Every remaining defence on this site can be undone here, because phishing does not break your security. It persuades you to use it on the attacker's behalf.
Why it works so much better than it used to
Three things changed, and none of them are about you being careless.
They have your details. Exchange and hardware wallet customer data has leaked repeatedly. A caller who opens with your full name, the device you bought and when you bought it has already cleared the suspicion barrier that generic scams fail at.
The tells are gone. Broken English, odd formatting and generic greetings were how people spotted phishing. Generated text has no grammar mistakes and can be tailored to your circumstances at scale.
Voices can be cloned. A short sample of someone's speech is enough to produce a convincing imitation, which is why an urgent call that sounds like a person you know is no longer proof of anything.
The approaches to recognise
Impersonation of support
The dominant pattern. Someone contacts you claiming to be from your exchange, your wallet manufacturer, or occasionally the police, warning of suspicious activity and offering to secure your funds. They are calm, competent and helpful. The request is always some version of moving your money somewhere safe, or proving ownership by entering your recovery phrase.
Real support teams do not initiate contact. They do not direct message you after you post a question in public. They never need your recovery phrase, ever, for any reason.
Letters through your door
Newer, and effective precisely because post feels expensive and official. Printed letters imitating hardware wallet manufacturers, complete with branding and a QR code, instructing recipients to complete a mandatory security update. The code leads to a convincing replica site whose final step asks for the recovery phrase. Funds are gone within minutes.
These campaigns follow customer data leaks, because a postal address is exactly what a leak of order data provides.
Address poisoning
Quiet and clever. An attacker generates an address whose first and last characters match one you use regularly, then sends a tiny transaction from it so that it appears in your history. Later you copy an address from that history, check the beginning and end as everyone does, and send funds to the attacker.
The defence is mechanical: verify the entire address on your hardware wallet screen, not just the ends, and never copy an address out of your transaction history.
Fake tools and updates
Applications, browser extensions and update prompts that present themselves as wallet utilities, synchronisation tools or verification steps. Some ask outright for your phrase. Others obtain permissions that let them move funds later.
Install wallet software only from the manufacturer's own site, typed in yourself, and update only from inside the official application.
Urgency is the tell
Technical indicators change constantly. The emotional signature does not. Every one of these attacks needs you to act now, before you check, before you tell anyone, because something bad is about to happen.
Genuine organisations are content to wait while you call them back. Treat manufactured urgency as the alarm itself, and give yourself a standing rule: anything involving your Bitcoin waits until tomorrow, or at minimum until you have spoken to someone you trust.
The habit that keeps you off the list
All of this presupposes the attacker knows you are worth contacting. Some of that comes from breaches you cannot control. A surprising amount comes from what holders say themselves, in group chats, at meetups, on social media, at work.
The best answer to the question of whether you own any Bitcoin remains the one that ends the conversation without a lie you have to maintain:
No, but I wish I had bought some.
It costs nothing, it is socially unremarkable, and it removes you from the only list that matters.
Sources