Crypto is fast and final. A signed transaction cannot be reversed, there is no chargeback, and no support line can claw your money back. That is why the most expensive mistakes happen in the last second before you tap confirm. This guide walks through the scams that actually drain wallets, how to recognise them, and how the B28 Sentinel screens what you are about to sign.
How the Sentinel protects you
The Sentinel is B28's scam-shield, and it is live today. Before you sign, it screens the recipient address and the token against known scams, drainer approvals, look-alike address poisoning, and honeypot tokens, then warns you in plain language. It speaks before you tap confirm, while you can still stop. It does not move money, it does not hold your keys, and it never signs for you. Think of it as a second pair of eyes on the one screen where mistakes are permanent.
No screen catches everything, so the habits below matter just as much as the shield. Read them once and they will save you later.
Address poisoning and look-alike addresses
Crypto addresses are long strings, and most people only check the first and last few characters. Attackers exploit this by sending you a tiny or zero-value transaction from an address that starts and ends the same way as someone you really transact with. Later, when you copy an address from your history, you grab theirs by mistake and send your funds to the attacker.
- Spot it: an unexpected dust transaction from an address that looks familiar but you never used.
- Beat it: never copy an address from your transaction history. Paste from the person directly, and verify the middle characters, not just the ends.
- B28 does this for you: the Sentinel flags when a recipient address closely resembles one you have used before, so a poisoned look-alike does not slip through.
Honeypot tokens (buy but never sell)
A honeypot is a token engineered so you can buy it but the contract blocks you from ever selling. The price chart looks like it only goes up, because no one can get out. By the time you try to take profit, your funds are trapped.
- Spot it: a token that is heavily promoted, rising fast, and that almost no one is selling.
- Beat it: be sceptical of any token pushed at you with urgency, especially one you found through a message rather than searched for yourself.
- B28 does this for you: the Sentinel screens tokens for honeypot behaviour and warns you before you sign.
Drainer approvals
Many scams do not ask for a transfer at all. They ask you to sign an approval, which grants a smart contract permission to move a token on your behalf. A malicious site dresses this up as a free mint, an airdrop claim, or a wallet check. Once you sign, the drainer empties that token whenever it likes, even days later.
- Spot it: a connect-wallet site that immediately asks you to approve or sign something to claim a reward.
- Beat it: never approve a contract you did not seek out. Treat unexpected free money as bait.
- B28 does this for you: the Sentinel recognises drainer-style approvals and warns you before you grant a contract access to your tokens.
Seed-phrase phishing
Your recovery phrase is the master key to everything you hold. Anyone who has it can take all of your funds, instantly and forever. So scammers build fake wallet apps, fake support chats, and fake "validation" pages whose only goal is to get you to type those words.
- Spot it: anything that asks for your 12 or 24 word recovery phrase, ever, for any reason.
- Beat it: a recovery phrase is typed into your own wallet only when you restore it on a device you control. B28 will never ask you for it. No legitimate person, app, or support agent ever needs it.
This is the single most important rule in crypto. If you only remember one thing from this page, remember that your phrase is for your eyes only. Read more in Self-custody & your keys.
Fake support and impersonation
Scammers pose as wallet support, exchange staff, or even friends. They reach out first, often after you posted a question publicly, and they create urgency: your account is at risk, act now, share your screen, verify your wallet. Real support does not message you out of the blue and never asks for your phrase or remote control of your device.
- Beat it: we contact you only at hello@joinb28.app in reply to you. We will never DM you, never ask for your recovery phrase, and never ask to take over your phone.
Giveaway and double-your-money scams
"Send 1 coin and get 2 back" is always a scam, with no exceptions. These run through hacked or look-alike accounts of well-known names and rely on fear of missing out. Crypto sends are final, so anything you send to a giveaway is simply gone.
- Beat it: no real giveaway requires you to send funds first. If sending money is a condition, it is theft.
Stay safe in three habits
- Slow down at the confirm screen. Read what the Sentinel tells you. The whole scam depends on you rushing.
- Verify the destination yourself. Check the full address, especially the middle, and paste from the source, never from history.
- Guard your phrase like the key it is. It never leaves your control, and B28 never asks for it.
Because B28 is non-custodial, you are always in control, which also means you are the last line of defence. The Sentinel is built to stand with you at that line. To understand why your keys live on your device and what that responsibility means, read Self-custody & your keys.