Skip to main content

Avoid common ENS scams

Nine rules block almost every ENS scam: fake renewals, fake upgrades, fake mints, phishing, airdrops, dust tokens, address poisoning, fake verification.

Most ENS scams come down to three attacks: a malicious transaction you approve in your wallet, a recovery phrase you type into a fake login, or funds you send to the wrong address. Nine rules block almost all of them.

Good to know

  • Never share your recovery phrase or private key. No real wallet or support agent will ever ask, and no ENS app or website needs it.

  • ENS has no active airdrops. The only one ended May 2022.

  • Official ENS sites are under ens.domains.

  • ens.dev and ens.xyz are also official ENS domains, used for testnet and supporting tools.

  • Full list of official sites, apps and tools: Official ENS websites, apps, and tools


The nine rules that catch most scams

Rule

What it blocks

Never renew from a link in a message.

Fake expiry warnings · forged renewal reminders

Never act on a message telling you to upgrade or migrate a name.

Fake upgrade, migration and "synchronisation for v2" messages

Never share your recovery phrase or private key.

Fake login screens · DM phishing · fake wallet updates

Read every wallet pop-up before you approve.

Fake mints · approval traps · claim-airdrop pages

Check the URL before you connect.

Lookalike domains · homoglyph names

Ignore tokens and NFTs you didn't ask for.

Dust tokens · NFTs that drain on swap

Send to ENS names, not addresses copied from your transaction history.

Address poisoning · lookalike-address swap

Never add .eth to your own address.

Fake-verification scams · live-call pressure

Ignore any "ENS Discord".

Fake community servers · impersonation


Fake upgrade and migration messages

Messages telling you to upgrade, migrate or sync your ENS name before a deadline. They arrive by email, and as direct messages on X, Discord and Telegram. The link leads to a page that asks you to connect your wallet and approve a transaction.

There is nothing to prepare. Upgrading is not available on Ethereum Mainnet, so no deadline applies to your name.

The ENS App and ENS Explorer that support ENSv2 run on Sepolia testnet. Names registered there are test names: they hold no value, and there is nothing to claim or pay for.

Important: ENS will not ask you to upgrade, migrate or sync a name. Check anything you receive on app.ens.domains.


Fake expiry and renewal messages

A warning that you are about to lose your name, with a link to renew it. It arrives by email, and as direct messages on X, Discord and Telegram. The link opens a page that asks you to connect your wallet and approve a transaction.

This one works because the deadline is real. Every name expires, and missing it does cost you the name, so the message carries a pressure a fake airdrop never does.

Check the date yourself instead. Search your name on app.ens.domains, read the expiry on the name's page, and extend from there. See Extend (renew) a .eth name for the steps.

If the date has already passed, the grace period gives you 90 days to renew, and nobody else can take the name during it. There is no reason to rush through a link.

Important: ENS does not send renewal demands with payment links. Check any expiry date yourself on app.ens.domains.


Fake mints and approval traps

A page that looks like an NFT project. You connect your wallet, click "Mint", and approve a transaction. The transaction either transfers your NFTs straight to the attacker, or grants their contract a sweeping approval (often setApprovalForAll) that lets them move everything in your wallet later.

The fix is in the wallet pop-up. Before you approve, read what the transaction actually does. If it says "Set approval for all" on a contract you don't recognise, or transfers an NFT you weren't expecting to send, reject it.

Important: The action shown in your wallet has to match what you clicked on the site. If it doesn't, reject the transaction.


Fake login screens and seed-phrase phishing

A page that looks like MetaMask (or another wallet) asks for your recovery phrase to "unlock" or "verify". Real MetaMask only asks for your password.

The same pattern crops up as fake browser pop-ups, "wallet update" prompts, and DMs from people claiming to be ENS support. If anything asks for your 12- or 24-word phrase, it's a phish.

Important: Never share your recovery phrase or private key — not with ENS support, not in this chat, not by email, not with anyone. No real support agent will ever ask for it, and no ENS app or website needs it: it plays no part in registering, renewing, or fixing anything.


Fake airdrops

Pages telling you to claim "your $ENS" by connecting your wallet. They harvest approvals, they don't send tokens.

Important: ENS has no current or planned airdrops. Any site claiming otherwise is a scam.


Dust tokens and unsolicited NFTs

Random tokens or NFTs appearing in your wallet. The swap or sell contract is malicious — interacting with it drains your other tokens. Don't click, don't swap, don't try to sell.

Important: Don't interact with tokens or NFTs you didn't request.


Address poisoning

Scammers can plant fake addresses in your wallet's history. They send you a zero-value transaction from an address whose first and last few characters match one you've already used. Copy the fake address next time, and your funds go to the attacker.

Send to ENS names instead. A memorable, human-readable name like friend.eth points at one wallet, set by its owner. A lookalike address can't claim it.

Important: Send to ENS names, not addresses copy-pasted from your transaction history.


Fake verification scams

Anyone can register an ENS name that copies any 0x address with .eth on the end. The name can point to any address; whoever owns it picks. Scammers register a name copying your address and point it at their wallet. Counting on you not knowing what ENS does, they tell you to append .eth to your address to "verify" by sending funds. The funds go to them.

Don't add .eth to your own address.

Important: No real process asks you to send funds to "verify" anything.


If you've already approved something dodgy

Move fast.

Did this answer your question?