Skip to content

September 1, 2026

CRYPTO·COINBEAT

Journalism for the digital-asset economy

BTC$67,240 2.4%/
ETH$3,418 1.1%/
SOL$182.40 0.8%/
BNB$604.20 0.3%/
XRP$0.624 1.9%/
ADA$0.512 0.6%/
AVAX$38.10 3.2%/
DOGE$0.158 0.4%/
BTC$67,240 2.4%/
ETH$3,418 1.1%/
SOL$182.40 0.8%/
BNB$604.20 0.3%/
XRP$0.624 1.9%/
ADA$0.512 0.6%/
AVAX$38.10 3.2%/
DOGE$0.158 0.4%/
Bitcoin· Explainer

How to Spot a Fake Crypto App or Website

By CryptoCoinBeat

Staff · September 1, 2026 · 8 min read

Published September 1, 2026 · Reviewed to our editorial standards. This article is informational and not financial advice.

Illustration · CryptoCoinBeat

Impersonation is the most productive attack in crypto, because it needs no exploit and no privileged access. It needs you to arrive at the wrong place while believing it is the right one — and then behave exactly as you normally would.

The modern fake is not a badly translated email. It is a sponsored search result for the wallet you already use, an app in an official store with hundreds of reviews, a support account that replies within seconds of you posting a problem, or a hardware wallet posted to your home address. Here is how to catch each one.

Search results are advertising, not verification

Paid placement above the organic results has been a dependable phishing channel for years, and it works because the domain looks close enough and the page is a pixel-accurate copy. The failure happens before anything is signed: you arrive, you connect, and from then on every prompt looks routine.

The defence is procedural rather than clever. Reach wallet and exchange sites through your own bookmarks, saved the first time from a source you verified. Never through a search, a message, a QR code on a poster, or a link in a reply. If a bookmark is missing, type the domain manually and check it character by character — homoglyph domains that swap one letter are standard.

App stores are a weaker filter than they look

Counterfeit wallets appear in both major app stores regularly, complete with fabricated reviews and a plausible download count. Some are removed within days, after they have already taken funds.

  • Follow the download link from the vendor's own website rather than searching the store directly.
  • Check the developer name against the vendor's published account, not the app title, which anyone can copy.
  • Treat a recent publish date on a long-established product as a strong warning sign.
  • Be suspicious of a five-star average with generic, similarly worded reviews posted in a narrow window.

The one question no legitimate service asks

Nobody legitimate will ever ask for your recovery phrase. Not support, not a migration tool, not a validation step, not an airdrop claim, not a wallet upgrade. There is no exception and no context in which it becomes reasonable.

That single rule defeats the majority of retail crypto theft, which is why attackers work so hard to build a scenario where it feels justified. The scenario is the attack. If you find yourself explaining to yourself why this time is different, stop.

Support that arrives unrequested is hostile

Post publicly about a stuck transaction and you will receive help within minutes, from accounts using the right logo and the right tone. They will move you to a private channel, walk you through a plausible diagnostic, and arrive at a screen asking you to import your wallet or approve a transaction.

Real support does not initiate contact, does not use private messages first, and does not need your keys to look at a public blockchain. If you need help, start from the vendor's own site — the same bookmark discipline as everything else here.

Physical fakes: the counterfeit device

After the 2020 breach of Ledger's e-commerce database exposed customer names and postal addresses, counterfeit devices began arriving by post to real owners, packaged convincingly, sometimes with a letter explaining a mandatory security replacement. The device inside is either pre-seeded or modified.

Buy hardware only from the manufacturer, and treat any unsolicited device as an attack regardless of how the packaging looks. A genuine wallet never ships with a recovery phrase, and no vendor mails replacements you did not order. Our hardware wallet setup guide covers verifying a device before you generate anything on it.

Fake tokens and cloned contracts

On-chain, impersonation continues. Anyone can deploy a token called USDC, or a pool that looks like a real project's. Trading interfaces try to filter these, and new fakes appear faster than lists update.

Verify the contract address from the project's own documentation or a reputable aggregator before you swap, not from a social media post. Wallets that flag known-malicious contracts and simulate transactions before signing catch a meaningful share of these — that capability is one of the axes in our self-custody wallet table.

Browser extensions deserve their own paranoia

A wallet extension sits inside the browser you use for everything, with permission to read pages and inject scripts. A counterfeit one, or a legitimate extension that changes hands and ships a malicious update, sees every site you visit and every prompt you approve.

Install only from the vendor's own link, check the publisher, and remove extensions you stopped using — dormant ones still update. If an extension you did not touch suddenly requests broader permissions, that is a change of ownership or a compromise, and the correct response is to remove it and move funds from any wallet it could reach.

The checks worth doing every time

  • Arrive by bookmark, never by search or message.
  • Confirm the domain character by character before connecting a wallet.
  • Refuse every recovery-phrase request, without exception.
  • Read what the transaction actually does on your hardware device's screen, not in the browser.
  • Verify contract addresses from primary sources before swapping an unfamiliar token.

None of this requires vigilance in the exhausting sense. It requires a small number of habits that make the attack fail regardless of how convincing the page is — which is the only defence that scales, because the fakes will keep getting better and your attention will not.

Frequently asked questions

How can I tell if a crypto app is fake?+

Follow the download link from the vendor's own website, check the developer account against the one they publish, and treat a recent publish date on an established product as a warning. Fabricated reviews and download counts are cheap; a matching developer account and a link from the official domain are not.

Why do fake crypto sites appear in search results?+

Because paid placement can be bought and the copy is pixel-accurate. Search advertising has been a reliable phishing channel for years, which is why bookmarks — saved once from a verified source — beat searching every time.

Will support ever ask for my seed phrase?+

No legitimate service ever asks, in any context: not migration, not validation, not an upgrade, not an airdrop. Any request is an attack, and the elaborate justification attached to it is part of the attack.

I received a hardware wallet I did not order. What should I do?+

Do not use it. Unsolicited devices have been mailed to addresses taken from a 2020 customer data leak, and they arrive pre-seeded or modified. Genuine wallets never ship with a recovery phrase and vendors do not send unrequested replacements.

Written by

CryptoCoinBeat

Keep Reading