Spot Fake Token Sites: Phishing Domains Guide
Every day, scammers register domains that look almost identical to popular crypto projects — uniswap.org vs uniswap.org (with a homoglyph), or ‘eth-airdrop.live’. One wrong click can drain your wallet. This guide teaches you exactly how to spot these fake token websites and phishing domains before you connect your wallet or enter any seed phrase.
You will learn: why phishing domains work, how to inspect a URL like a security pro, where to verify token contract addresses, which browser extensions can save you, and what to do if you already clicked a bad link. No hype — just durable, actionable steps.
- Always inspect the full URL character by character — homoglyphs and lookalike TLDs are the most common tricks.
- Verify token contract addresses only through CoinGecko, CoinMarketCap, or the project's official docs — never via Google ads or DMs.
- Install browser extensions like MetaMask's built-in protection and PhishFort/Connect for an extra warning layer.
- Cross-check any link from social media against at least two independent official sources before clicking.
- If you connect to a phishing site, immediately revoke all approvals and move funds to a new wallet.
- Build security habits: bookmark official URLs, use a hardware wallet, and test new dApps with a burner wallet first.
Why Phishing Domains Are So Dangerous
Phishing domains exploit trust and urgency. Scammers copy the exact layout of a legitimate DeFi site, replace the URL with a lookalike, and drive traffic through fake ads, airdrop announcements, or compromised social media accounts. Once you connect your wallet, the fake site can execute malicious smart contract approvals — draining your tokens without you signing a visible transaction.
Beginners often rely on the site’s appearance rather than its address. Attackers know this. They register domains like:
pancakeswap.finance(real) vspancakeswap.finance(homoglyph ‘c’ replaced with Cyrillic ‘с’)curve.fivscurve.fi.org(different TLD)opensea.iovsopensea.app(subdomain trick)
The key vulnerability: users only see the first few letters in a browser tab or ad. Scammers exploit that blind spot.
“The most expensive mistake in crypto is not a failed trade — it’s a signed approval on a phishing site.” — DeFi security analyst
Understanding why these sites are effective is the first step to building a critical eye. Every new token launch — especially with airdrops — attracts a wave of phishing domains. Never click links from Twitter replies, Telegram groups, or Google ads offering ‘free tokens.’
Step 1: Inspect the URL Like a Security Researcher
Before you even load the page, slow down and parse the entire URL. A domain has three parts: protocol (https://), domain name (example.com), and path (/claim). Scammers manipulate all three.
Check the protocol: Legitimate sites use HTTPS, but many phishing sites also use HTTPS because SSL certificates are free. HTTPS alone does not mean safe.
Inspect the domain name carefully:
- Look for subtle letter swaps: ‘r’ vs ‘г’ (Cyrillic), ‘o’ vs ‘0’, ‘l’ vs ‘1’.
- Check for extra hyphens or dots:
eth-airdrop.comvsethdrop.com. - Beware of subdomain tricks:
wallet.ethereum.orgis safe, butethereum.org.wallet.xyzis not. The last word before the TLD is the real owner.
Compare with official sources: Open a new tab and manually type the official domain (from CoinGecko or project docs). Do not use Google search results — they may contain paid ads that lead to phishing sites.
| What to Check | Safe Example | Phishing Example |
|---|---|---|
| Domain spellling | uniswap.org | unϊswap.org (homoglyph) |
| TLD | pancakeswap.finance | pancakeswap.com |
| Subdomain | app.uniswap.org | uniswap.org.app.xyz |
If the URL feels off, it probably is. Trust your gut and double-check every character.
Step 2: Verify the Token Contract Address
Phishing sites often mimic token sale pages or airdrop claims. They ask you to connect your wallet to a fake ‘claim’ contract. To avoid this, never interact with a contract address you haven’t verified on a block explorer.
How to find the real contract:
- Go to CoinGecko or CoinMarketCap. Search for the token by name. The official contract address is listed under the token’s page — often with a link to Etherscan or BscScan.
