How to spot fake Kraken emails
How fake Kraken emails work
Phishing emails create urgency (“account locked”, “suspicious login”, “withdrawal request”) and push you to a fake login page. The page forwards whatever you type — including your 2FA code — to the attacker in real time.
Signs an email is not really from Kraken
A link that doesn't point exactly to kraken.com; urgency and threats; requests for your password, seed phrase or 2FA; small misspellings in the sender domain.
What to do instead
- Never click login links in emails. Open Kraken from your own bookmark of kraken.com.
- Kraken will never ask for your seed phrase — no real exchange ever does.
- Enable an authenticator app or hardware key, not SMS, for 2FA.
- Use a browser extension that blocks fake Kraken login pages before they load.
Trust Line blocks fake Kraken pages
Even if you click a link, Trust Line recognises look-alike Kraken domains and stops the page loading — so a stolen click doesn't become a stolen account.
FAQ
Does Kraken send emails asking me to log in?
Kraken may send notifications, but you should never log in via an email link. Always open kraken.com from a bookmark instead.
Will Kraken ever ask for my seed phrase?
No. No legitimate exchange asks for your seed phrase. Any message that does is a scam.
Trust Line does the checking for you
Trust Line is a free browser extension that blocks fake versions of sites like this before they load and warns you about dangerous signatures on any site.
Add to browser — free