Skip to content
Sat, Jul 25, 2026
BTC $00,000 ETH $0,000 SOL $000
Your keys are yours — we never ask for them Live
Scam Alerts & Red Flags

Verifying Official Channels: The Check to Do Before You Click

Most reward scams do not break anything technical. They just get you to the wrong address. Here is the short verification habit that stops nearly all of them.

Verifying Official Channels: The Check to Do Before You Click

The uncomfortable truth about most crypto reward scams is that nothing gets hacked. No encryption is broken, no wallet is cracked, no clever exploit is deployed. Someone simply gets you to the wrong website, or into a conversation with the wrong person, and you do the rest yourself while feeling perfectly sensible about it.

That is good news, because it means the defence is not technical either. It is a habit that takes about twenty seconds, done in the same order every time, before you type anything or click anything that matters.

Read the domain, character by character

The address bar is the single most important piece of information on any page, and it is the piece people glance at least. A copied site can be pixel-perfect. The domain cannot be copied, only imitated.

So read it deliberately, slowly, one character at a time. Look for:

  • Swapped or doubled letters that the eye smooths over at a glance, particularly in longer brand names.
  • Look-alike characters from other alphabets or number-for-letter substitutions that render almost identically in many fonts.
  • Hyphens inserted into a name that does not normally contain one, or removed from one that does.
  • A different ending. The part after the final dot is not decoration. A familiar name on an unfamiliar extension is a different site with no relationship to the original.
  • Extra words bolted on, like a brand name followed by “-rewards”, “-claim”, “-airdrop” or “-support”.

The right-to-left trick

Domains are read by browsers from right to left, and so should you. Find the ending, then step backwards to the actual site name immediately before it. Everything to the left of that is subdomain, and anyone can put any words there. A well-known brand name appearing early in a long address means nothing at all if the real registered name sitting just before the ending is something you have never seen.

This one reading habit defeats a large share of impersonation pages by itself.

Arrive from somewhere you already trust

Verifying a domain works best when you already know what the correct one looks like. That is why how you arrive matters as much as what you read.

The safest route is one you established while nothing was happening: a bookmark you saved calmly, an app you installed deliberately, or a link from a reference source you already rely on. Build that set of bookmarks on an ordinary day, not in the middle of a claim window.

Treat these arrival routes as unverified until proven otherwise:

  • Search results and paid placements. The top slot is not a badge of authenticity, and impersonators buy visibility.
  • Links in messages, emails or comments, including replies to genuine posts from genuine accounts.
  • QR codes in images, screenshots or physical spaces, which hide the destination entirely until you have already travelled to it.
  • Shortened links, which do the same thing by design.

When something reaches you through one of those routes, do not click it. Note the name, then navigate to the site independently by your own trusted route and look for the same announcement there. If a genuine opportunity exists, it will exist on the official page too. If it only exists in the message, that is your answer.

Our radar lists programmes we have looked at and where their real presence lives, which gives you an independent second reference point.

Treat unsolicited help as hostile until proven otherwise

Here is a pattern worth memorising, because it holds up remarkably well: legitimate support does not message you first.

Post publicly about a wallet problem and you may receive several friendly private messages within minutes. They will use the right terminology, they will be patient and polite, and they will guide you towards a page, a form, a “validation” step or a “sync tool”. Some will be a support account whose display name matches the real one perfectly, because display names are free and can be anything.

What follows is always a request for something no genuine process needs: a recovery phrase, a private key, remote access to your screen, an upfront payment to unlock a withdrawal, or a signature on a transaction whose purpose is not explained.

Adopt a flat rule and hold it without exception: you contact support, support does not contact you. Anyone who reverses that direction has told you what they are. You owe them no politeness, no explanation and no reply.

Never let urgency do your thinking

Every manufactured element of a scam exists to shorten the gap between seeing and acting. Countdown timers. Limited allocations. A claim window closing tonight. A warning that your account will be suspended within hours. A wallet that must be verified immediately or lose access.

Urgency is not evidence of opportunity. It is the mechanism. A pressured decision is one made without checking, and checking is the only thing standing between you and the loss.

So put a rule between the feeling and the action: when you notice urgency, slow down instead of speeding up. Step away for ten minutes. Genuine reward programmes survive a ten-minute pause without harm. Fraudulent ones depend on you not taking it.

If a delay would genuinely cost you something real, that is precisely the situation the pressure was engineered to create.

The check, in order

Put together, the whole habit is short enough to run every time:

  • Notice that you are about to act on something you did not seek out.
  • Stop. Do not click the link that reached you.
  • Navigate independently, from a bookmark or a source you already trust.
  • Read the domain character by character, right to left.
  • Confirm the offer exists on the official page, not only in the message.
  • If anyone asks for a recovery phrase, a key, a fee or an unexplained signature, stop entirely.

You can run an offer past our scam checker as an extra step, and how we vet explains what we check and, honestly, what we cannot check. Our scam alerts section tracks the recurring patterns.

A last word on TokenSpin itself. We are informational only. We never ask you to connect a wallet, sign a transaction, approve a token or enter a recovery phrase, and nobody from TokenSpin will ever message you privately offering to help with your funds. If someone does, they are not us. Apply exactly the check above to any page claiming our name.

Get The Spin

The week's vetted rewards + the scams to avoid — free, every week. Informational. Not financial advice. We never ask for your keys.