is the most important defence.
Morsel's Built-in Protections
- Domain blocklist — known phishing sites are blocked before they load in the in-app browser
- Connection popups always show the exact domain requesting access — you see the real URL before approving
- Transaction simulation — transactions are simulated before you sign them, so you can see what actually happens
How Phishing Works
Most crypto phishing follows the same pattern:
- You receive a link via Discord, Twitter, email, or an NFT airdrop
- The site looks exactly like a real dApp (same UI, logo, layout)
- But the domain is slightly different — e.g. jup1ter.ag instead of jup.ag
- You connect your wallet and approve a transaction
- The transaction drains your wallet
Verifying the Domain
The single most important habit: always check the domain in the Morsel approval popup before tapping Connect.
If the domain in the popup does not exactly match the official site, tap Reject immediately. Do not continue.
| Safe | Phishing (examples) |
|---|---|
| jup.ag | jup-ag.com, jup1.ag, jup.ag.io |
| raydium.io | raydium.app, raydium-io.com |
| magic.eden | magiceden.app, magic-eden.io |
Transaction Simulation
Before you confirm any transaction, Morsel simulates it and shows you what will actually happen — which tokens will leave your wallet, which will arrive, and any unusual programs being called.
If a transaction simulation shows tokens leaving your wallet that you did not expect, reject the transaction immediately. Do not trust the dApp's UI description over the simulation result.
Common Scam Patterns to Recognise
- Free NFT or token claims — "You won! Click to claim" — almost always wallet drainers
- Urgent warnings — "Your wallet is compromised, verify now" — Morsel will never send you such messages
- "Revoke approval" scams — fake sites that ask you to approve a transaction to revoke permissions
- Discord DMs offering support — always go to official support channels, never DMs
If You Think You Were Phished
- Immediately create a new wallet with a new seed phrase
- Move any remaining funds to the new wallet
- Do not reuse the compromised seed phrase anywhere
- Report the phishing site to Morsel support so it can be added to the blocklist
If your seed phrase was exposed, treat that wallet as permanently compromised. Create a new one immediately — there is no way to "secure" a wallet once the seed phrase is known.