Identify Phishing Sites Before You Connect
Scammers create look-alike domains that are nearly indistinguishable from legitimate exchanges. Common techniques include homograph attacks (using visually similar Unicode characters), subdomain spoofing (e.g., secure.ledger.attacker.com), and typosquatting (lledger.com, ledgr.com).
Before connecting your wallet to any site, check the full domain in the address bar — not just the favicon or page title. Use bookmark-based navigation for exchanges you use regularly. Never click links from DMs, Telegram messages, or social media ads. Verify URLs against the official project's verified social channels.
Our indexcrypto engine automatically cross-references domains against known phishing clusters, giving you a Trust Score before you engage.
Security Checklist
- ✓Bookmark official exchange URLs — never type them manually
- ✓Check the full domain, not just the subdomain (e.g., "ledger.com" not "support.ledger.phishing.com")
- ✓Look for HTTPS with a valid SSL certificate
- ✓Cross-check URLs with official Twitter/Discord announcement channels
- ✓Use indexcrypto to verify Trust Score before connecting