Bybit's app and official channels: what's real

Updated 2026-08-28

Impersonation is the most common way people lose money around exchanges, and it is not close. Not hacks, not liquidations — a copy of an interface, presented at the moment someone was already looking for it. This guide is about making that attack fail structurally rather than by luck.

Why fakes keep appearing

Because it works, and it is cheap. A lookalike domain costs almost nothing. Cloning a login page takes an afternoon. Getting in front of people is the only real expense, and search results, social replies and messaging groups solve that.

The economics mean fakes will keep appearing no matter how many are taken down. Which is why the answer is a habit on your side, not a list on ours.

Finding the real website

Type the address yourself. Not a search result, not a link in a message, not a bookmark you created by clicking something once. Type it, then bookmark the page you arrived at and use the bookmark afterwards.

Read the address from right to left. The part immediately before the first single slash is the real domain — everything to the left of it can be anything the attacker wants, including the genuine brand name. This is the mechanic that fools people: a convincing brand name early in a long address means nothing at all.

A padlock icon proves only that the connection is encrypted. Attackers have encryption too. It says nothing about who owns the site.

Be especially careful with paid or promoted search results. A promoted position is bought, not earned, and impersonators buy it deliberately.

Finding the real app

Do not search an app store and install the top result. Store search rankings are gameable, and fake listings with plausible names appear regularly.

Navigate from the exchange's own website to the store link it publishes, and follow that. Once on the listing, sanity-check it: the developer name, the number of ratings, how long it has existed. A major exchange has an enormous review count and a long history. A recent upload with a few hundred ratings is not it, however good the icon looks.

Never install a package sent to you in a message or downloaded from a link outside the official stores. On Android in particular, sideloaded applications are the main distribution route for credential stealers, and the app will look exactly right — that is the entire point of it.

Recognising fake support

Genuine support responds to tickets you opened, through the platform. It does not appear in your direct messages, under your public post, or in a group chat offering to help.

Treat every one of these as an attack: an unsolicited message from "support"; a request for your password, seed phrase or authenticator codes; a request to install remote access software or share your screen; an offer to speed up verification or unlock a withdrawal for a fee; a request to move the conversation to another app; and anyone who creates urgency about your account.

Nobody legitimate needs your secrets. That single sentence covers the entire category, and it holds even when the person knows your name, your email and the amount stuck in your account — that information leaks from data breaches and from public posts, and it is used precisely to sound authoritative.

Withdrawal delays attract this behaviour more than anything else. If yours is delayed, read what actually delays withdrawals rather than describing your situation publicly.

We are not the exchange

This site is independent. It is not operated by Bybit, not affiliated with it, and does not act on its behalf. We cannot see your account, unlock it, speed up a review or recover funds. If you need the exchange, go to the exchange — and go there by typing the address, not by clicking us.

That distinction is a rule we hold ourselves to, and it is also a useful test to apply to any other site you land on: a page that presents itself as the official platform, or as able to act on your account, is either careless or hostile.

If you think you were caught

Act immediately and in this order. Change the password from a device you trust — if the current device may be compromised, use another one. Revoke active sessions. Delete API keys, particularly any with withdrawal permission. Check the withdrawal address whitelist and two-factor settings for entries you did not create, because an attacker's first move after entry is to add their own. Then contact support through a route you navigated to yourself.

Do not accept help from anyone who materialises afterwards offering recovery. The people who target victims a second time know exactly what happened to them the first time.

The durable habits

Type the address. Bookmark it. Get the app from a link on the site you typed. Assume anyone contacting you first is an impersonator. Never share codes or screens. Keep only working balances on any exchange — see how to judge exchange safety — so that even a bad day is survivable.

These are unglamorous and they work better than everything else combined.

Frequently asked questions

How do I check an app in the store is the real one?
Do not search the store name and pick the top result. Navigate from the exchange's own website to the store listing it links to, then confirm the developer name, the review count and the install history look consistent with a major platform rather than a recent upload.
Will support ever contact me first?
No. Genuine support responds to tickets you opened. Anyone who reaches you first in a direct message, a comment or a reply — however helpful they sound — should be treated as an impersonator by default.
Is it safe to install an app from a link someone sent me?
No, regardless of who sent it. Sideloaded packages and links from messages are the primary distribution route for credential-stealing fake apps. Navigate to the store yourself.
What should I do if I entered my details into a fake site or app?
Change the password from a device you trust, revoke active sessions and API keys, check the two-factor settings and withdrawal whitelist for changes, and contact real support through a route you navigated to yourself. Speed matters more than certainty.
Why does this site not publish a list of known fake domains?
Because such a list is stale within days and a wrong entry defames a legitimate business. Teaching the check is more durable than maintaining a list that gives false confidence.

Keep reading