Skip to main content
Don't invest unless you're prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong. Take 2 min to learn more.

How to Verify a Crypto Website Is Real

The padlock proves nothing. A working checklist for telling a genuine crypto site from a copy, and the habits that make the check automatic.

beginner4 min readWritten by Dan Clarke
Hero image for how-to-verify-a-crypto-website-is-real

TL;DR

  • The browser padlock means the connection is encrypted, not that the site is genuine. Most phishing sites have one.
  • Read the domain right to left: the part before the first single slash is what you are actually visiting.
  • Reach crypto sites by bookmark or typed address, never through search ads or links in messages.
  • Cross-check a platform against an official regulator register before money moves, and verify social links from the site outwards.

The top search result looked perfect. It was an advert, bought that morning, wearing a real exchange's branding over a domain one letter off, with a login page built to harvest whatever got typed into it. In December 2022 the FBI put out a warning about precisely this trade: criminals buying search adverts to impersonate crypto platforms and outrank the genuine site. Everything about the fakes was professional, including the padlock.

About that padlock. By 2020, the security firm PhishLabs was reporting that four in five phishing sites served their pages over HTTPS, so the lock tells you one thing only: nobody can eavesdrop while a counterfeit steals your money in private. Encryption is not identity, so verification has to happen elsewhere, and here is the check, in the order that catches the most.

Step 1: read the domain, right to left

The only part of a web address that identifies the owner is the registered domain: the last two pieces before the first single slash. In banxa.com/coins, that is banxa.com, and in banxa.com.checkout-secure.net, it is checkout-secure.net, the familiar name at the front is bait. Subdomains are free costume, the right-hand end is the passport.

Then look for substitutions: swapped letters, an extra hyphen, .net for .com, the digit 1 for the letter l. Some attacks go further and register lookalike characters from other alphabets, so the address renders convincingly in the bar. If a domain arrived via a message and you have any doubt, do not squint at it: open a fresh tab and type the address you know.

The advert trade from the opening works because people navigate by searching a brand name and clicking whatever ranks, and the defence costs nothing. The first time you use any crypto platform, verify it once, bookmark it, and arrive by bookmark forever after, with type-and-autocomplete a fine second. Clicking through from search adverts, social posts or chat messages is how nearly every fake-site loss begins.

Step 3: check the company, not just the address

A real platform exists off its own website. Licensed crypto businesses appear on public regulator registers, searchable by legal name, and a fake site impersonating one usually cannot survive that lookup: the register entry points to a different domain, or the entry does not exist. The ten-minute version of that check has its own guide in this library, and you run it before first deposit, not after.

Verify in the right direction: find the platform's X account or support channel from links on the verified website, outwards. Searching social media first and trusting whatever verified-looking account appears is backwards, and support impersonation is a thriving trade.

Step 4: treat the rare, sophisticated attack as survivable

Occasionally the address bar itself lies: in April 2018, attackers hijacked internet routing for MyEtherWallet's DNS and served a fake site at the genuine address, and users who clicked through an unexpected certificate warning lost around 150,000 dollars in hours. The lesson is not that verification is pointless, it is that certificate warnings on a site you know are a stop sign, never a click-through, because they appear precisely when something structural has gone wrong.

Wallet users get one more backstop: a transaction preview. Whatever a page claims, the wallet shows what you are actually signing. An approval request from a site you came to for reading, or an unlimited spending permission where a plain transfer belongs, is the page confessing.

Make it automatic

None of this takes expertise: bookmark the platforms you use, read domains right to left, treat search adverts and messaged links as untrusted by default, check the register once per platform, and stop on certificate warnings. Five habits, a few seconds each, and the entire class of copied-website scams loses its audience.

Frequently Asked Questions

No. It means the connection is encrypted. Most phishing sites use HTTPS and show the padlock. Judge identity by the domain and independent checks, not the lock.

Read the domain right to left. The registered domain, the piece immediately before the first single slash, is what you are visiting. A famous name in the subdomain or path means nothing.

Treat them as untrusted. The FBI warned in 2022 about criminals buying adverts that impersonate crypto brands. Reach platforms by bookmark or typed address instead.

Search the regulator's own public register for the company's legal name and compare the domain the entry lists with the site in front of you. This library's guide to checking a platform's licence walks through it register by register.

Stop. On a site you already know, an unexpected certificate warning can mean the address itself is being intercepted, which is rare but real. Close the tab and try again later rather than clicking through.

About the author — Dan Clarke
Dan Clarke

Dan Clarke is the author of Bitcoin: The Complete Guide and a former content lead at Binance Academy, where he wrote crypto education for readers arriving with no background in the subject. He has worked in the cryptocurrency industry since 2017. His rule for these guides: plain language first, precision where it matters, no cheerleading.