نسخهٔ فارسی

Transparent, non-custodial, yours

The clone is perfect. The domain is not.

Crypto phishing copies the real site exactly and changes only the address. Where the traffic comes from, and the one habit that defeats all of it.

What is cloned The entire front end — the page is genuinely identical
What differs The domain, and the transaction the page builds
Arrival channel A link sent to you, in almost every case

FBT Swap

What you should know

A phishing site for a crypto interface is usually a byte-for-byte copy of the real front end with the transaction logic replaced. Nothing on the page is wrong, because the page is the real page.

The only difference is the address bar, which is why every effective defence is about how you arrive rather than what you see.

How people arrive at the clone

Paid advertisements above genuine search results. Replies and quote-posts under official announcements. Compromised community servers posting a "new domain". Direct messages from accounts that copied a real profile. QR codes in images.

Notice what these share: in every case the link came to you. Almost nobody reaches a phishing site by typing an address they already knew.

The lookalike domain tricks

Character substitution that is hard to see at a glance, extra hyphens, a different top-level domain, a subdomain arrangement that puts the real name where the path should be, and internationalised characters that render identically to Latin ones.

Reading a domain carefully once is far more reliable than trying to spot these under time pressure.

The habit that works

Reach the site from your own bookmark, created from an address you verified once. Never from a message, an advertisement or a search result. If you must search, verify the domain before connecting anything.

FBT Swap has exactly one official domain: fbtswap.ir. Any other address using the name is not us, including addresses that look like a regional or backup version.

If you already connected

Connecting alone grants nothing. Check whether you approved any transaction or signed any message; if you did, assume the permission is live. Move assets to a fresh wallet, then revoke allowances on the old address.

Do not use a "revoke" link provided by the same source. Navigate to the explorer or a revocation tool by typing the address yourself.

At a glance

At a glance

What is cloned

The entire front end — the page is genuinely identical

What differs

The domain, and the transaction the page builds

Arrival channel

A link sent to you, in almost every case

Our only domain

fbtswap.ir

FAQ

Frequently asked questions

Clear answers before you decide.

Does HTTPS mean a site is genuine?

No. A padlock means the connection is encrypted, not that the operator is honest. Phishing sites have valid certificates as a matter of course.

Is a top search result safe?

Not necessarily, especially if it is an advertisement. Paid placement above organic results has been used repeatedly to serve crypto phishing, and the ad label is easy to miss on a phone.

What if the clone is on a domain that looks official?

Compare it character by character against the address you verified. If it differs in any way at all, it is a different site, regardless of how plausible the difference seems.

Risk notice

Crypto assets are volatile and on-chain transactions cannot be reversed. You can lose money, including all of it. Nothing here is financial advice.