What is phishing? How can we educate our customers on phishing?
- Cathryn Cui
Ok i’ll start by explaining what’s phishing, then i’ll just need to clarify some things about customers and our abilities, before moving onto the second part of the question.
phishing is a specific malicious activity aimed to hack users private data/funds.
lately it comes in many different forms, but it has a very simple base logic, behind all of them.
- creating a malicious interface (person,chat, website, wallet, platform. etc) disguised as an official one
- tricking user into thinking he is interacting with original interface
- aquiring private data/funds from a convinced user
- securing stolen data/funds from access of the original owner
let’s take a phishing website as an example:
usually it completely copies the original websites login page, but there might be a slight difference in the domain name e.g. gooogle.com instead of google.com
user goes in thinking it’s the original website, enters his credentials, and once he logs in, automated software/or some bad actor tries to use those credentials, to compromise user account ( block out the user out of his account, via login -> change email/change password). if the successful user no longer has access to his account.
Now onto educating customers.
Q:I’m i right to think we want to increase retention ( customer satisfaction ), by securing customer funds via educating?
A: Yes
Q: By our customers you mean users of the coinbase exchange, twitter and discord, or do we want to educate about phishing in general?
A: let’s concentrate on the exchange for now, but proving additional info should not be an obstacle
Q: I assume we are talking about registered and verified users on the platform?
A: As well as new users…
Q: Do we have any other restrictions?
A:No, we can even dedicate a team and funding to this task.
Q: first lets identify where custemers generally get scamed by phishing?
- exchange login
- funds withdrawal
- wallet connection interface/ wallet signatures
- support team interactions
any particular type you want to concetrate on?
A: let’s address all of them
Ok, here are principles we should follow while designing solution details
- they shouldn’t discourage the customers from using the platform
- they should be easy to understand
- educational guidelines be simple to use
solutions:
- 1. we could implement educational tests as part of the onboarding process(for new users) or at dangerous points usage (withdraw funds to a suspicious address)
- 2. we could create some educational lectures and give out bonuses to those users who go through them (like fee reduction)
- 3. we can partner with learn&earn crypto projects, and outsource educating to them
- 4. we can use banners indicating to check the domain and wallet addresses
2 and 3 seem to be the most efficient options. they provide additional value via benefits, that makes the educational process more valuable to the user overall, and may bring more satisfaction compared to forced tests, or banners.

Coinbase