A convincing clone is a perfect copy of the real site with one difference: connecting your wallet sends your assets somewhere else. This checks a web address against how crypto phishing domains are actually built, without ever opening it.
Do not visit the site to copy the address. Copy the link without opening it. See an example.
Check the address before you open it, not after. A convincing clone is a perfect copy of the real site with one difference: the wallet connection sends your assets somewhere else. By the time the page looks right, you have already trusted it.
This checks the domain against how crypto phishing domains are actually built. It runs on your device and never visits the site.
Almost none of them are creative. They take a name you trust and attach something to it, because the real domain is taken and a plausible variation is not. The patterns repeat because they work on a glance, and a glance is all anyone gives a URL.
Never reach a crypto site through a link. Not from an email, a message, a reply, a QR code or a search advert, which are bought by scammers routinely and sit above the real result. Type the address yourself or use a bookmark you created when you were not in a hurry. That single habit defeats every pattern above, including the ones nobody has invented yet.
Assume a permission was granted. Revoke approvals on that wallet immediately across every chain, then move what remains to a wallet created fresh on a clean device. The drain checklist covers the order, and speed matters more than getting it perfect.
Look at the part of the address immediately before the ending, because that is the only part that identifies who owns it. If the real site is metamask.io then metamask-wallet.com, metamask.security-check.com and metarnask.io are all different owners, and all three look right at a glance. Everything to the left of the registrable domain can be written by anyone, which is exactly what makes this attack work.
Almost certainly. Visiting a page does not move funds by itself. The loss happens when you connect a wallet and approve a transaction, or when you type a recovery phrase. If you did neither, close the tab and carry on. If you are unsure whether you approved something, check the wallet with a revocation tool.
Because it is a copy. Cloning a website is trivial: the whole front end is public and can be downloaded in seconds. The only change made is where the wallet connection points. Visual accuracy tells you nothing at all about who is running a site, which is why the address is the only thing worth checking.
No, and this catches people out constantly. Scammers buy search adverts against brand names, and paid results sit above real ones. During brand searches for wallets these ads appear regularly and are often the top result. A search engine ranks and sells placement, it does not verify.
It means the address does not use the constructions crypto phishing usually uses, which is not the same as safe. A careful attacker avoids all of them, and a legitimate domain can be compromised. The rule that survives every variation is to never reach a crypto site through a link, and never enter a recovery phrase on any website including the real one.
We seal the list every week and keep re-checking every token on it, so you can see what actually happened to them rather than only what is trading today.