Swap security

How to verify an aggregator website without trusting a search ad

Verify the real application domain and contract request when search ads or copied swap interfaces look convincing.

A polished swap interface and a secure-connection icon do not establish that a website belongs to the protocol you intended. Verify the domain independently before connecting, then verify the actual signing request.

Establish the official starting point

Use a known genuine project website or an independently verified official documentation link. Inspect the complete domain, including spelling and subdomain structure. A brand name embedded somewhere in a longer address is not necessarily the brand’s domain.

Ethereum’s security guidance discusses phishing risk, while MetaMask’s authenticity guidance illustrates checking against official product sources. Search placement and paid advertising are discovery mechanisms, not identity guarantees.

Verify after navigation too

Look at the final address after redirects. A copied front end can reproduce colors, token lists and documentation links while changing the spender or recipient in a signing request.

Compare any approval spender with the protocol’s official chain-specific deployment information. A previously bookmarked domain is useful, but bookmarks do not protect against a later compromise of a genuine front end.

Do not use appearance as the final test

Grammar mistakes can be clues, but excellent design can also be copied. A valid TLS certificate encrypts the connection to that domain; it does not certify the owner’s honesty or contract safety.

If you reached a suspicious site but signed nothing, leave and inspect wallet activity if uncertain. If you approved or signed, investigate that authorization specifically rather than assuming closing the page removed it.

Sources & verification (3)

Source-check date is recorded in the article details. URLs are provided for manual verification. Use Copy to keep this page open.

  1. Ethereum security and scam prevention

    Secret protection, phishing, address checks and public-key custody hygiene.

    https://ethereum.org/security/
  2. How to verify the real MetaMask wallet

    Official installation provenance and fake-wallet phishing risks.

    https://support.metamask.io/stay-safe/safety-in-web3/how-do-i-recognize-the-real-metamask-/
  3. Contracts | 0x Docs

    Allowance targets differ from execution entry points; 0x warns against allowances to Settler.

    https://docs.0x.org/docs/core-concepts/contracts

Continue reading

A familiar swap interface can still request an unfamiliar spender How to verify the spender before approving an aggregator