A fake exchange email is a message designed to look like it came from a crypto exchange, built to steal your login details or your two-factor code. The most important thing to know: no legitimate exchange emails you a link asking you to 'verify' or 'unlock' your account. If a message pressures you to act now, treat it as hostile until you have checked it independently.
This article takes a typical credential-harvest attempt apart line by line. Each part of the email — the sender address, the greeting, the urgency, the link, the sign-off — carries a tell. Learn the tells once and they repeat across nearly every phishing email you will ever receive.
What is phishing, in plain terms?
Phishing is a scam in which an attacker pretends to be someone you trust — a bank, an exchange, a colleague — and tricks you into revealing sensitive information or installing malware. Wikipedia describes it as a form of social engineering: the attack targets human judgement rather than software weaknesses. The word plays on fishing, because the fraudulent message is the bait.
The scale matters for context. IBM reports that phishing is the most common data breach vector, accounting for 15% of all breaches, with breaches caused by phishing costing organizations an average of USD 4.88 million. Crypto holders are one target among many, but a stolen exchange login can mean money gone for good, because transfers on a blockchain are not reversible.
Line 1: the sender address
Open the email and read the actual sender address, not the display name. The display name can say anything — 'Exchange Support' — because it is just text the sender typed. The real tell is the domain after the @ sign.
A fake typically uses a lookalike domain: extra letters, swapped characters, or a real brand name bolted onto an unrelated ending. Wikipedia's annotated example of a phishing email lists a fraudulent but similar domain name for the sender as the first feature to check, alongside incorrect branding and spelling errors. Read the domain letter by letter. Slow down — Microsoft Security advises exactly that: examine hyperlinks and senders' email addresses before clicking anything.
One caveat: a correct-looking sender address is not proof of legitimacy. Sender addresses can be spoofed. A clean address lowers suspicion; it should never remove it.
Line 2: the greeting and the story
Next comes the greeting. 'Dear Customer' or 'Dear User' is a red flag. A service that actually holds your account knows your name. Generic greetings appear because the same email is being sent to thousands of people at once.
Then the story. According to the US Federal Trade Commission, phishing messages commonly claim suspicious activity or log-in attempts that did not happen, a problem with your account or payment information that does not exist, or a need to confirm personal or financial information that you do not actually need to confirm. Other common stories include an invoice you do not recognise, a coupon, or a government refund you are supposedly eligible for.
The story is the payload. Everything before it is set dressing; everything after it is the mechanism for harvesting your credentials.
Line 3: the urgency
'Your account will be permanently deleted in 24 hours.' 'Unauthorised access detected — act now.' Urgency is not a service style; it is a technique. Microsoft Security describes the pattern plainly: attackers build trust by impersonating a familiar source, then create a false sense of urgency and exploit fear and anxiety so you act before you think. The FTC's advice is to be cautious of any message that requires you to 'act now', because it may be fraudulent.
Think of it like a checkout queue with a countdown clock — the analogy breaks down here: a real countdown would come from a system you can verify, not from a message demanding you click first and think later.
Line 4: the link, and where it really goes
The link is the trapdoor. On a computer, hover over it without clicking and read the destination URL in the corner of your browser window. On a phone, press and hold the link to preview the address. If the visible text says 'exchange.com' but the destination reads something else entirely, you have your answer.
Wikipedia's annotated example lists the fake link as a core feature of a phishing email. The destination is usually a counterfeit login page that collects what you type. Some attacks go further: Wikipedia describes adversary-in-the-middle phishing, where an impostor site relays your login — including a one-time two-factor code — to the real service in real time. That is why a code from an authenticator app or text message is not, by itself, proof a page is genuine.
If you want a second opinion on a site before you trust it, our guide on how to verify a crypto website is real walks through the checks.
Line 5: the sign-off and the attachments
A vague sign-off ('Security Team'), a missing company address, or an unexpected attachment all belong on the same list. Microsoft Security notes that malware is often disguised as a trustworthy attachment such as a resume or a bank statement. An attachment you did not ask for is not a document; it is a delivery mechanism. Do not open it.
Real exchanges also have habits phishers cannot copy. They do not ask for your password or seed phrase by email. They do not need you to 'confirm' your wallet. If a message asks for either, it is a scam, full stop.
What this means: a checklist you can run in 30 seconds
Our analysis of the source material is that nearly every phishing email fails at least two of these checks. Run them in order:
- Sender domain: read it letter by letter, not the display name.
- Greeting: generic 'Dear User' means bulk send.
- Story: suspicious activity, account problems, or verification requests you did not trigger.
- Urgency: deadlines and 'act now' pressure.
- Link: hover or long-press and compare the real destination.
- Ask: does any real exchange ever request a password, seed phrase, or payment 'confirmation' by email? No.
If any check fails, do not click. Contact the company using a phone number or website you already know is real — the FTC is explicit that you should never use the contact details inside the suspicious message itself.
If you already clicked
Move fast, and in this order. Change the password on the affected account from a device you trust, and change it anywhere you reused that password. Revoke anything the attacker could reach: for exchange accounts, that means sessions and API keys. The FTC advises running a security scan if you clicked a link or opened an attachment that may have installed software.
If the compromised account touched a self-custody wallet, the situation is different and worse: a seed phrase typed into a fake site is compromised permanently. Our guide on what to do if your wallet is compromised covers the recovery sequence. And if the attempt came by text or call instead of email, the same anatomy applies — Wikipedia documents these variants as smishing and vishing, and our piece on SIM swap attacks explains the phone-based version.
You can also report what you received. The FTC recommends forwarding phishing emails to the Anti-Phishing Working Group at [email protected], forwarding scam texts to SPAM (7726), and reporting at ReportFraud.ftc.gov. Reporting does not recover losses, but it helps filters and investigators catch the next batch.
The takeaway
A fake exchange email is not clever; it is formulaic. Similar domain, generic greeting, invented problem, false deadline, poisoned link. The FTC notes scammers keep updating their stories to follow the news, but the underlying structure stays the same. Learn the structure once, and the next email — whatever brand it wears — reads as exactly what it is.
One honest caveat to close on: phishing works on careful people too. In a field experiment Wikipedia cites, 43% of participants clicked at least one simulated phishing link over 21 days. Falling for one is not a character flaw; it is the expected outcome of a well-made lure. The defence is the habit, not the IQ.




