Fake On-Ramp Sites: How the Cloned Checkout Works
A cloned exchange front end takes the payment and never delivers. How the clones are distributed, what they get right, and the checks that catch them.
Priya Raman · 2 min read
The cloned on-ramp is one of the most profitable frauds in crypto because it takes real money through real payment rails and returns nothing. The victim’s bank sees an ordinary card payment to a merchant. Read this against an on-ramp that publishes its limits, whose authorisation and permissions are on a public register you can check.
How the clone is built
The operator copies the visual design of a known exchange, registers a domain that reads correctly at a glance, and puts up a checkout that accepts card details or bank transfers.
What they usually do not copy is the licensing footer, the terms page, or the support system. Those take work and nobody checks them.
How you arrive at it
Three routes dominate.
Search advertising. The clone buys the brand name as a keyword. The advert sits above the real result. This is the most common route and the one people least expect, because a search engine feels authoritative.
A link from a support conversation. Someone contacts you about an issue and sends a link to resolve it. The link goes to the clone.
A comment or reply under a genuine post. Automated accounts reply under exchange announcements with a near-identical domain.
What tells you it is a clone
The domain, if you read it character by character rather than glancing. Substituted letters, an extra word, a different top level domain. For a fintech the exposure multiplies across users, and crypto rails built for fintech companies addresses it at that layer.
The absence of a verifiable licence. A real European provider names its regulator and its registration number, and you can find that entry on the regulator’s own register. A clone either omits it or lists a number that does not resolve.
The payment destination. A genuine provider takes card payments through a named payment institution and receives bank transfers in its own registered company name. A transfer to an individual’s account, or to a company with no relationship to the brand, is conclusive.
Pressure. Real on-ramps do not tell you a rate expires in ninety seconds unless it genuinely does, and they do not chase you to complete.
The check that costs nothing
Navigate to the provider yourself. Type the address, or use a bookmark you made previously from a source you trust.
Never arrive at a financial site from an advert, a message or a reply. That single habit removes the entire category.
If you already paid
Contact your bank immediately and describe it as a fraudulent merchant rather than a disputed purchase. Card payments are occasionally recoverable within a short window. Bank transfers rarely are.
Report the domain to the real provider. They maintain takedown processes and a report accelerates it.
What the real thing looks like
A provider that publishes its regulator and licence number, that receives payments in its own registered company name, and that you reached by typing the address yourself. Everything else is decoration. Whatever else you conclude, the balance you keep in motion belongs at a regulated crypto exchange rather than wherever onboarding was fastest.
Move any remaining funds to a wallet with a newly generated seed phrase before anything else. Then revoke token approvals, and report the incident to your local authorities and the exchange involved. Do not pay anyone who promises to "recover" your coins. That is a second scam, aimed at victims of the first.