Skip to content
Wallets & SecurityBeginner

How to recognize a crypto phishing site

You can recognize a crypto phishing page by checking the web address, the certificate, and the domain's registration date. A padlock is not proof.

Vahe HakobyanVahe HakobyanEditor-in-chief Updated Oct 5, 20263 min readFact-checked
A dark desk with a laptop, a security key and a padlock in red light.
Illustration: World-Crypt
On this page

Short answer

You can recognize a crypto phishing page by checking the web address, the certificate, and the domain's age before you connect a wallet or type a password.

Phishing pages copy the layout and logo of real exchanges, so a polished design tells you little. The clues sit in the web address, the certificate details, and the public record of the domain, and all of them are free to check.

What to check before you connect

Two checks take a minute and rule out most copycat pages. One is the security certificate that encrypts the connection between your browser and the server. The other is how long the domain has existed, which anyone can look up in a public record.

Quick checks before you connect

  • Open the certificate details and confirm the domain matches the official one exactly.
  • Check that the certificate is current and was not self-signed.
  • Look up the domain's registration date in a public WHOIS record.
  • Treat a domain registered in the past few months as a warning sign.

Steps to spot a phishing page

Run these checks before you type a password, connect a wallet, or approve a request. If a step leaves you unsure, close the page and reach the service another way.

  1. 1Inspect the web addressLook for misspellings, swapped letters, extra words, or a wrong domain ending, such as .net where the real service uses .com. Compare it with an address you already trust.
  2. 2Refuse to share your seed phraseA legitimate crypto service does not ask for your seed phrase or private key, and support staff do not need them to fix an account. Anyone who asks wants your funds.
  3. 3Open it from a bookmarkSave the official address as a bookmark, or type it by hand. Search ads and links in direct messages often point to paid placements that copy a brand.

After you spot one: secure accounts

A connected wallet is not drained right away, but a signed approval lets an attacker move those tokens later. Note the web address and any transaction hash, which help if you report it.

Frequently asked questions

Connecting alone usually moves nothing. The page can then ask you to sign a token spending approval, and once you sign, an attacker can move those tokens later.

File a report with the FTC at ReportFraud.ftc.gov and with the FBI's IC3 at ic3.gov. Include the web address and any wallet addresses involved.

Yes. HTTPS encrypts the connection between your browser and the server, but it does not show that the operator is honest. Free certificates are easy to get.

Was this guide helpful?
Written byVahe HakobyanVahe Hakobyan is the editor-in-chief of World-Crypt. He covers bitcoin, markets and regulation, and leads the newsroom that fact-checks every story before it goes live.