- Copy that address and paste it into your browser’s address bar. Do not paste it into a site that claims to ‘check’ it — that could be a phishing site itself.
- Check the block explorer for:
- High liquidity and age (recently created contracts are riskier).
- Verified source code (green checkmark on Etherscan).
- A reasonable number of holders (fewer than 100 is suspicious for a known project).
Red flag: If the phishing site does not show a contract address at all, but asks you to connect your wallet, that is a clear danger. Legitimate airdrop claims and token swaps will always reference a publicly known contract.
“If you have to ‘Paste your wallet address to check eligibility’ — and the site isn’t a known official dashboard — you are almost certainly on a phishing domain.”
Bookmark the official contract pages of projects you follow. Do not rely on search engine results for contract addresses.
Step 3: Use Browser Extensions That Flag Phishing Domains
Your browser can be your first line of defense. Several free extensions maintain blacklists of known phishing domains and warn you before you interact.
Essential extensions:
- MetaMask’s built-in phishing detection: If you have MetaMask installed, it will warn you when you visit a flagged phishing site. Keep MetaMask updated to receive the latest blacklist.
- Etherscan’s Contract Checker: The Etherscan Chrome extension automatically verifies whether a contract address is verified and shows a warning if it’s unverified or newly created.
- PhishFort/Connect: This open-source extension scans the site’s scripts and warns about suspicious wallet connect prompts.
How to test them: Visit a known safe site like app.uniswap.org — the extension should remain quiet. Then visit a known phishing site (if you have a test wallet with no funds) — the extension should block the connection or display a red warning.
Extensions are not perfect. They rely on blacklists that may lag behind new phishing domains. Treat them as a helpful safety net, not a replacement for URL inspection.
One important tip: Do not install random browser extensions from unknown sources. Only use extensions from the official Chrome Web Store or Firefox Add-ons, and check their reviews and permissions.
Step 4: Cross-Check Official Sources for All Links
Even if a domain looks perfect, you must confirm it through multiple trusted sources. Scammers sometimes compromise official social media accounts to post phishing links. Here’s a reliable verification workflow:
1. Start with CoinGecko or CoinMarketCap. Look up the token. The “Official Links” section lists the project’s website, Twitter, and Discord. Click the website link — it is manually reviewed and rarely wrong.
2. Use the project’s official documentation. Reputable projects have a docs site (docs.projectname.io). That docs site almost always links to the correct app or claim site.
3. Check the pinned tweet on the official Twitter (X) account. But note: even verified blue check accounts can be hacked. Once a hacker has the account, they pin a tweet with a phishing link. To counter this, wait a few hours. If the link is real, the community will usually shout about it. If it’s a hack, warnings will appear quickly.
4. Use a community verification tool like Revoke.cash or Token Sniffer. These tools allow you to check approvals and token contract legitimacy without connecting your wallet in a risky way.
Rule of thumb: Never trust a single source. If you find a link on Twitter, verify it on CoinGecko. If it’s in a Telegram announcement, check the project’s official blog. Two independent confirmations significantly reduce risk.
Step 5: Recognize the Social Engineering Lures
Phishing domains rarely appear by accident. Scammers actively lure you to them. The most common bait:
- Free token airdrops: “We’re giving away 1,000 ETH to early supporters — connect your wallet to claim.” Real airdrops never require you to pay gas fees first or connect to an external site.
- Urgency and scarcity: “Only 100 spots left!” Time pressure makes you skip security checks.
- Fake giveaways from impersonated influencers: A tweet from a verified account that says “I’m giving away 10 ETH to the first 1000 people who send 0.1 ETH to this address.” That is a classic advance‑fee scam.
- Compromised Telegram or Discord bots: Bots that DM you a link to “claim rewards.” Official projects rarely DM individuals with links.
What to do: If a message triggers excitement or panic, pause. Read the URL out loud. Compare it with the official one you have bookmarked. Ask a trusted friend or search the project name + “scam” on Twitter. Almost always, the warning posts appear before you finish reading the lure.
