Beware of SMS messages claiming to protect your Pi Coin account—phishing sites are stealing wallets
One day, out of the blue, I received a text message claiming to protect my cryptocurrency account. However, this message concealed a sinister intent: to steal the user’s wallet information. Recently, a smishing campaign was identified that impersonated Pi Coin account protection to lure users to phishing pages and steal their cryptocurrency wallet information. The threat actors present a screen designed to look like the actual Pi Network service and trick users into directly entering the confidential information needed to recover their wallets. Since this tactic has been consistently observed in various regions—including the US, Europe, India, and Vietnam—users in Korea cannot afford to let their guard down. Let’s take a closer look at the Pi Coin smishing scheme hidden behind the phrase “account protection.”
The threat actors exploit users’ anxiety by suggesting there is a problem with their account or that additional verification is required, thereby prompting them to click on the link included in the message.The smishing message identified in this incident resembled patterns previously used to compromise Telegram or Microsoft accounts. It is designed to look like a security note or account protection note from a legitimate Service, tricking users into visiting the phishing page without raising suspicion.

[Figure 1] Pi Coin Smishing Example
When a user clicks the link, they are redirected to a phishing page that is disguised as the official Pi Network Service website. Both the website address and the page layout are designed to closely resemble the legitimate service, and users are prompted to enter their 24-word wallet recovery seed phrase. Since the seed phrase is critical information that grants access to the wallet, if it is exposed, a threat actor can take control of the wallet.

[Figure 2] Actual screenshot of the phishing page
This smishing campaign is not limited to specific regions. It is configured to support multiple languages, which can be seen as an attempt to broaden the scope of the attack to target users in various regions. In fact, since 2025, there have been ongoing reports of users being lured to phishing sites through advertisements in various regions, including the US, Europe, China, India, and Vietnam.

[Figure 3] Phishing page supporting multiple languages
If you receive a message regarding Pi Coin account protection or wallet verification, it is safer to check directly through the official Pi app or website rather than immediately clicking on links included in text messages or ads.
In particular, the seed phrase used for wallet recovery is critical information that grants access to your cryptocurrency wallet, so you should never enter it on a generic webpage or through an external link. If a page asks you to enter your recovery words, you should immediately stop using that page, as it is likely a phishing attempt.