Fake Decentralized Applications

Scammers create fake applications that look like legitimate services. Their main trick is showing a well-known website address in the TON Connect window while actually operating from a different domain.

How does it work?

Users see that they're connecting to an app at example.app, but the connection is actually going to fake-example.app—scammers use this domain spoofing to steal users' funds.

How to stay protected?

MyTonWallet automatically checks whether the address user sees matches where the connection is actually going. If something's wrong—a warning will pop up in TON Connect.

What to do when a warning appears?

If you see a warning about a suspicious decentralized application, make sure you're actually working with the original dapp.

If you have any doubts or discover it's a fake—cancel the current action.

Last updated