Exchange safety

How to spot fake Kraken emails

An email lands: “Your Kraken account is at risk — verify now.” It looks perfect: right logo, right tone, a login button. The button doesn't go to kraken.com — it goes to a copy built to capture your password and 2FA. This is the most common way Kraken users lose funds.

How fake Kraken emails work

Phishing emails create urgency (“account locked”, “suspicious login”, “withdrawal request”) and push you to a fake login page. The page forwards whatever you type — including your 2FA code — to the attacker in real time.

Signs an email is not really from Kraken

A link that doesn't point exactly to kraken.com; urgency and threats; requests for your password, seed phrase or 2FA; small misspellings in the sender domain.

What to do instead

  • Never click login links in emails. Open Kraken from your own bookmark of kraken.com.
  • Kraken will never ask for your seed phrase — no real exchange ever does.
  • Enable an authenticator app or hardware key, not SMS, for 2FA.
  • Use a browser extension that blocks fake Kraken login pages before they load.

Trust Line blocks fake Kraken pages

Even if you click a link, Trust Line recognises look-alike Kraken domains and stops the page loading — so a stolen click doesn't become a stolen account.

FAQ

Does Kraken send emails asking me to log in?

Kraken may send notifications, but you should never log in via an email link. Always open kraken.com from a bookmark instead.

Will Kraken ever ask for my seed phrase?

No. No legitimate exchange asks for your seed phrase. Any message that does is a scam.

خصوصية بحكم التصميم

Trust Line is a free browser extension that blocks fake versions of sites like this before they load and warns you about dangerous signatures on any site.

أضِفه إلى المتصفّح — مجّانًا