CoinMarketCap is a widely used Research service on multi-chain, which makes it a favorite target for phishing. This post breaks down exactly how CoinMarketCap scams work so you can recognize them instantly.

Step 1: the bait

It starts with a link — an ad at the top of search results, a reply from a fake support account, or a message in a group chat. The link points to a domain that looks like coinmarketcap.com but is not it: extra words, swapped letters, or an unusual ending.

Step 2: the perfect copy

The fake CoinMarketCap page is a pixel-perfect clone. Everything looks right, so you connect your wallet without a second thought. This is where the trap closes.

Step 3: the malicious signature

Instead of a normal connection, the site asks you to sign a transaction or approval. On a real CoinMarketCap this might be routine — on the clone it is a drainer that grants the attacker permission to move your tokens or NFTs. Once you approve, your assets are gone.

The CoinMarketCap phishing checklist

  • Confirm the domain is exactly coinmarketcap.com — nothing more, nothing less.
  • Never reach CoinMarketCap through an ad or a link someone sent you.
  • Read every signature request. Reject anything granting broad or unlimited access.
  • Never enter your seed phrase — CoinMarketCap will never ask for it.
  • If connecting via WalletConnect, verify the request matches the real site.

How Trust Line protects you on CoinMarketCap

Trust Line blocks known CoinMarketCap phishing clones before they load, and on any site it decodes the signature you are about to make — warning you in plain language if it is a drainer, before you approve.