

Social Engineering: How Users Get Exploited
βπ Social Engineering in Web3: How Attackers Exploit You, Not Your Code
βMost Web3 attacks don't break smart contracts. They break people.
βThis session is a hands-on deep dive into the human side of crypto security, the manipulation tactics that bypass technical defenses entirely. Whether you're a developer, trader, NFT collector, or just getting started in Web3, this talk is built for you.
βWhat we'll cover:
βWe'll open with a simple but uncomfortable truth: the majority of on-chain losses don't come from code exploits. They come from users approving malicious actions, wallets drained after signing a "harmless" message, assets lost to a fake mint, funds gone after a support DM.
βThen we break down the mechanics. Using a structured framework of attack mechanisms - from urgency and authority to information asymmetry and delayed consequences β we'll map exactly how these attacks work on a psychological level.
βThe core of the session is four interactive showcases, each based on real incidents:
βπ¨ Fake NFT mint: urgency, familiarity, and the BAYC Discord compromise
ββοΈ Signature request scams: habit loops, control illusion, and Angel/Monkey Drainer
ββ³ Approval with delayed drain: default bias and the 2022 OpenSea phishing wave
βπ¬ Fake support messages: authority, identity spoofing, and Ledger phishing campaigns
βFor each scenario, you'll have a chance to identify the mechanisms at play before we reveal them - then we'll discuss real mitigation strategies you can apply immediately.
βYou'll leave with:
ββ
A mental model for recognizing manipulation before you sign
β
An understanding of how attacks chain multiple mechanisms together
β
Practical tools and habits to protect yourself on-chain
βWho this is for: Anyone active in Web3 - no prior security background needed. The goal is pattern recognition, not technical expertise.
βSpeaker & Host
ββSpeaker: Masha Vaverova - Smart Contract Security Researcher, FullStack Blockchain Developer
ββHost: GetBlock - Web3 node infrastructure for building dApps across 130+ blockchains.