“If it feels too good to be true, the URL is probably fake.”
Remember: scammers invest time to make the site look identical to the real one. The only difference is the domain name and the malicious intent behind the connect button.
Step 6: What to Do If You Already Clicked a Phishing Site
If you connected your wallet to a phishing site, act immediately. Speed is critical.
Immediate actions:
- Disconnect your wallet from the site. Go to your wallet (MetaMask, etc.) and revoke the connection from the phishing site. In MetaMask: click the three dots → Connected Sites → Disconnect the suspicious site.
- Use Revoke.cash or Etherscan’s Token Approval tool to check for any approvals that the phishing site may have requested. Revoke any approval that looks unfamiliar or was granted at the time you visited the site. Do this with a clean browser session (no suspicious tabs open).
- Transfer your funds to a new wallet that has never been connected to that site. Use a wallet with a different seed phrase. This is the safest option if you are unsure whether an approval is malicious.
- Change your password if the phishing site asked for a password (common for exchange wallets). Use a password manager and enable 2FA.
What not to do: Do not panic and connect again to ‘check’ approvals — that could trigger further damage. Do not click on any links in emails or DMs claiming to help you ‘recover’ stolen funds — those are recovery scams.
Report the phishing domain to MetaMask, Etherscan, or PhishFort to help protect others. The faster it is blacklisted, the fewer victims.
Step 7: Build Long-Term Habits to Stay Safe
Security is not a one-time checklist; it’s a habit. Integrate these practices into your daily crypto routine:
- Bookmark official URLs: Save the real website of every token you own. Use a dedicated folder in your browser bookmarks. Never type a URL from memory — click the bookmark.
- Use a hardware wallet: Ledger or Trezor. Even if you approve a malicious transaction, the hardware wallet will display the contract details on the device screen. If it says “Contract interaction” without a contract address you recognize, reject it.
- Enable two-factor authentication on your email, Telegram, and any crypto service (e.g., exchanges). This reduces the chance of account takeovers that can lead to phishing.
- Stay updated on common scams: Follow security firms like SlowMist, CertiK, or PeckShield on Twitter. They often post alerts about new phishing domain campaigns.
- Test with a dummy wallet: Before connecting your main wallet to any new dApp, first connect a small, empty wallet (called a “burner wallet”). If everything looks normal, then switch to your main wallet.
These habits become automatic over time. The goal is to reduce the cognitive load — you won’t have to inspect every URL from scratch because you already trust your bookmarks and hardware wallet.
“The best defense is not a tool — it’s a deliberate pause before every wallet connection.”
Frequently asked questions
How can I spot a fake token website quickly?
Look for subtle URL changes like swapped letters (Cyrillic homoglyphs), extra dots, or unusual TLDs (e.g., .org vs .com). Always verify the domain via CoinGecko's official links before connecting your wallet.
What is typosquatting in crypto phishing?
Typosquatting (or URL hijacking) registers domains that are simple misspellings of popular sites, like 'pancakeswap.com' instead of 'pancakeswap.finance'. Scammers rely on users typing the wrong address or clicking a typo in an ad.
Can I safely recover tokens lost to a phishing site?
If you approved a malicious contract, revoke the approval immediately using Revoke.cash. Transfer remaining funds to a new wallet with a different seed phrase. Do not engage with recovery services — they are usually scams.
Do browser extensions guarantee safety from phishing?
No — extensions rely on blacklists that can be outdated for minutes or hours. They are helpful but not foolproof. Always combine extension warnings with manual URL inspection and source cross-checking.
What should I do if a project's official Twitter account posts a link?
Treat it with suspicion even if the account is verified. Wait for community confirmation, compare the URL to bookmarks or CoinGecko, and avoid interacting until multiple reliable sources verify the link.
Related reading
Track the entities behind the concepts
DeFi Intel maps 11,000+ protocols, tokens and companies to a typed knowledge graph — with live data, incidents and regulation.