Wallets and Security
Spotting Phishing Sites in Crypto
How to recognise crypto phishing sites, from lookalike domains and fake search ads to cloned interfaces, plus simple habits that keep you on the real site.

Phishing sites are copies of real crypto websites built to steal funds or credentials. Many are pixel-perfect clones. The logo, colours and layout match the real project exactly. The only difference is where your approvals, signatures or seed phrase end up. Knowing where to look makes clones far easier to catch.
The domain is the first check
The address bar is the most reliable signal. Phishing domains use tricks such as:
- Extra words: projectname-app.com instead of projectname.com
- Different endings: projectname.io when the real site is projectname.xyz
- Swapped letters: rn in place of m, or a zero in place of the letter o
- Lookalike characters from other alphabets that appear identical
- Subdomains that hide the real domain, such as projectname.com.claim-rewards.net
Read the domain from right to left. The part just before the ending, such as .com, is the real site owner.
Search ads and sponsored results
Attackers buy search ads for popular crypto apps. The ad appears above the real result and links to a clone. Many users click the first result without noticing the "sponsored" label.
Avoid searching for apps you use regularly. Save bookmarks for important sites and use them every time.
Links from social media and messages
Phishing links spread through:
- Replies under popular posts from lookalike accounts
- DMs offering support, airdrops or job opportunities
- Compromised project accounts announcing fake claims
- Discord and Telegram messages from hacked moderator accounts
- Emails pretending to come from exchanges or wallet providers
Treat any link that arrives with urgency as suspicious, even if it seems to come from an account you trust. Cross-check announcements on the project's website before acting.

Signs inside the site
Once a site loads, other warning signs appear:
| Sign | What it may mean |
|---|---|
| Immediate wallet connection prompt | Site wants approvals before you look around |
| Request for seed phrase | Always a scam, no legitimate site asks |
| Claim requires approving tokens | Drainer pattern |
| Countdown timers and pressure | Designed to stop you checking |
| Broken links on secondary pages | Clone only copied the main page |
| Slight visual differences | Rushed copy of the real interface |
A legitimate app never needs your seed phrase. That single rule stops a large share of phishing losses.
Tools that help
Several protections add useful layers:
- Browser extensions and wallets that warn about known phishing domains
- Transaction simulation that shows what a signature will do
- Password managers that only autofill on the exact saved domain, which also flags lookalikes
- Bookmark folders for important crypto sites
None of these catches everything. They support careful habits and do not replace them.
If you visited a phishing site
If you only visited and did not connect or sign anything, close the tab and clear the site data. If you connected, disconnect the site in your wallet. If you signed an approval or transaction, revoke approvals and move funds to a new wallet quickly. If you entered a seed phrase, assume the wallet is fully compromised and move everything immediately from a clean device.
Report the domain to your wallet provider, to the project being impersonated and to browser safe browsing services.
Help your community stay on the real site
Projects can reduce phishing by publishing one official links page, keeping the domain consistent everywhere, and listing verified links on independent public profiles. When a member can compare the link in a DM against the website, the docs and a Proud Globe pin, a lookalike domain stands out fast.
Educational content only. Nothing here is financial, legal or tax advice. Crypto assets carry risk, so check the details for your own situation.