What are phishing and scams in crypto?

In plain words
Many of a beginner’s losses are not a blockchain hack but deception. You are convinced to hand over access yourself or to send money. The blockchain protocol itself is very hard to hack, and the weaker points are the apps and services around it and the person.
Two words are worth distinguishing. Phishing is luring out passwords and seed phrases, or the actions a fraudster needs, through a fake, for example a look-alike site, fake support, or a bait email. A scam is the whole fraudulent scheme, deception for the sake of your money.
The main thing to accept right away: a common vulnerability is not a weak password, but haste and trust. A couple of minutes of checking saves the whole wallet. That is exactly what the front page warns about too, since people go wrong most often at the fast, trusting step.
Deeper
Typical traps worth knowing by sight
A look-alike site is a copy of an exchange or wallet. The picture is the same, but the address is different. You enter your data and thereby hand it to a fraudster. Check the site’s address by hand and do not follow links from ads and emails.
Fake support asks for a seed phrase or private key. This is always fraud, since real support never asks for them, which the articles what is a seed phrase and what is a private key cover.
Giveaways and doubling: you are promised that if you send coins, you will get twice as much back, but there is no free money, and the goal of such a scheme is to lure you to a trap site or coax a transfer out of you.
A dangerous confirmation, which is called approve, is a signature that gives a smart contract access to your coins. A malicious contract uses this access to withdraw funds. So understand exactly what you are allowing with such a signature.
Returns too good to be true, and a mentor: you are promised guaranteed earnings or invited to an investment guru, sometimes through a long trusting or romantic acquaintance that leads to an invest here.
What to remember about phishing and scams
All these schemes share one handwriting: urgency, pressure, and the feeling that it is too good to be true. The moment you feel this set, it is a stop signal, not a reason to hurry.
A few simple rules cover most cases. Do not rush, since fraudsters deliberately hurry you. Check the site’s address by hand and do not click links from ads and private messages. Never give anyone your seed phrase or private key, and if you are unsure what you are allowing, better not to confirm.
Specific schemes change over time, but this handwriting and these rules do not.