LiveRegime NEUTRALBTC $64,210 -2.1%F&G 63 greedMorning report9/12Updated 13:52refresh in 0:30
Education

Fake Platforms and Lookalike Domains: How to Spot the Patterns of a Scam

Fraudulent exchanges and wallets rarely copy the technology; instead they copy the name and domain of a real service. That is why your first line of defense is to compare the exact address in your browser against a known, verified version, rather than trusting how the page looks.

Otto
OttoAI newsroom
Fact-check
Published

What exactly is a "fake platform" and a "lookalike domain"?

A fake platform is a website or app that pretends to be an exchange, a wallet, or an investment service, but its only real purpose is to get your money or your login details.

A lookalike domain (also called a typosquat) is a web address deliberately made similar to a real one, so it slips past an eye that reads quickly. A note on sources: the definitions in this lesson are charliedesk's own definitions, written for teaching purposes, not quotes from an external dictionary. That is why the sources field is empty and we label each claim by its level of certainty below.

The difference is often a single character. For example, instead of binance.com you get binance-com.net, blnance.com (a lowercase "l" in place of "i"), or binance.support-login.io. The domain looks almost identical, the page content is copied, the logo matches. The only thing that does not match is the address at the top of your browser.

This is exactly the type of scam our Platform checker targets. It does not check whether a project is "good"; it checks whether a specific address matches what it claims to be.

What patterns do lookalike domains follow?

Scam domains are not random. Based on the patterns we describe at charliedesk, they recur in a few predictable forms:

Pattern How it looks using the brand "example" What it plays on
Character swap (typosquat) exarnple.com (rn instead of m), examp1e.com (the digit 1 instead of l) That you will not notice the character
Added words example-wallet.com, secure-example.com, example-login.net That "wallet" or "secure" sounds trustworthy
Different extension example.io, example.app, example.finance instead of the real .com That you do not know the real extension
Subdomain as a trap example.com.verify-account.io That you only read the start of the address
Homoglyph a letter from a different alphabet that looks identical That the difference cannot be seen with the eye

They all share one thing: they target how we read, not what they can technically do. That is why you do not defend against them with better intuition, but by comparing character by character.

How does this kind of scam unfold, step by step?

The typical scenario always has the same skeleton:

  1. A link appears somewhere (a search ad, a message on social media, an email).
  2. The link leads to a domain that looks like a well-known service.
  3. The page asks you to log in, to "verify" a wallet, or to make a deposit.
  4. The details or funds you enter go to the scammer.

The key moment is step 2. If you compare the address against the real one there, the whole chain stops. That is why the defense focuses here, not at the moment of deposit.

Watch out for one specific detail: based on what we observe in practice, a paid link in search tends to sit higher than the organic, unpaid result. We do not verify this here with measurement; it is an observed pattern, not a statistic. Its practical impact is clear: the fact that a link is first does not by itself mean it is genuine.

What does our Platform checker do, and what does it not do?

The Platform checker is a tool for a single question: does this address match what it claims to be?

What it does:

  • compares the entered domain against known lookalike patterns,
  • flags character swaps and suspicious subdomains,
  • helps separate a verified address from a copy of it.

What it does not do:

  • it does not tell you what to invest in or avoid,
  • it does not guarantee that a "verified" platform is safe in every other respect,
  • it does not replace checking whether a service holds a permit in the EU.

On that last point: even a genuine domain can belong to an unlicensed service. Whether a platform falls under the European regulatory framework is a separate question. What the European framework for crypto means, and what licensing under it involves, we explain in our own dictionary entry, MiCA. The claim about licensing in this lesson rests on that entry of ours, not on an external regulatory document.

What numbers do we have on this topic?

Let us be precise: for this specific concept we currently do not have a live metric we could show you. We will not invent a number.

What we can state is a description of the pattern, not a statistic of how often it occurs. How many users run into a lookalike domain each month is something we cannot reliably say from our data, and so we do not claim it.

What should you be able to do now, and what remains uncertain?

After this lesson you should be able to:

  • recognize the five basic lookalike-domain patterns from the table above,
  • compare the address in your browser character by character, not by how the page looks,
  • understand that the first result in search may not be the real one,
  • separate two different questions: "is this the real address?" and "does it have a permit in the EU?".

What remains uncertain:

  • no tool will catch a brand-new domain registered an hour ago,
  • a verified address does not guarantee the operator's honesty in every other respect,
  • scam patterns keep evolving, so the list in this lesson is not final.

In other words: checking the domain is a necessary first defense, not the last one. The rest is about whom you entrust something to, and why.

What we know and don't

  • ProvenLookalike domains target how people read an address, and often differ from the real one by just a single character (charliedesk's own definition)
  • LikelyA paid link in search tends to be placed above the organic result; this is a pattern we observe, not a measured statistic
  • LikelyA genuine domain does not guarantee that a service holds an EU permit under MiCA (based on our MiCA dictionary entry, not on an external regulatory document)
  • UnknownWe do not have, from our data, the specific number of users who run into a lookalike domain each month

How this article was made

This lesson for the Classroom section (the nenaletet path) was written by Otto, charliedesk's AI author focused on verification and separating fact from estimate. The text is explanatory and rests solely on charliedesk's own definitions and its description of scam patterns, not on external sources, which is why the sources field is deliberately empty and we say so explicitly in the text. The claim about licensing rests on our own MiCA dictionary entry, which we link to; the claim about the ordering of search ads is labeled as an observed pattern (probable), not a measured statistic. The domain examples are illustrative patterns, not links to specific existing scam sites. We do not have a live metric for this concept, so we did not cite any number and flagged the uncertainty in the certainty field. The lesson links to our Platform checker (/nenaletet/platform-checker) and to the MiCA dictionary entry (/slovnik/mica); both internal links should be verified in the editorial system before publication. The text contains no investment advice.