Bridge Safety: Keep Your Funds Yours

Nobody "hacks" a bridge user anymore — they get invited to a fake one. The threats are social, and so are the defenses.

Rule zero: bookmarks, not ads

The dominant loss vector in crypto isn't broken contracts — it's spoofed interfaces served through search ads, sponsored posts and DM links. They pixel-match the real site, connect to your wallet, and ask for one "approval" that drains every approved token. The defense is boring and absolute: save the official URL of every service you use in bookmarks, and type nothing into a search bar when money is involved.

  • Jumper's official domain is jumper.exchange. LI.FI's infrastructure lives at li.fi. Check the certificate, check the spelling, check the domain ends there — lookalikes append the real name to a fake suffix.
  • A wallet connection can never move funds. An approval can. The dangerous click always looks like a routine permission, never like a transfer.

Approval hygiene

Token approvals are standing permissions. Every one you've ever granted is a door you've left unlocked until revoked.

  1. Limit by default. When a site offers "approve exact amount" vs "unlimited," choose exact. It costs one extra approval later and caps your exposure.
  2. Audit quarterly. Free tools let you see every live approval on your address. Revoke anything you don't recognize or no longer use.
  3. After interacting with any new service, revoke immediately if you don't plan to return soon.

The scam catalog

ScamThe HookThe Tell
Fake support"Customer service" DMs you first after a public help requestReal support never DMs first, never asks for seed phrase or a screen share
Airdrop baitA surprise token appears in your wallet with a claim linkInteracting with the token or its site is the drain — ignore and hide it
Lookalike domainsSponsored search results one letter off the real domainBookmarks make this vector impossible
"Verification" requestsA site asks you to "verify ownership" by signing a messageA signature can authorize a transfer — read what you sign, blindly signing is how multisigs get robbed

The pre-flight checklist

  1. URL matches your bookmark, certificate valid, no lookalike characters in the domain.
  2. Quote numbers are within the range the calculator showed — wild deviations mean wrong site or manipulated data.
  3. Approval is exact-amount, not unlimited.
  4. Minimum received is displayed and sane (see slippage guide).
  5. Test with a small amount first on any new service or corridor.

If something goes wrong

  • Suspicious approval granted? Revoke it immediately — revocation is itself an on-chain transaction and beats waiting.
  • Seed phrase compromised? The wallet is gone. Create a new wallet and move everything to it now — seconds count.
  • Funds stolen? Report to the FBI's IC3 (ic3.gov) and the FTC. Recovery odds are poor, but reports build the cases that eventually take these operations down.

Last reviewed: September 2026.