Trading Bot Scams: 9 Checks That Expose a Fake Platform
Fake trading bots copy every visual cue of a real broker, but they cannot fake their own infrastructure. Nine WHOIS, hosting, DNS and regulator checks that expose a fake platform in ten minutes.
A trading bot scam does not have to fool you about trading. It only has to fool you about one thing: that there is a real company on the other side of the deposit button. Everything the operator controls directly - the website, the profit dashboard, the testimonials, the license number printed in the footer - is content, and content is cheap. What they do not control is the public record their own infrastructure leaves behind. When the domain was registered, which network hosts it, where the server physically sits, whether their mail passes authentication: those facts are recorded by third parties who have no stake in whether you deposit, and every one of them is visible before you send a single payment.

This article is about reading that record. It is not a list of warning signs to memorize, because warning signs change faster than anyone can publish them. It is a repeatable ten-minute check you can run on any platform, using lookups that are free and require no account with the company you are investigating.
Why the front end tells you nothing
The most persuasive part of a fake trading platform is the part that costs the least to build. That inversion is the whole reason these scams work, and it is worth sitting with for a moment.
Consider what a trading dashboard actually is. It is a web page that displays numbers. On a real platform those numbers come from positions held at a broker, reconciled against a market. On a fake one they come from a database column the operator can edit. There is no market connection to fake, because there was never a market connection. The rising equity curve, the trade history, the win rate, the little green arrows - all of it is a rendering job, and the same rendering job whether the underlying number moves because of a currency pair or because somebody typed it.
This means the quality of the interface carries no information about the legitimacy of the operation. A polished, responsive, professional-feeling dashboard tells you the operator hired a competent front-end developer or bought a template. Entire scam platforms ship as commercial kits: the same layout, the same charting library, the same onboarding flow, rebranded per deployment. When you notice that two unrelated platforms feel oddly similar, you are usually looking at two instances of one product.
The supporting material is equally cheap. Team photographs come from stock libraries. Press logos are copied from the sites they claim coverage from. Testimonials are written to order. License numbers are the easiest of all, because a license number is just a string, and almost nobody checks a string against the register it supposedly came from. We will come back to that, because checking it is the single most valuable thing in this article.
There is one element of the experience that is genuinely real, and it is the one pointing the wrong way: the payment rail. The deposit works. The money leaves your account and arrives somewhere. That single working mechanism does a great deal of persuasive work, because it feels like proof that the rest of the machinery is connected to something. It is not. Taking a payment is the easiest thing on the internet.
What a real trading bot actually does
Automated trading is a real thing, which is exactly why the scam works. If the whole category were fictional the pitch would collapse on contact. Grid and dollar-cost-averaging bots are built into several mainstream exchanges. Copy-trading platforms let you mirror another account. Expert Advisors have run on MetaTrader for two decades. People use these, and some of them work.
What separates the genuine article from the pitch is not sophistication. It is what the product is willing to admit. Real automated strategies lose money regularly. They have losing months. They have drawdowns - periods where the account is worth less than its previous peak - and anyone selling one seriously will show you the worst drawdown on record, because that number is what determines whether you can live with the strategy. They charge a subscription, a spread, or a share of real profits at a real broker, and they tell you plainly that past results do not predict future ones.
Now look at what the fake version claims, because the claims themselves are diagnostic before you check a single DNS record.
A smooth equity curve is a warning, not a selling point. Genuine returns are jagged. A line that rises at a steady angle with no meaningful dips is not describing market exposure; it is describing something that pays a fixed rate, which is a loan or a Ponzi structure rather than trading.
A win rate near 100 percent usually hides its losses rather than avoiding them. This one is worth understanding properly, because it also catches real but dangerous products. Martingale and grid strategies never close a losing position - they open more in the same direction and wait for a reversal. On paper this produces a long string of small wins and almost no losses, right up until a move that does not reverse takes the entire account in a single session. A very high win rate is therefore evidence about how losses are being accounted for, not evidence that the strategy is good.
A backtest is a claim about the past, and it can be manufactured. Any strategy can be tuned until it performs beautifully on historical data it was tuned against. That is called overfitting, and it is the default outcome rather than a rare failure. The meaningful question is whether there is a forward record - results produced after the rules were fixed, on money that was actually at risk.
Ask who verified the track record. Serious operations publish third-party verified account statements, where the reporting service connects to the broker directly and the trader cannot edit the numbers. Screenshots are not verification. A PDF is not verification. If the only evidence that the returns exist is the platform showing you its own dashboard, then the returns and the dashboard are the same artifact.
How the scam actually runs
Understanding the sequence matters because each stage has a different purpose, and only one of them is where the operator makes money. Recognizing which stage you are in tells you how much time you have.
| Stage | What you experience | What is actually happening |
|---|---|---|
| Contact | An ad, a message from a stranger, or a friend whose account was taken over mentions an automated trading system. | You are being sorted into a list of people who replied. Replying is the only qualification that matters at this stage. |
| Onboarding | A polished dashboard, a license number, a named account manager, and a small first deposit. | The deposit amount is chosen to be low enough that losing it would not make you go to the police. |
| The winning phase | The balance rises steadily. A small withdrawal succeeds quickly. | The balance is a number in a database. The small withdrawal is paid out of your own deposit as proof the system works. |
| Escalation | Pressure to deposit more before a market window closes, often with borrowed money or retirement savings. | This is the only stage that generates real revenue. Everything before it was an unpaid setup cost. |
| The wall | Withdrawals stop. You are told to pay tax, a release fee, or a compliance charge first. | There is nothing to withdraw. The fee is a second extraction from someone already proven to pay. |
| Recovery | A firm contacts you offering to trace and recover the lost funds for an upfront fee. | Frequently the same operation, or a buyer of their victim list. Losing money once puts you on a more valuable list. |
Two rows in that table deserve expansion, because they are where otherwise careful people get caught.
