the Scam
A site that is not the site
The interface matches and the rate looks normal, but the domain is one character off and the deposit address is not SimpleSwap's.
Gives it away: The address bar settles it; design never does.
Read the breakdown →Know the Scam is the fraud-education project run by SimpleSwap. Rather than list threats alphabetically, this page follows the order in which an attack actually reaches you: first contact, then persuasion, then the action it needs.
That order matters because a scam, unlike a hack, cannot proceed without you. It has to make contact, build a reason, and ask for something. Each of those three moments leaves a signal.
Each links to its full write-up in Know Scam on the SimpleSwap blog.
The interface matches and the rate looks normal, but the domain is one character off and the deposit address is not SimpleSwap's.
Gives it away: The address bar settles it; design never does.
Read the breakdown →
Spelling mistakes and broken layouts have stopped being reliable signals. What arrives now looks like the genuine article.
Gives it away: Navigate from your own bookmark instead of a supplied link.
Read the breakdown →An attentive acquaintance over several weeks, then an investment platform whose balance grows and whose withdrawals stall.
Gives it away: When a personal connection routes to a trading site, that is the pattern.
Read the breakdown →
Video of a recognisable figure offering to return double. The face is synthetic; the address is real.
Gives it away: Nothing legitimate requires you to send first.
Read the breakdown →
Impersonators monitor public questions and reply faster than anyone real.
Gives it away: Support does not arrive uninvited, and never wants a seed phrase.
Read the breakdown →
The sell path is blocked in the contract, or liquidity disappears once enough buyers arrive.
Gives it away: Check for successful sells before committing.
Read the breakdown →
Scripts and codes promising SimpleSwap rewards, built to take credentials or a signature.
Gives it away: Rewards never require pasting code or connecting a wallet.
Read the breakdown →
Unexpected balances appear; claiming them means signing on a site built to drain.
Gives it away: Unrequested tokens are bait, not luck.
Read the breakdown →
The prompt looks routine. What it grants is ongoing permission to move tokens, used later.
Gives it away: Approvals are permissions. Review and revoke them.
Read the breakdown →
Pending transactions are public. Bots position around yours and take the spread.
Gives it away: Narrow slippage limits how much can be taken.
Read the breakdown →
The first and last characters match an address you trust. The middle does not.
Gives it away: Copy from source, verify the middle.
Read the breakdown →
The address you copied is replaced before it reaches the field.
Gives it away: Re-read the pasted address in full, every time.
Read the breakdown →Six signals that show up at contact, at persuasion and at the moment of action alike.
Any other domain carrying the name is a copy, however exact the interface.
Logos, colours and layout clone in minutes. The domain does not.
HTTPS encrypts the connection. Phishing sites hold valid certificates too.
Standard swaps never require one, and never a seed phrase.
An account that contacts you first did not come from SimpleSwap.
Once confirmed there is no chargeback, so the check belongs before you send.
These summaries condense the SimpleSwap Safety Academy, where each pattern is documented with current examples.