Security

How to Spot a Phishing Email Pretending to Be Your Crypto Exchange

  • September 26, 2026

How to Spot a Phishing Email Pretending to Be Your Crypto Exchange

At 7.14 on a Tuesday morning, the message arrives: Unusual sign-in detected on your account. Verify your identity within 24 hours or withdrawals will be suspended. The logo is right. The typeface is right. The sender name says your exchange. Your pulse is less convinced.

Crypto phishing has one advantage over the ordinary sort: the stakes are already high, and most of us know it. The fake only has to survive your attention for about ninety seconds. Here is how to make sure it doesn't.

Start with the sender address, not the sender name

Anyone can set a display name to "Coinbase" or "Kraken Support". The display name is decoration. The address after the @ is the claim being made, and it is the part worth reading.

On a computer, click the sender name to expand the header. On a phone, tap it. You may find something like Coinbase <[email protected]>. That message is not from Coinbase, whatever the top line says.

Things to look at in the domain:

  • Lookalikes: one character swapped (c0inbase.com), a hyphen added (coinbase-support.com), or a different ending (coinbase.co, coinbase.net).
  • Nested names: coinbase.com.account-check.xyz belongs to whoever owns account-check.xyz.
  • A reply-to address that goes somewhere else entirely. Some clients show this, and it is a strong tell.
  • Genuine exchanges do often send from a subdomain such as [email protected]. That is normal. The root domain is what counts.

None of that needs technical skill. It needs thirty seconds and the habit of looking.

Hover over links before you go near them

On a desktop, hover. On a phone, press and hold. Either way you get a preview of where the link actually goes, which is often not where the button claims.

Read the URL backwards from the first single slash. In https://exchange.com.login-secure.top/verify, the site you would be visiting is login-secure.top. Everything before it is a costume.

Two variations catch people out. Shortened links, where a bit.ly or t.co address hides the destination entirely, have no place in a genuine account notification. And some emails now ask you to scan a QR code to "confirm" something; the code simply opens the same fake login page, on a screen that shows even less of the address.

There is also the follow-up call. A fake alert is often chased by someone claiming to be support, offering to fix the problem. That call exists to talk you into reading out a two-factor code or installing remote-access software. Real support does not do either.

The cleanest defence is to ignore the link altogether. Open the app, or type the exchange's address yourself. Any genuine notification will also be waiting inside your account.

Urgency is the entire point

Phishing emails are not built to be believed for long. They are built to be acted on before you think. Every one manufactures a clock: a login you did not make, a withdrawal on hold, an account about to be locked, a "security upgrade" that expires tonight.

Notice the shape of the pressure. It offers a disaster you can prevent only by clicking, and it makes waiting feel reckless. Real exchanges are, if anything, unhelpfully calm. They send routine notices, they do not put two-hour deadlines on your money, and they never ask you to cancel a withdrawal by logging in through a link.

One more marker. No exchange, wallet provider or support agent will ever ask for your seed phrase, private key, password or the six-digit code your authenticator app has just produced. That request is the fraud, however warm and helpful the person making it sounds.

The quick checks that catch most fakes

  • The sender's domain does not match the exchange's.
  • A link's destination does not match its text.
  • There is a deadline, a threat, or both.
  • You are asked for a seed phrase, private key, password or 2FA code.
  • You are told to move funds to a "safe wallet" for your protection.
  • There is an attachment you did not request: an invoice, a statement, an HTML file.

Poor spelling is a weak signal these days; good phishing is clean. Trust the structure of the message, not the polish.

If you clicked, or nearly did

A near miss is still worth acting on. Work through this in order, and do not use any link from the suspicious email to do it.

  1. Stop. Close the message. Do not reply, and do not use its unsubscribe link.
  2. If you entered your password, change it now from a typed address or the app. If you use that password anywhere else, change it there too.
  3. Sign out of all sessions and revoke any API keys you do not recognise.
  4. Audit your security settings: two-factor methods, trusted devices, withdrawal whitelists, linked bank details, and any email forwarding rules you did not create.
  5. Check activity. If anything has moved, contact the exchange's official support immediately. Speed matters far more than a well-worded message, and a significant sum is worth discussing with your bank and, where appropriate, taking professional advice.
  6. If you typed a seed phrase, treat the wallet as compromised. Create a new wallet and move the funds. Do not wait for a reply from support first.
  7. If you installed remote-access software, disconnect the device from the internet and get help from someone qualified before using it for anything financial.
  8. Report it. Forward the message to the exchange's phishing reporting address, and in the UK pass it to the NCSC's Suspicious Email Reporting Service at [email protected]. If money has gone, report to Action Fraud and tell your bank.

Make yourself a harder target

Most of the work happens before any email arrives. Bookmark your exchange and reach it that way, or use the app, so a link never has a reason to be trusted. Use an authenticator app or a hardware key rather than SMS codes, which can be intercepted. Turn on withdrawal address allowlisting if your exchange offers it, and accept the small inconvenience of a hold on new addresses.

It also helps to give your exchange a different email address from the one you use everywhere else. If a fake lands in an inbox that only ever receives exchange mail, it stands out instantly.

The habit underneath all of it is simple: no message about your crypto requires a decision in the next ten minutes. Read it later, from the app, and check for yourself.

Photo: 27707 / Pixabay

PreviousCrypto Security Checklist: 15 Checks to Run Before You Buy or TradeNextRug Pulls and Fake Tokens: Warning Signs Every Investor Should Recognise