Phishing prevention

How to Spot a Fake Crypto Exchange Website

A fake exchange page may copy a real logo, layout, login form, app download page, or support message. Visual polish and HTTPS do not prove who operates a site, so verify the route, domain, payment request, and support behavior before entering credentials or sending money.

Reviewed and last updated: June 17, 2026

Security decision matrix

Identify the threat before changing settings

Fast action helps only when it matches the incident. Start with the account, email, device, and withdrawal path.

SignalLikely riskFirst safe action
Unexpected login alertPossible credential exposureSecure email first, then review sessions from a clean device.
2FA device lostAccess recovery riskUse official recovery. Do not pay anyone or share backup codes.
Fake support contactPhishing or recovery scamStop replying. Open the provider through a bookmark or typed domain.
Unknown API keyAutomated account access riskRevoke it, rotate credentials, and review trades and withdrawals.
Withdrawal address changedFunds may be at immediate riskFreeze withdrawals if available and contact official support.
Account lockedSecurity, KYC, region, or policy reviewRead the exact status and use the matching official appeal route.

Fake exchange check desk

Verify the site before you prove who you are

The useful question is not whether the page looks professional. It is whether the route, domain, request, and support behavior match a real provider.

Domain

Read the registered domain, not the logo

A copied logo, HTTPS padlock, app-style layout, or support badge does not prove ownership. Check the exact registered domain and every character before login.

Open the exchange from a trusted bookmark or typed address, then compare.
Route

Treat messages and ads as untrusted entry points

Emails, texts, sponsored results, QR codes, group chats, and direct messages can all send you to a fake login or fake support flow.

Do not use the link that created the urgency.
Demand

Stop at any unlock payment or safe-wallet story

Requests for tax, verification fees, deposits to unlock withdrawals, or a transfer to a safe wallet are major fraud signals.

Check the real account status through the official provider.
Secrets

No support flow needs wallet keys or live 2FA codes

A fake page may collect a password, then ask for a one-time code, recovery code, seed phrase, or remote-control access in real time.

Close the page and secure affected accounts from a clean device.

Immediate hard stop

These requests should end the session

  • Pay more crypto to unlock a withdrawal.
  • Move funds to a safe wallet supplied by support.
  • Install remote-control software for account verification.
  • Share a 2FA code, seed phrase, private key, or recovery code.

Verify how you reached the page

Unexpected emails, texts, social posts, direct messages, sponsored search results, app download prompts, and QR codes can direct users to impersonation pages. The FTC warns that phishing messages often invent suspicious logins, account holds, payment problems, refunds, or urgent verification requests to trigger a click.

Use a bookmark created from a previously verified domain or type the known address yourself. Check every character in the registered domain, not only the logo, page title, padlock, favicon, or first word of a long URL.

If the page arrived through a private chat, investment group, dating app contact, or recovery agent, treat the route itself as evidence. Real exchange support does not need a social-media tunnel to verify your account.

Check the domain and app path like evidence

Look for character swaps, extra words, hyphens, unusual top-level domains, copied landing pages, and links that hide the real destination behind shorteners or redirects. A fake site can still have a valid HTTPS certificate for its own domain.

For mobile apps, do not install an APK or profile from a chat link, email, or pop-up. Use the provider's official app-store listing reached from the verified website or the store's own search, then compare publisher name, reviews, and linked domain.

If you cannot confidently explain who owns the domain or app publisher, do not enter a password, identity document, payment card, or wallet information there.

Treat urgent account stories as a warning

Stop when a page or caller says funds must immediately move to a safe wallet, a tax or fee must be prepaid in crypto, a withdrawal needs another deposit, or support needs remote device access. These demands do not become legitimate because the person knows your email, phone number, balance claim, or transaction details.

Independently open the official account and check notifications there. Contact support only through the provider's verified app or website, not through a number, chat handle, or link supplied in the suspicious message.

A real support path should not need you to install remote-control software, read a one-time code, scan a new authenticator setup QR code, or move assets to a wallet supplied by the caller.

Never hand over authentication secrets

A fake login may collect a password and then request a one-time code in real time. A caller may ask you to read a code, approve a login prompt, scan a setup QR code, install remote-control software, or share a screen.

Do not provide passwords, authenticator codes, recovery codes, seed phrases, private keys, card security codes, or full identity numbers through a suspicious page. A wallet seed phrase is not an exchange support credential. Anyone who obtains it may control the wallet.

If you typed a password but stopped before the 2FA code, still treat the password as exposed. Secure the linked email and real exchange account from a clean device.

Respond after a suspicious interaction

If you only received the message, report and delete it. If you entered information, use a clean device and the verified services to change affected passwords, secure email, revoke sessions and API keys, review withdrawal settings, and contact official support.

If malware may have been installed, disconnect the affected device as appropriate, update security software, run a scan, and avoid using it for account recovery until it is trusted. Preserve URLs, messages, timestamps, transaction IDs, wallet addresses, app names, and case numbers for reports.

If crypto has already been sent, do not send a second payment to unlock, trace, or recover the first one. Preserve the TXID and use official reporting channels instead.

  • Do not send another payment
  • Secure email before resetting the exchange account
  • Revoke unknown sessions and API keys
  • Freeze activity if the official provider offers that control
  • Report impersonation to the provider and relevant authority
  • Ignore unsolicited recovery offers

Common questions

Frequently asked questions

Does HTTPS mean a crypto exchange website is genuine?

No. HTTPS protects the connection to a domain but does not prove the domain belongs to the exchange. Verify the complete registered domain and how you obtained it.

Will exchange support ask for my 2FA code or seed phrase?

Do not disclose either. A one-time code can authorize account access, and a seed phrase can control a wallet. Use only the provider's official support flow.

What should I do after logging into a fake exchange page?

From a clean device, secure email and the real exchange account, change exposed passwords, revoke sessions and API keys, inspect withdrawal settings and activity, and contact official support.

Is a crypto recovery website safe if it shows testimonials?

Do not rely on testimonials, logos, or screenshots. Guaranteed recovery, upfront fees, safe-wallet transfers, and private-message support are serious warning signs.

Primary references

Official sources checked

These official pages were reviewed on June 15, 2026. Exchange policies can change, so open the source before acting.

  1. FTCHow To Recognize and Avoid Phishing Scams
  2. FTCWhat To Know About Cryptocurrency and Scams
  3. NISTDigital Identity Guidelines: Authentication and Authenticator Management