A wallet pop-up upgrade notification could be genuine, or it could be specifically designed to trick you into handing over your private keys or seed phrase. Before clicking any button, use the following 4 checks to spot the fakes.

A leading global cryptocurrency platform,suitable for both beginners and experienced traders.
New user benefit: 20% off trading fees upon registration!!
1. First Understand: A Real Update Will Never Ask for Your Seed Phrase in a Pop-Up
This is the most important rule. No wallet—whether MetaMask, Phantom, or hardware wallets like Ledger—will ever ask you to enter your recovery phrase (seed phrase) or private key via a pop-up, email, or text message.
SlowMist has publicly warned about a new phishing attack targeting MetaMask: scammers create a fake "2FA Security Verification" page that looks highly convincing, complete with security reminders and a countdown, eventually guiding you to "enter your seed phrase to complete verification." Once entered, the wallet assets are drained in seconds.
Phantom wallet has faced similar attacks. Scammers pop up a signature request for "Update Extension," and after approval, a window asks for the seed phrase. Scam Sniffer's security reports explicitly state this is designed to steal wallet control.
Remember: Your seed phrase is the sole control of your wallet; any pop-up asking you to enter it is fake.

A leading global cryptocurrency platform,suitable for both beginners and experienced traders.
New user benefit: 20% off trading fees upon registration!!
2. Do These 4 Checks to Avoid Fake Updates
Check 1: Observe Pop-Up Behavior
What to do: See if the pop-up can be dragged, resized, and whether you can right-click on blank space.
How to do it: Genuine wallet pop-ups (like Phantom) are system-level windows that can be resized and usually don't disable right-click. Fake pop-ups are locked within the browser tab and usually disable the right-click menu.
Done criteria: Confirm the pop-up behaves normally and isn't "locked" inside the page.
Check 2: Check Page Address and Source
What to do: If the pop-up prompts you to click a link or navigate to a page, first verify the URL.
How to do it:
If it's a browser extension pop-up: Real Phantom or MetaMask pop-ups will show
chrome-extension://in the address bar, something a phishing site can never fake.If it's an email or SMS notification: Check the sender address. Ledger phishing emails often pretend to be official, but if you look closely at the domain, it usually has a few extra strange letters or suffixes. A hardware wallet like Ledger will never actively urge you to update firmware via email. TokenPocket officially states: we do not send update reminders via SMS or email.
Done criteria: Confirm the pop-up source is an official domain or secure prefix.
Check 3: Assess Whether the Update Flow Makes Sense
What to do: After the pop-up appears, observe what it asks you to do.
How to do it: Genuine update flows are triggered from within the wallet app's settings or "About" page, or like Feather Wallet, provide an installation package verified by PGP signature. Cold wallet upgrades complete digital signature verification through the official app.
If the pop-up asks you to "click a link" to download: This is a high-risk signal. Even if it claims to be the official site, it's safer to manually visit the official website instead of clicking the link.
If the pop-up asks you to "scan a QR code": Equally dangerous, as the QR code may point to a malicious site.
Done criteria: Confirm the update flow is triggered within the app, not led by an external link.
Check 4: Look for Artificial Urgency
What to do: Pay attention to the wording in the pop-up or notification.
How to do it: Scammers love using phrases like "Your account will be locked," "Mandatory update," "Must complete within 24 hours" to create panic and prevent you from thinking. Genuine wallet updates rarely impose such "deadlines," let alone threaten to "freeze assets."
Done criteria: Confirm the notification does not use urgent language to pressure you into acting.
Prerequisite: You received a wallet upgrade pop-up, email, or SMS notification.
Common Failure Cause: Most victims simply "didn't look closely." blind signing and blind spots are the main reasons for asset theft. No matter how realistic a pop-up looks, it is fake if it asks for your seed phrase.
Risk Warning: Once you enter your seed phrase in a fake pop-up, attackers can drain all assets from your wallet in seconds, and the transactions are irreversible. If you encounter a suspicious pop-up in your browser, closing the tab immediately is the safest action.
After Completing the Checks, How to Confirm the Pop-Up Is Safe?
If the pop-up passes all checks—normal behavior, trusted source, logical flow, no urgency—you can manually trigger an update check in your wallet app's "Settings" or "About" to see if you get the same prompt. If the built-in updater shows a new version, you can download it safely. If any check fails, close the pop-up immediately and manually visit the wallet's official website to confirm whether an update exists.


