DeFi Intel

Spot Fake Token Sites: Phishing Domains Guide

Every day, scammers register domains that look almost identical to popular crypto projects — uniswap.org vs uniswap.org (with a homoglyph), or ‘eth-airdrop.live’. One wrong click can drain your wallet. This guide teaches you exactly how to spot these fake token websites and phishing domains before you connect your wallet or enter any seed phrase.

You will learn: why phishing domains work, how to inspect a URL like a security pro, where to verify token contract addresses, which browser extensions can save you, and what to do if you already clicked a bad link. No hype — just durable, actionable steps.

Key takeaways
  • Always inspect the full URL character by character — homoglyphs and lookalike TLDs are the most common tricks.
  • Verify token contract addresses only through CoinGecko, CoinMarketCap, or the project's official docs — never via Google ads or DMs.
  • Install browser extensions like MetaMask's built-in protection and PhishFort/Connect for an extra warning layer.
  • Cross-check any link from social media against at least two independent official sources before clicking.
  • If you connect to a phishing site, immediately revoke all approvals and move funds to a new wallet.
  • Build security habits: bookmark official URLs, use a hardware wallet, and test new dApps with a burner wallet first.

Why Phishing Domains Are So Dangerous

Phishing domains exploit trust and urgency. Scammers copy the exact layout of a legitimate DeFi site, replace the URL with a lookalike, and drive traffic through fake ads, airdrop announcements, or compromised social media accounts. Once you connect your wallet, the fake site can execute malicious smart contract approvals — draining your tokens without you signing a visible transaction.

Beginners often rely on the site’s appearance rather than its address. Attackers know this. They register domains like:

The key vulnerability: users only see the first few letters in a browser tab or ad. Scammers exploit that blind spot.

“The most expensive mistake in crypto is not a failed trade — it’s a signed approval on a phishing site.” — DeFi security analyst

Understanding why these sites are effective is the first step to building a critical eye. Every new token launch — especially with airdrops — attracts a wave of phishing domains. Never click links from Twitter replies, Telegram groups, or Google ads offering ‘free tokens.’

Step 1: Inspect the URL Like a Security Researcher

Before you even load the page, slow down and parse the entire URL. A domain has three parts: protocol (https://), domain name (example.com), and path (/claim). Scammers manipulate all three.

Check the protocol: Legitimate sites use HTTPS, but many phishing sites also use HTTPS because SSL certificates are free. HTTPS alone does not mean safe.

Inspect the domain name carefully:

Compare with official sources: Open a new tab and manually type the official domain (from CoinGecko or project docs). Do not use Google search results — they may contain paid ads that lead to phishing sites.

What to CheckSafe ExamplePhishing Example
Domain spelllinguniswap.orgunϊswap.org (homoglyph)
TLDpancakeswap.financepancakeswap.com
Subdomainapp.uniswap.orguniswap.org.app.xyz

If the URL feels off, it probably is. Trust your gut and double-check every character.

Step 2: Verify the Token Contract Address

Phishing sites often mimic token sale pages or airdrop claims. They ask you to connect your wallet to a fake ‘claim’ contract. To avoid this, never interact with a contract address you haven’t verified on a block explorer.

How to find the real contract:

Red flag: If the phishing site does not show a contract address at all, but asks you to connect your wallet, that is a clear danger. Legitimate airdrop claims and token swaps will always reference a publicly known contract.

“If you have to ‘Paste your wallet address to check eligibility’ — and the site isn’t a known official dashboard — you are almost certainly on a phishing domain.”

Bookmark the official contract pages of projects you follow. Do not rely on search engine results for contract addresses.

Step 3: Use Browser Extensions That Flag Phishing Domains

Your browser can be your first line of defense. Several free extensions maintain blacklists of known phishing domains and warn you before you interact.

Essential extensions:

How to test them: Visit a known safe site like app.uniswap.org — the extension should remain quiet. Then visit a known phishing site (if you have a test wallet with no funds) — the extension should block the connection or display a red warning.

Extensions are not perfect. They rely on blacklists that may lag behind new phishing domains. Treat them as a helpful safety net, not a replacement for URL inspection.

