Security

How to spot fake crypto exchange apps before you install

Clone apps harvest logins. Use publisher checks, URL habits, and install hygiene to stay safer.

How to spot fake crypto exchange apps before you install

How to spot fake crypto apps before they drain a phone

Fake exchange and wallet apps are an industry: cloned icons, stolen screenshots, bought reviews, and ads that outrank honest listings for a weekend. This guide is about install hygiene—mobile stores, sideloads, and the support scams that push “the real APK.”

Educational only. Not a guarantee that any single check is perfect. Stack checks.

Why fakes convert

People search brand names under time pressure. Icons look “close enough” on a small screen. Reviews can be purchased. Sideloaded packages bypass store review. Chat scammers send “official mirrors” during account panic.

If funds will touch the install, treat the install as a security decision equal to a password choice.

Official install path (default)

  1. Open the bookmarked website first (verify official domains).
  2. Use in-site links to the official store listing when the company provides them.
  3. In the store, inspect publisher name, update recency, and install base—none is sufficient alone; together they filter junk.
  4. Prefer store installs over random APK sites.
  5. After install, open once, confirm security settings pages load, then tighten permissions.

Store listing red flags

  • Publisher name that is almost correct
  • Broken language full of urgency
  • Permissions for SMS, accessibility services, or contacts without a clear product reason
  • Brand-new listing wearing a famous logo
  • Telegram or WhatsApp “support” handles inside the description
  • Screenshots that look like desktop web pages pasted into a phone frame
  • Ratings that jump overnight with repetitive review text

Sideloading policy

Default: disabled. If you temporarily enable install-from-unknown-sources:

  1. Install only from a path you initiated via official guidance you can re-find later
  2. Disable unknown sources immediately after
  3. Never install because a DM said your account will be closed in one hour

Remote-control “helpers” are a separate kill-chain—refuse them. See device hygiene.

Desktop cousins: extensions and “helpers”

Malicious browser extensions can rewrite withdrawal addresses after you copy them. Keep a boring browser profile for finance. Audit extensions quarterly. Prefer typing critical addresses with visual prefix/suffix checks.

After a suspicious install (incident mini-runbook)

  1. Remove the app and related profiles
  2. From a known-clean device, open the real site via bookmark
  3. Change password; revoke sessions and devices
  4. Rotate authenticator if codes may have been phished; keep backup codes offline
  5. Review API keys and disable unexpected ones (API key basics)
  6. Tighten withdrawals / allowlists (withdrawal whitelist)
  7. Assume clipboard malware may rewrite addresses—re-verify every string character-by-character
  8. Write what happened so household members do not repeat it

Seed phrases and “wallet import” lies

Centralized exchanges should not need your self-custody seed phrase to “sync.” Any app that demands a recovery phrase to “verify your exchange account” is hostile until proven otherwise. Self-custody mistakes are covered in seed phrase backup mistakes and custody vs seed phrase.

Pairing scams that push fake apps

Real support is something you open yourself after a clean path:

Public support center orientation—start from a bookmark

Pre-login checklist on a new install

  • Publisher comparison notes written offline
  • App ID / package name checked against official docs when published
  • Authenticator 2FA preferred over SMS when available
  • First login on a network you trust
  • No seed phrase entry
  • Password manager autofill only engages on the correct domain

Bottom line

If the install path required a stranger’s link, treat the app as guilty until proven otherwise. Convenience is how phones get owned.

Install decision tree

  1. Did I start from my bookmark? If no, stop.
  2. Is the publisher name exact? If no, stop.
  3. Am I sideloading? If yes, require written justification stronger than “someone said so.”
  4. Does the app request accessibility or SMS? If yes without a crystal-clear reason, stop.
  5. After install, do security pages load as expected? If no, remove immediately.

Corporate-sounding but personal rule

No finance app installs after 10pm local time. Fatigue installs are attacker-friendly installs.

Store listing comparison worksheet

For any candidate app write: publisher string, first seen date, last update, install count band, permission list, whether you arrived from a bookmark, and a yes/no on sideload. If more than two fields are “unknown,” do not install.

Kids / shared phone note

Shared family phones are hostile for finance apps. Prefer a device you control exclusively for anything that can move funds. Shared Face ID / fingerprint profiles have caused messy authorization stories in households.

After OS major upgrades

Re-check app publisher identity and permissions. Major upgrades sometimes re-enable settings or confuse users into installing “helper” tools from search ads.

Pre-install scorecard (0–2 each)

Bookmark origin; publisher exact match; update recency; permission reasonableness; no sideload; no chat-sourced APK; security pages load after install. Score under 10 → do not put funds on that install.

Enterprise-personal policy template

Allowed stores only. No finance apps from search ads. Quarterly extension audit date: ____. Shared phones: no fund-moving apps. After OS upgrade: re-verify publisher and permissions within 48 hours.

Incident communication

If a family member installed a lookalike, do not shame first—contain first: remove app, clean-device password changes, session revoke, allowlist review, official support if needed. Shame delays reporting.

Red-team your own phone

Once a quarter, search your brand names in the store and screenshot the top lookalikes for private notes (do not install). Knowing what fakes look like today trains faster rejection tomorrow.

Closing practical standard

Re-read this guide only when calm. If you are about to act under urgency from a stranger, stop and open your bookmark first. Skill compounds from boring repetition—not from one heroic night of clicks. Last reviewed: 2026-07-27.

Educational only. Not investment advice.

Permission archaeology

After install, open system settings and list every permission granted. If you cannot explain a permission in one sentence tied to the product, revoke it or remove the app. Accessibility and SMS permissions deserve special skepticism for finance apps.

Additional operating notes

Write your own offline summary of this guide in ten bullet points before you act. If you cannot produce ten bullets without looking, you have not absorbed the process. Rehearse on a non-urgent day. Prefer bookmarked official domains, authenticator 2FA, and tiny tests before irreversible actions. When product labels change after app updates, re-open official documentation rather than relying on memory. Keep a dated note of what you verified. Refuse social urgency scripts. Measure costs in both asset units and cash terms. Stop sessions when emotion rises. Review weekly: what process failed, not only what price did. Skill is repetition of correct order of operations under calm conditions.


Educational content only. Not investment, legal, or tax advice. Digital assets can lose value. Re-check official pages via bookmark. Last reviewed: 2026-07-27. Learning path.