How to Recognize a Phishing Message: Signs and Safe Checks
Phishing works because it looks routine and makes you hurry. Here is what to look for and what to do instead of tapping.
Published September 30, 2026 · 2 min read
Phishing works because it looks routine and makes you hurry. Here is what to look for and what to do instead of tapping.
Published September 30, 2026 · 2 min read
Phishing messages try to make you act before you think. They usually combine a few elements, and the more of them you see together, the higher the risk.
The page behind the link is fake, and whatever you type into it goes to the sender.
A genuine service never needs your password or one-time code from you. You enter them yourself, on its own login screen, to prove who you are. If a message asks you to send or read them out, the sender is trying to get in as you. Treat this request alone as enough reason to stop, even if the rest of the message looks convincing.
Before tapping, hover over the link, or press and hold it on a phone, to see its real destination. An address that only looks official can differ from the real one by a character or an extra word. If the destination is not exactly what you expect, do not open it. The table below pairs each warning sign with a sensible response.
| Sign | What it looks like | What to do |
|---|---|---|
| Urgency | A deadline or a threat that pushes you to act right now | Pause; urgency is a pressure tactic, not proof of a real problem |
| Link to log in | A button or address leading to a page asking you to sign in or confirm | Check the real destination, or skip the link and use the official entry point |
| Request for password or code | A message asking you to reply with or enter a secret | Never share it; a genuine service does not need it from you |
| Look-alike address | A web address that seems official at a glance | Inspect the full address carefully before tapping, and do not open it if unsure |
Do not use the link in the message. Reach the service through its known official entry point: a saved bookmark, the app you installed earlier, or the chat you opened yourself. For Nexus Pay, that means the wallet you opened in Telegram through the bot @nexuspaymybot, not a link that arrived in a message. If the message was genuine, the same notice or task will be waiting there.
Blockchain transfers are irreversible: nobody can bring back a transfer sent to the wrong address. If a fake page persuades you to send funds or reveal access details, there is usually no way to undo the result. That makes the checking habit more important than any after-the-fact fix. Nexus Pay offers an optional four-digit access code and lets you freeze the card in one tap, but these are extra layers, not a substitute for spotting the trap.
Stop and do not enter anything more on that page. Then go to the real service through its official entry point rather than through the message, and change any password you typed into the fake page. If you use a card, freezing it while you sort things out limits further use. Anything sent by blockchain transfer cannot be reversed, so act quickly on the parts you can still control.
Opening…