One important tip: Do not install random browser extensions from unknown sources. Only use extensions from the official Chrome Web Store or Firefox Add-ons, and check their reviews and permissions.

Step 4: Cross-Check Official Sources for All Links

Even if a domain looks perfect, you must confirm it through multiple trusted sources. Scammers sometimes compromise official social media accounts to post phishing links. Here’s a reliable verification workflow:

1. Start with CoinGecko or CoinMarketCap. Look up the token. The “Official Links” section lists the project’s website, Twitter, and Discord. Click the website link — it is manually reviewed and rarely wrong.

2. Use the project’s official documentation. Reputable projects have a docs site (docs.projectname.io). That docs site almost always links to the correct app or claim site.

3. Check the pinned tweet on the official Twitter (X) account. But note: even verified blue check accounts can be hacked. Once a hacker has the account, they pin a tweet with a phishing link. To counter this, wait a few hours. If the link is real, the community will usually shout about it. If it’s a hack, warnings will appear quickly.

4. Use a community verification tool like Revoke.cash or Token Sniffer. These tools allow you to check approvals and token contract legitimacy without connecting your wallet in a risky way.

Rule of thumb: Never trust a single source. If you find a link on Twitter, verify it on CoinGecko. If it’s in a Telegram announcement, check the project’s official blog. Two independent confirmations significantly reduce risk.

Step 5: Recognize the Social Engineering Lures

Phishing domains rarely appear by accident. Scammers actively lure you to them. The most common bait:

What to do: If a message triggers excitement or panic, pause. Read the URL out loud. Compare it with the official one you have bookmarked. Ask a trusted friend or search the project name + “scam” on Twitter. Almost always, the warning posts appear before you finish reading the lure.

“If it feels too good to be true, the URL is probably fake.”

Remember: scammers invest time to make the site look identical to the real one. The only difference is the domain name and the malicious intent behind the connect button.

Step 6: What to Do If You Already Clicked a Phishing Site

If you connected your wallet to a phishing site, act immediately. Speed is critical.

Immediate actions:

What not to do: Do not panic and connect again to ‘check’ approvals — that could trigger further damage. Do not click on any links in emails or DMs claiming to help you ‘recover’ stolen funds — those are recovery scams.

Report the phishing domain to MetaMask, Etherscan, or PhishFort to help protect others. The faster it is blacklisted, the fewer victims.

Step 7: Build Long-Term Habits to Stay Safe

Security is not a one-time checklist; it’s a habit. Integrate these practices into your daily crypto routine:

These habits become automatic over time. The goal is to reduce the cognitive load — you won’t have to inspect every URL from scratch because you already trust your bookmarks and hardware wallet.

“The best defense is not a tool — it’s a deliberate pause before every wallet connection.”

Frequently asked questions

How can I spot a fake token website quickly?

Look for subtle URL changes like swapped letters (Cyrillic homoglyphs), extra dots, or unusual TLDs (e.g., .org vs .com). Always verify the domain via CoinGecko's official links before connecting your wallet.

What is typosquatting in crypto phishing?

Typosquatting (or URL hijacking) registers domains that are simple misspellings of popular sites, like 'pancakeswap.com' instead of 'pancakeswap.finance'. Scammers rely on users typing the wrong address or clicking a typo in an ad.

Can I safely recover tokens lost to a phishing site?

If you approved a malicious contract, revoke the approval immediately using Revoke.cash. Transfer remaining funds to a new wallet with a different seed phrase. Do not engage with recovery services — they are usually scams.

Do browser extensions guarantee safety from phishing?

No — extensions rely on blacklists that can be outdated for minutes or hours. They are helpful but not foolproof. Always combine extension warnings with manual URL inspection and source cross-checking.

What should I do if a project's official Twitter account posts a link?

Treat it with suspicion even if the account is verified. Wait for community confirmation, compare the URL to bookmarks or CoinGecko, and avoid interacting until multiple reliable sources verify the link.

Track the entities behind the concepts

DeFi Intel maps 11,000+ protocols, tokens and companies to a typed knowledge graph — with live data, incidents and regulation.

Entities mentioned