If you searched "Binance login" on Google last week, there's a 1-in-12 chance the top sponsored result was a phishing clone. Cloned exchange sites are the largest single attack surface in crypto right now — bigger than smart-contract hacks, bigger than seed-phrase theft. They work because the real sites are visually simple, and a $30 template + a typo-domain reproduces them perfectly.
How clones get to the top of your search
- Sponsored Google ads with display URLs that read "binance.com" but click through to "binance-login-secure.app".
- SEO-stuffed lookalike domains —
binnance.com,b1nance.com,binance-us-official.net. - Compromised browser extensions that quietly rewrite the URL when you type in the address bar.
- Punycode domains that render as Cyrillic-Latin lookalikes —
binаnce.com(the 'a' is actually 'а'). - YouTube/Twitter promotion of "support" sites that "help you recover" or "verify" your account.
The four-layer verification
### 1. The bookmark rule
The single highest-impact habit: never type the URL, never click a search result, never click a link in an email. Bookmark the official site once, from a trusted source (the exchange's official mobile app → Settings → website link), and only ever use that bookmark.
### 2. Check the exact TLD
Real exchanges in 2026:
- Binance → binance.com (global), binance.us (United States). That's it.
- Coinbase → coinbase.com and pro.coinbase.com.
- Kraken → kraken.com.
- OKX → okx.com.
- Bybit → bybit.com.
Anything ending in .app, .io, .net, .support, .help, .live, or a country code you don't expect is a clone. Period.
### 3. Inspect the certificate
Click the padlock → Certificate. Real exchange certs are issued to the verified company name ("Binance Holdings Limited", "Coinbase, Inc."). A cert issued to "Cloudflare Inc." or the bare domain with no organization line is a red flag for a clone hiding behind a CDN.
### 4. Cross-check the domain age and registrant
Paste the domain into any free WHOIS tool. Real exchange domains are registered for 5–10 years out, with privacy protection by a known registrar (MarkMonitor for Coinbase, CSC for Binance). A domain registered three weeks ago through Namecheap with privacy hidden is a clone.
The phishing kit tells (once you're on the page)
- A fake "login session expired — verify your seed phrase" prompt. Real exchanges never, ever ask for your seed phrase. They don't have one for you.
- A 2FA page that accepts *any* code. Real 2FA rejects wrong codes; clones accept everything so they can harvest creds for later.
- A "support agent" pop-up chat offering to help "restore" your account.
- A withdrawal flow that requires you to send a "verification deposit" first.
- Branding that's 98% perfect but has a slightly-wrong shade of yellow or a 2021-era logo.
Mobile is not safer
Cloned exchange *apps* in the App Store and Play Store are even more dangerous because users assume store-listed apps are vetted. They're not — review them like a website. Check the developer name (must match the company exactly), review count and age (real exchanges have 500k+ reviews going back years), and last-update date (real exchanges ship often).
If you logged in to a clone
- Open the real exchange from your bookmark and change your password immediately.
- Rotate your 2FA device — assume the seed for the authenticator app is also compromised if you typed it in.
- Withdraw all funds to a hardware wallet whose seed has never touched a browser.
- Submit the clone URL to GACS so the next victim searching it gets a red warning.
- Report the clone to the real exchange's phishing inbox (
reportphishing@binance.com,security@coinbase.com).
The 4-second habit
Before logging in to *any* exchange, paste the URL into the GACS Safe Scanner. It cross-checks against the real exchange registry, our 250k-entity blacklist, the domain's age, and the cert. Four seconds, free, no signup. It's the cheapest insurance in crypto.
