Independent educational website - not an official exchange service

Reviewed guide | 2026-09-27

Spotting Exchange Phishing Sites Before You Log In

A practical pre-login routine for Australian crypto users to check whether an exchange page is genuine before typing a password or 2FA code, with concrete steps, records to keep and stop conditions.

australiacryptoguide.com

Multiple exchanges | Australia | AUD | fees, access and account safety

Phishing pages rarely look obviously wrong. They copy logos, colours and layout closely enough that the only reliable difference is the address bar, the certificate details and how you arrived at the page. Because login credentials and one-time codes are the target, the moment before you type anything is the moment that matters most. This guide sets out a repeatable pre-login check you can run in under a minute, covering how you reached the page, what the browser is telling you, how to verify the site through official channels, and what to record so you can compare notes over time. It applies to the major exchanges Australian users commonly hold accounts with, including Binance, OKX, Bybit and Bitget, and the same sequence works for each of them. Nothing here replaces the official help centre of the exchange you use; treat those pages as the reference point whenever something looks unfamiliar.

Start with how you arrived at the page

Most successful phishing depends on the route, not the design. Before you look at anything on screen, ask how you got there. A link in an email, an SMS, a social media message, a comment under a video or a sponsored search result should all be treated as unverified until you confirm the destination independently. If you tapped a link and the page immediately asks for your password, your 2FA code or a seed phrase, close it and start again from a bookmark you created yourself.

The safer habit is to never log in from a link you did not create. Open a new tab, use your own bookmark or type the address you already know, and only then sign in. If a message claims there is an urgent problem with your account and pushes you to act quickly, that urgency is itself a reason to slow down. Genuine account notices will still be waiting for you when you reach the site through your own route.

Keep a short note of the routes you actually use: which bookmark, which device, which browser profile. When something feels off, you can compare the current page against that note rather than relying on memory. This single habit removes the largest category of credential theft before any technical check is needed.

Read the address bar and certificate, not the page

The address bar is the only part of the screen a phishing page cannot fully control. Read it character by character rather than glancing at it. Look for extra words, hyphens, unusual endings, misspellings that are easy to skim past, and combinations that place the exchange name somewhere other than the main part of the address. A name appearing in a subdomain or a path is not the same as being the site itself.

Next, open the certificate information through your browser's padlock or site information panel. Check which organisation the certificate was issued to and whether that matches the exchange you intend to use. A valid certificate alone proves only that the connection is encrypted, not that the site is genuine, so treat it as one signal among several. If your browser shows a warning page, do not click through it to reach a login form.

Finally, confirm that the page is served over a secure connection and that you are not looking at a cached or saved copy of a login screen. If anything in the address bar or certificate panel does not match what you expect, stop there. There is no version of this check where proceeding to type your password is the safer option.

Verify the site through official channels

When a page looks right but you are not certain, verify it from a source that phishing cannot easily imitate. Open the exchange's official help centre in a separate tab and look for guidance on recognising genuine communications and reporting suspicious pages. Support hubs of the major exchanges, including Binance, OKX, Bybit and Bitget, publish this kind of material, and reading it once means you know where to look next time.

You can also confirm details from inside an account you already trust. Log in through your own bookmark, then check your account settings and security notifications for anything you did not do. If you received a message claiming to be from the exchange, compare it against the messages that actually appear in your account. A real notice will normally be visible there; a phishing message will not be.

Never verify a page by using contact details, phone numbers or chat links supplied by the page or message you are trying to check. That is circular and plays into the attacker's hands. Verification only counts when it comes from a route you established independently, such as your own bookmark or the help centre you navigated to yourself.

What to record and when to stop

Keep a simple log of anything suspicious: the date and time, the device and browser, how you reached the page, what the address bar showed, and what the page asked for. Do not record passwords, 2FA codes or seed phrases anywhere. If you already entered credentials on a page you now doubt, change your password from a known-good session, review your active sessions and API keys in account settings, and report the page through the exchange's official support channel.

Set clear stop conditions in advance so you are not deciding under pressure. Stop immediately if the page asks for a seed phrase or recovery phrase, if it requests your 2FA code before your password, if it asks you to disable security features, if it opens a chat window offering to help you log in, or if the address bar or certificate does not match your expectations. Any one of these is enough to end the session.

Remember that fee pages and product documentation are also common phishing bait, because they attract people who are already logged in and relaxed. If you want to check current trading fees or product rules, reach those pages from inside your own bookmarked session or from the official help centre, and record what you find rather than trusting a figure shown on an unfamiliar page. Consistency in how you check is what makes the routine reliable over time.

Risk boundary: Australia Crypto Guide

Digital assets are volatile and derivatives can amplify losses. This website has no login, wallet connection, deposit form or customer-support chat. A referral link only records attribution; it does not guarantee access, pricing, rewards, approval or investment results. Availability can differ by residence, legal entity and product, so no regional access is assumed from language or branding alone.

Scenario checkpoint

  • Confirm you reached the login page through your own bookmark or typed address, not a link from a message, email, search result or social post.
  • Read the full address bar character by character and check the certificate details through your browser's site information panel.
  • Verify anything unfamiliar against the exchange's official help centre in a separate tab before entering credentials.
  • Stop immediately if a page asks for a seed phrase, a 2FA code before your password, or asks you to weaken your security settings.
  • Log the date, device, route and what the page requested, without recording passwords, codes or recovery phrases.
  • If you already entered credentials, change your password from a known-good session and review active sessions and API keys.
Risk boundary

Digital assets are volatile and derivatives can amplify losses. This website has no login, wallet connection, deposit form or customer-support chat.