Security decision matrix
Identify the threat before changing settings
Fast action helps only when it matches the incident. Start with the account, email, device, and withdrawal path.
| Signal | Likely risk | First safe action |
|---|---|---|
| Unexpected login alert | Possible credential exposure | Secure email first, then review sessions from a clean device. |
| 2FA device lost | Access recovery risk | Use official recovery. Do not pay anyone or share backup codes. |
| Fake support contact | Phishing or recovery scam | Stop replying. Open the provider through a bookmark or typed domain. |
| Unknown API key | Automated account access risk | Revoke it, rotate credentials, and review trades and withdrawals. |
| Withdrawal address changed | Funds may be at immediate risk | Freeze withdrawals if available and contact official support. |
| Account locked | Security, KYC, region, or policy review | Read the exact status and use the matching official appeal route. |
Fake exchange check desk
Verify the site before you prove who you are
The useful question is not whether the page looks professional. It is whether the route, domain, request, and support behavior match a real provider.
Read the registered domain, not the logo
A copied logo, HTTPS padlock, app-style layout, or support badge does not prove ownership. Check the exact registered domain and every character before login.
Open the exchange from a trusted bookmark or typed address, then compare.Treat messages and ads as untrusted entry points
Emails, texts, sponsored results, QR codes, group chats, and direct messages can all send you to a fake login or fake support flow.
Do not use the link that created the urgency.Stop at any unlock payment or safe-wallet story
Requests for tax, verification fees, deposits to unlock withdrawals, or a transfer to a safe wallet are major fraud signals.
Check the real account status through the official provider.No support flow needs wallet keys or live 2FA codes
A fake page may collect a password, then ask for a one-time code, recovery code, seed phrase, or remote-control access in real time.
Close the page and secure affected accounts from a clean device.Immediate hard stop
These requests should end the session
- Pay more crypto to unlock a withdrawal.
- Move funds to a safe wallet supplied by support.
- Install remote-control software for account verification.
- Share a 2FA code, seed phrase, private key, or recovery code.
Verify how you reached the page
Unexpected emails, texts, social posts, direct messages, sponsored search results, app download prompts, and QR codes can direct users to impersonation pages. The FTC warns that phishing messages often invent suspicious logins, account holds, payment problems, refunds, or urgent verification requests to trigger a click.
Use a bookmark created from a previously verified domain or type the known address yourself. Check every character in the registered domain, not only the logo, page title, padlock, favicon, or first word of a long URL.
If the page arrived through a private chat, investment group, dating app contact, or recovery agent, treat the route itself as evidence. Real exchange support does not need a social-media tunnel to verify your account.
Check the domain and app path like evidence
Look for character swaps, extra words, hyphens, unusual top-level domains, copied landing pages, and links that hide the real destination behind shorteners or redirects. A fake site can still have a valid HTTPS certificate for its own domain.
For mobile apps, do not install an APK or profile from a chat link, email, or pop-up. Use the provider's official app-store listing reached from the verified website or the store's own search, then compare publisher name, reviews, and linked domain.
If you cannot confidently explain who owns the domain or app publisher, do not enter a password, identity document, payment card, or wallet information there.
Treat urgent account stories as a warning
Stop when a page or caller says funds must immediately move to a safe wallet, a tax or fee must be prepaid in crypto, a withdrawal needs another deposit, or support needs remote device access. These demands do not become legitimate because the person knows your email, phone number, balance claim, or transaction details.
Independently open the official account and check notifications there. Contact support only through the provider's verified app or website, not through a number, chat handle, or link supplied in the suspicious message.
A real support path should not need you to install remote-control software, read a one-time code, scan a new authenticator setup QR code, or move assets to a wallet supplied by the caller.
Never hand over authentication secrets
A fake login may collect a password and then request a one-time code in real time. A caller may ask you to read a code, approve a login prompt, scan a setup QR code, install remote-control software, or share a screen.
Do not provide passwords, authenticator codes, recovery codes, seed phrases, private keys, card security codes, or full identity numbers through a suspicious page. A wallet seed phrase is not an exchange support credential. Anyone who obtains it may control the wallet.
If you typed a password but stopped before the 2FA code, still treat the password as exposed. Secure the linked email and real exchange account from a clean device.
Respond after a suspicious interaction
If you only received the message, report and delete it. If you entered information, use a clean device and the verified services to change affected passwords, secure email, revoke sessions and API keys, review withdrawal settings, and contact official support.
If malware may have been installed, disconnect the affected device as appropriate, update security software, run a scan, and avoid using it for account recovery until it is trusted. Preserve URLs, messages, timestamps, transaction IDs, wallet addresses, app names, and case numbers for reports.
If crypto has already been sent, do not send a second payment to unlock, trace, or recover the first one. Preserve the TXID and use official reporting channels instead.
- Do not send another payment
- Secure email before resetting the exchange account
- Revoke unknown sessions and API keys
- Freeze activity if the official provider offers that control
- Report impersonation to the provider and relevant authority
- Ignore unsolicited recovery offers
Common questions
Frequently asked questions
Does HTTPS mean a crypto exchange website is genuine?
No. HTTPS protects the connection to a domain but does not prove the domain belongs to the exchange. Verify the complete registered domain and how you obtained it.
Will exchange support ask for my 2FA code or seed phrase?
Do not disclose either. A one-time code can authorize account access, and a seed phrase can control a wallet. Use only the provider's official support flow.
What should I do after logging into a fake exchange page?
From a clean device, secure email and the real exchange account, change exposed passwords, revoke sessions and API keys, inspect withdrawal settings and activity, and contact official support.
Is a crypto recovery website safe if it shows testimonials?
Do not rely on testimonials, logos, or screenshots. Guaranteed recovery, upfront fees, safe-wallet transfers, and private-message support are serious warning signs.
Primary references
Official sources checked
These official pages were reviewed on June 15, 2026. Exchange policies can change, so open the source before acting.