On-chain Safety Education

Understand the chain.
Protect your wallet.

Onchain Diary is an independent Web3 safety education site: 110 deep-dive articles, a 232-term glossary, and the complete BIP-39 wordlist — covering crypto scams, smart contract security, and on-chain analysis. No jargon. No sign-up. No tools to install. Just the knowledge you need to stop getting rekt.

110 Articles
232 Glossary Terms
0 Sign-ups Required
§ 01

Latest

Guides, tutorials, and deep dives.

Fake Crypto Support Scams Explained: Why Support That Contacts You First Is Always Fake

The FBI-documented scam where 'exchange employees' call you about an account problem. How the fake-admin funnel works, the three ways it ends — phishing, a malicious signature, or remote access — and the one rule that filters all of it.

MetaMask Infrastructure Incident Explained: Why Your Wallet Was Never at Risk

MetaMask disclosed a security incident on September 30 that hit part of its Ethereum validator infrastructure. Around 17,000 validators holding roughly 523,000 ETH began exiting, and one researcher traced about 0.36 ETH in skimmed rewards. Yet wallets and funds were never exposed — because of how Ethereum splits validator keys from withdrawal keys. Here is the timeline, the architecture, and what actually deserves your attention.

Blast L2 Is Shutting Down: How to Withdraw Safely Before October 26

Blast announced on October 2, 2026 that it is winding down its Ethereum L2. Users have until October 26 to withdraw through the normal interface. Full timeline, the L1 bridge-contract path after the deadline, and the scam wave every shutdown attracts.

NEAR Intents Hack Explained: How a Signed-Note Bug Drained $3.87M

NEAR Intents lost $3.87 million on October 1, 2026 when a bug in its Omni deposit-and-withdrawal system let an attacker withdraw funds with valid signed notes. Full timeline, where the money went, and why no user signature could have prevented it.

ClickFix Scam Explained: How a Fake CAPTCHA Drains Crypto Wallets

ClickFix shows you a fake CAPTCHA, then talks you into pasting one command into Run or Terminal. Here is the full chain, the on-chain dead drop, and what it does to wallets.

GIWA Fake RPC Scam: Full Forensics of a 771-ETH Fake Bridge Built From Verified Code

1331 depositors, 771 ETH, 14 hours. How a proxy pointing at verified OptimismPortal2 source, a fake RPC, and a coordinated distribution push drained users bridging to a mainnet that doesn't exist.

Don't transact blind.

Whether you're new to crypto or deep into DeFi, understanding how scams work is the best defense. Every guide here is free.

Start Reading →