Part of "Know the Scam by SimpleSwap." Clone sites are one of the most common ways people lose crypto to a brand they already trust. Here is how to tell the real simpleswap.io from a lookalike in about ten seconds, and why the one signal most people rely on is the wrong one.
A fake exchange does not need to fool you for long. It needs to fool you for one transaction. By the time the transfer confirms, the job is done, and on-chain there is no taking it back.
Clones are effective precisely because they copy the part you look at: the logo, the colors, the layout, the exchange form. What they cannot copy is the part most people don't look at closely enough, which is the address bar. So that is where a ten-second check lives.
The one thing that actually identifies us
Our only official website is:
simpleswap.io
That is the whole test. Not the logo, not the design, not the padlock. The domain. Everything after simpleswap.io/ can vary, but the part right before the first single / must read exactly simpleswap.io and nothing else.
Read the domain right-to-left from the first single slash: the last two pieces (simpleswap + .io) are what matter. If either is off, you're not on our site, no matter how right the page looks.
The 10-second check
-
Look at the address bar, not the page. The page is completely under the attacker's control. The URL is the one thing they can only imitate, never duplicate.
-
Read the ending. It must be .io. .org, .net, .app, .co, .com on their own are not us.
-
Read the name attached to it. Exactly simpleswap, one word, correctly spelt, with nothing hyphenated or added in front.
-
Zoom in if anything feels off. Homograph tricks use characters that look almost identical at a glance (a Cyrillic letter standing in for a Latin one). Zooming or clicking into the URL breaks the illusion.
If all three read clean - simpleswap · .io · nothing extra - you're home. That's the ten seconds.
One more signal, once you're in the flow. On the real site, the exchange screen carries an Anti-phishing check on the left of the swap flow. It's a second confirmation, and it arrives at exactly the moment it's worth having: when you're setting up a transfer rather than just browsing. Treat it as supporting evidence rather than the test itself, because the domain is still what decides. But a swap screen missing that panel is a reason to stop and re-read the URL before you touch anything else.
Why the padlock is not the check
This is the part most guides get wrong, so it's worth saying plainly.
The padlock icon (and the https://) only means the connection to the site is encrypted. It says nothing about who owns the site. Security researchers have found that the vast majority of phishing sites now display a valid SSL certificate and the padlock icon because certificates are free and can be obtained in minutes. A clone at simpleswap.org can display a perfect padlock while being a pure phishing page.
So: a missing padlock is a hard no, but a present padlock proves nothing on its own. The domain is the signal. The lock is not.
Build the habit that removes the check entirely
The fastest ten-second check is the one you never have to run:
-
Bookmark simpleswap.io once, from a URL you typed by hand, and open the exchange from that bookmark every time after. A bookmark cannot be misspelled and does not get hijacked by a search ad.
-
Don't reach us through search ads. Paid results and lookalikes can sit above the real organic link. If you must search, verify the domain before you interact.
-
Install our app only from links published on simpleswap.io itself.
-
Our support will never DM you first, and never needs your seed phrase. That's a different scam in the same family (fake support), covered elsewhere in this series.
If you spot a clone
Report it to our official support with the URL, a screenshot, and the date. That's genuinely useful: it lets the team pursue a takedown and warn other users. Recording the link, the screenshot, and the date is the same first step our own team takes when a fake surfaces.
And if you think you already interacted with one: a confirmed on-chain transfer can't be reversed by us or any exchange, so the priority is to stop further loss. Move any remaining funds from an affected wallet to a new one, revoke any approvals you granted, and never engage anyone promising to "recover" your funds for an upfront fee - that's the sequel scam.
The takeaway
A clone can copy everything on the page. It cannot become simpleswap.io. Check the domain, not the design, and trust the address bar over the padlock. Ten seconds, every time - or zero seconds, if you're opening your own bookmark.
What comes next
Each entry above will get its own breakdown in "Know the Scam by SimpleSwap" over the coming months. Follow #KnowTheScam to catch every new one as it drops - phishing kits, fake support DMs, drainer contracts, the whole map: new scam, same hashtag, one place to check.
This article is for educational purposes only and is not financial or legal advice. Our only official domain is simpleswap.io. Last updated: July 2026.