The most dangerous crypto link is often the one that arrives at the perfect moment. It looks official, answers the question you just asked, and gives you a reason to act before thinking. The defense is not technical genius. It is a repeatable pause.
1. Start from a source you already trust
Do not begin with a direct message, search ad, forwarded screenshot, or reply under a popular post. Type the known website address yourself or use a bookmark you created earlier. From there, follow the project’s published official links.
2. Read the entire domain
Attackers rely on familiar fragments: an extra letter, a swapped character, a misleading subdomain, or a different top-level domain. Read from the final slash backward. A padlock only means the connection is encrypted; it does not mean the site is honest.
3. Compare the complete mint address
Names and tickers can be copied. The mint address is the durable identifier. Compare the beginning, middle, and end—or better, compare the entire address through more than one official source. Never trust an ellipsis when the full value matters.
4. Treat urgency as a warning
“Last chance,” “wallet issue,” “claim now,” and “support is waiting” are pressure tools. A legitimate security process should give you enough time to verify. Stop when a message makes delay feel dangerous.
A real opportunity can survive sixty seconds of verification. A trap depends on you skipping them.
5. Inspect what the wallet is asking
A connection request, signature, token approval, and transaction are different actions. Read the wallet prompt. If it is unclear, reject it. Never share a seed phrase or private key. Real support does not need either one.
6. Separate help from access
Impersonators often move a public question into a private conversation. Verify moderator identities through published community roles, and remember that support can explain a process without taking control of your device or wallet.
7. Check the project’s current status
A polished trading page means nothing if the project has not announced market availability through its official website and verified channels. MADGER is not yet publicly launched for trading. Any page that contradicts that status should be treated as unaffiliated.
When something feels wrong
Close the page without signing. Revoke suspicious approvals through a trusted tool if you already granted them. Move remaining assets only when you understand the situation, and report the impersonator through the platform where you found it.
No checklist removes all risk. It does turn a rushed reaction into a deliberate decision—and that is a much harder environment for a scam to survive.

