Decentralized apps, or dApps, let you lend, trade, and interact with crypto directly from your wallet, with no middleman. But there's often no undo button once you approve a transaction or sign a message. Knowing the risks before you connect is the best protection you have.
What is a dApp?
A decentralized application (dApp) is an app that runs on a blockchain network like Ethereum or BNB Chain instead of a centralized server. On your Binance.US Wallet, you can connect to dApps via QR code or browse dApps directly in the app.
Common dApp scams
The openness of blockchain means anyone can deploy a smart contract or create a dApp. Scammers exploit this by building fake dApps that closely mimic legitimate ones, tricking users into signing risky messages or approving harmful transactions.
Social engineering
Social engineering is one of the most common ways scammers trick users into connecting their wallets to malicious dApps. Instead of relying on technical exploits, these scams manipulate emotions like fear, curiosity, and urgency.
Here's how it typically unfolds:
Impersonation. Scammers pose as official representatives of trusted platforms. They mimic logos, use convincing usernames, and clone community groups on Telegram, Discord, or X.
Building trust. They engage users in friendly conversation or offer unsolicited help, slowly gaining rapport.
FOMO pitches. Once trust is established, they create urgency around a "limited-time opportunity" like an exclusive presale, airdrop, or high-reward dApp. You're pressured to act fast.
The trap. These dApps are rigged to drain your wallet the moment you sign an approval, or grant the scammer ongoing access to your funds.
Approval phishing
In DeFi, approvals are a normal part of interacting with smart contracts. They let a dApp move your tokens on your behalf. In approval phishing, malicious dApps abuse this by prompting you to approve unlimited token spending.
Once granted, scammers can drain your wallet over time using smart contract functions. Since approvals stay active until you manually revoke them, the scammer can keep accessing your wallet long after the initial interaction.
Signature phishing
Signature phishing tricks you into signing unreadable or arbitrary data off-chain. Unlike a standard transaction, there's no gas fee, no blockchain record, and no immediate red flag. Once a valid signature is created, scammers can submit it to a smart contract later to gain access to your tokens without you realizing it.
A common version of this scam abuses Permit and Permit2, which are legitimate off-chain approval methods:
Permit lets users approve token spending via signature instead of an on-chain transaction.
Permit2 extends this by allowing a single signature to approve multiple tokens, with customizable limits and expiration settings.
Scammers disguise malicious Permit or Permit2 requests as harmless prompts. If you sign one, they can withdraw your funds long after the interaction. Since no transaction is broadcast when you sign, the breach often goes unnoticed until the tokens are gone.
If a signature request is unreadable or doesn't make sense, don't sign it.
Blockchain rectification scams
These scam sites claim to fix common wallet issues like slippage errors or failed transactions. They're actually designed to steal your seed phrase or private keys.
Here's how it works:
Targeting frustrated users. Scammers look for users dealing with wallet errors and offer fake "quick fixes."
Imitation. The sites copy the look of trusted services, using clean designs to lower your guard.
Simulated errors. Once on the site, you're shown fake urgent error messages and prompted to "connect manually," where you're tricked into entering your seed phrase or private key, giving the scammer full access to your wallet.
How to protect yourself
Take warnings seriously
Your Binance.US Wallet has built-in safeguards including transaction simulations and signature filters. It also blocks approvals to externally owned addresses (EOAs), high-risk requests, and known malicious dApps. Always read wallet warnings before confirming a transaction or signing a message.
Practice smart approvals
Carefully scrutinize any grant of unlimited token access. Always approve the minimum amount a dApp needs.
Revoke approvals you no longer need. Go to Assets, then Approvals to review and revoke them regularly.
Disconnect dApps you no longer use. Go to More, then Connected dApps to remove access.
Do your own research
Before interacting with any dApp, take time to evaluate it. Legitimate projects are typically audited by independent security firms, with reports available on their official website. Be cautious of anonymous teams, vague documentation, or low community activity.
Stick to official sources
Always access dApps from verified links on the project's official website. Scammers create fake sites by subtly misspelling domain names or swapping in lookalike characters, which can be hard to spot at a glance. Avoid clicking search ads, as phishing sites frequently pay to appear at the top of results. When in doubt, type the URL manually.
Never share your seed phrase or private key
If anyone asks for your seed phrase or private key, stop immediately. No legitimate dApp, service, or support agent will ever ask for it. The moment you share it, your wallet is compromised. Close the tab and walk away.
If you've been scammed
Disconnect your Binance.US Wallet from the dApp immediately and change your password.
If your bank account is involved, freeze your cards and change your passwords.
File a police report with your local authorities, providing as much detail as possible.
Report the scammer's profile to the platform where they first contacted you.
Contact Binance.US Support as soon as possible.
