Skip to main content

Avoid common ENS scams

Seven rules block almost every ENS scam. Spot fake upgrade messages, fake mints, phishing, fake airdrops, dust tokens, address poisoning, and fake verification.

Most ENS scams come down to three attacks: a malicious transaction you approve in your wallet, a recovery phrase you type into a fake login, or funds you send to the wrong address. Seven rules block almost all of them.

Good to know

  • Never share your recovery phrase or private key. No real wallet or support agent will ever ask, and no ENS app or website needs it.

  • ENS has no active airdrops. The only one ended May 2022.

  • Official ENS sites are under ens.domains.

  • ens.dev and ens.xyz are also official ENS domains, used for testnet and supporting tools.

  • Full list of official sites, apps and tools: Official ENS websites, apps, and tools


The seven rules that catch most scams

Rule

What it blocks

Read every wallet pop-up before you approve. The transaction details have to match what you're trying to do.

Fake mints · approval traps · "claim airdrop" pages

Never share your recovery phrase or private key. No real wallet, site, or support agent needs it.

Fake login screens · DM phishing · fake "wallet update" prompts

Check the URL before you connect. Official ENS sites sit under ens.domains, ens.dev and ens.xyz.

Lookalike domains · homoglyph names

Ignore unsolicited tokens and NFTs.

Dust tokens · scam NFTs that drain on swap

Send to ENS names, not hex addresses copied from your transaction history.

Address poisoning · lookalike-address swap

Real verification never means sending funds, and don't add .eth to your own address.

Fake-verification scams · live-call pressure

Be wary of any message asking you to upgrade, migrate or sync a name. Always check on app.ens.domains.

Fake upgrade, migration and "synchronisation for v2" messages

The sections below show what each scam looks like in practice.


Fake upgrade and migration messages

Messages telling you to upgrade, migrate or sync your ENS name before a deadline. They arrive by email, and as direct messages on X, Discord and Telegram. The link leads to a page that asks you to connect your wallet and approve a transaction.

There is nothing to prepare. Upgrading is not available on Ethereum Mainnet, so no deadline applies to your name.

The ENS App and ENS Explorer that support ENSv2 run on Sepolia testnet. Names registered there are test names: they hold no value, and there is nothing to claim or pay for.

Check anything you receive on app.ens.domains first, rather than acting on the message.

Important: ENS will not ask you to upgrade, migrate or sync a name. Check anything you receive on app.ens.domains.


Fake mints and approval traps

A page that looks like an NFT project. You connect your wallet, click "Mint", and approve a transaction. The transaction either transfers your NFTs straight to the attacker, or grants their contract a sweeping approval (often setApprovalForAll) that lets them move everything in your wallet later.

The fix is in the wallet pop-up. Before you approve, read what the transaction actually does. If it says "Set approval for all" on a contract you don't recognise, or transfers an NFT you weren't expecting to send, reject it.

Important: The action shown in your wallet has to match what you clicked on the site. If it doesn't, reject the transaction.


Fake login screens and seed-phrase phishing

A page that looks like MetaMask (or another wallet) asks for your recovery phrase to "unlock" or "verify". Real MetaMask only asks for your password.

The same pattern crops up as fake browser pop-ups, "wallet update" prompts, and DMs from people claiming to be ENS support. If anything asks for your 12- or 24-word phrase, it's a phish.

Important: Never share your recovery phrase or private key — not with ENS support, not in this chat, not by email, not with anyone. No real support agent will ever ask for it, and no ENS app or website needs it: it plays no part in registering, renewing, or fixing anything.


Fake airdrops

Pages telling you to claim "your $ENS" by connecting your wallet. They harvest approvals, they don't send tokens. ENS has no current airdrop and none planned. The only airdrop ended May 2022.

Important: ENS has no current or planned airdrops. Any site claiming otherwise is a scam.


Dust tokens and unsolicited NFTs

Random tokens or NFTs appearing in your wallet. The swap or sell contract is malicious — interacting with it drains your other tokens. Don't click, don't swap, don't try to sell.

Important: Don't interact with tokens or NFTs you didn't request.


Address poisoning

Scammers can plant fake addresses in your wallet's history. They send you a zero-value transaction from an address whose first and last few characters match one you've already used. Copy the fake address next time, and your funds go to the attacker.

Send to ENS names instead. A memorable, human-readable name like friend.eth points at one wallet, set by its owner. A lookalike address can't claim it.

Important: Send to ENS names, not addresses copy-pasted from your transaction history.


Fake verification scams

Anyone can register an ENS name that copies any 0x address with .eth on the end. The name can point to any address; whoever owns it picks. Scammers register a name copying your address, point it at their wallet, and, counting on you not knowing what ENS does, tell you to append .eth to your address to "verify" by sending funds. The funds go to them.

Don't add .eth to your own address.

Important: No real process asks you to send funds to "verify" anything.


If you've already approved something dodgy

Move fast.

Did this answer your question?