The successful small withdrawalis the most effective single element in the entire scheme, and it works precisely because it is real. You ask for a modest sum, it arrives in your account, and the question you were quietly holding - can I actually get money out of this - appears to be answered. It is not answered. You have been paid a fraction of your own deposit back. From the operator's point of view this is a marketing expense with an outstanding return, because a person who has successfully withdrawn once will deposit substantially more the second time, and will defend the platform to friends and family who express doubt.
The withdrawal wall is where the model actually earns. Notice that the demand is never framed as a payment to the platform. It is a tax obligation, a regulatory release fee, a compliance charge, an anti-money-laundering deposit, an insurance requirement. The framing does two things at once: it makes the demand sound like it comes from an outside authority rather than from them, and it gives you a story in which paying is the responsible thing to do. If you pay it, there will be another one. There is no sequence of fees that ends with a withdrawal, because there is nothing to withdraw.
The recovery stage is the cruelest part and the least discussed. Being defrauded once moves you onto a list that is worth more than a list of untested strangers, because everyone on it has demonstrated both that they have money and that they can be persuaded to send it. That list gets sold, and sometimes it is not sold at all - the same operation comes back wearing a different name, offering to recover what it took.
Four shapes this fraud takes
The sequence above describes the custodial version, where the platform holds the money and the balance is fiction. It is the most common shape and the one most guides describe, but it is not the only one, and the others fail in ways the custodial checklist does not catch. It is worth knowing which one you are looking at, because the defense differs completely.
| Shape | Where your money sits | How the loss happens | The control that matters |
|---|---|---|---|
| Custodial fake platform | On their platform, according to their dashboard | The deposit is spent on arrival. The balance was only ever a display. | Infrastructure and regulator checks before the first deposit |
| API-connected bot | In your own account at a real exchange | The key is used to trade against you, or to move funds out entirely. | API key permissions and an address allowlist |
| Signal or pump-and-dump bot | In your own account, in real positions | You buy an inflated price so that somebody else can sell into you. | Refusing to trade on timed calls from anonymous groups |
| Subscription grind | In your own account, or with a broker | Fees accumulate while the strategy quietly underperforms holding cash. | A verified forward record and a cancellation path you have tested |
Notice that only the first row involves sending money to the operator. In the other three your funds stay at a real exchange or broker the whole time, which is exactly why they work on people who have already learned not to wire money to strangers. Nothing about connecting a bot feels like paying anyone.
The two middle rows deserve particular attention. The pump-and-dump variant does not steal from you directly at all - it recruits you as the buyer. A coordinated group accumulates a thinly traded asset, promotes it, and sells into the demand that promotion creates. If your bot is following their signal, you are not a customer of the strategy; you are the exit liquidity for it. Worth knowing too that participating in coordinated market manipulation is illegal in most jurisdictions regardless of whether you understood what you had joined.
The subscription grind is the hardest to recognize as fraud, because there is no dramatic moment. Nobody disappears. The bot runs, the fees come out monthly, and the returns hover somewhere between mediocre and negative. Ask two questions of any recurring-fee product: whether there is a verified forward record covering the period you would be paying for, and whether you can find and complete the cancellation flow before you subscribe rather than after.
When the bot connects to your own exchange
This is the variant most worth understanding in detail, because the defense is technical, specific, and almost entirely within your control.
An API key is a credential that lets software act on your exchange account without your password or your second factor. Every serious exchange lets you scope what a key may do, and the scoping is the whole game. Broadly the permissions are read, trade, and withdraw.
Never enable withdrawal. No trading strategy requires it. A bot that trades needs to place orders, cancel orders and read balances, and nothing beyond that. Any vendor explaining that withdrawal access is needed for rebalancing, margin management, profit distribution or tax handling is describing the theft in advance. This single setting separates an account that can lose money from an account that can be emptied.
Bind the key to an address allowlist. Most exchanges let you restrict a key so it is only accepted from specific source addresses. This is the strongest control available to you, because a stolen key is inert from anywhere else - and keys do leak, through breached vendors far more often than through anything you did. There is a second benefit that costs the vendor nothing to provide and tells you a great deal: they have to tell you which addresses their bot runs from. An operation running defined infrastructure answers that immediately. An operation that cannot answer it, or asks you to leave the key open to the whole internet for convenience, has told you what kind of setup it is. You can put the addresses they give you through an ASN lookup and see whether the answer matches the company they claim to be.
Trade-only is not the same as safe. This is the part that gets skipped, and it matters. A key with no withdrawal permission can still drain an account in a thin market. The operator places orders on the other side of a shallow order book and uses your key to trade into them at deliberately bad prices. The value leaves as realized trading losses rather than as a withdrawal, every transaction is a genuine trade, and the exchange sees nothing unusual because nothing unusual happened - you authorized trading and trading is what occurred. The signals to watch are a bot touching pairs with very little volume, trading far more frequently than the described strategy would explain, or consistently taking the worse side of a spread.
Segregate the funds. Use a dedicated account, or a sub-account where your exchange supports them, holding only the capital you have decided to put at risk. Most exchanges allow separate API keys per sub-account. This converts a catastrophic outcome into a survivable one and costs nothing but a few minutes of setup.
Know how to revoke before you need to. Find the key revocation page on your exchange and use it once, on a test key, so that you are not learning the interface during an incident. Review the list of active keys periodically and delete anything you do not recognize or no longer use. Revoke on suspicion rather than on proof; a key you are unsure about is a key you do not want.
The infrastructure checks in the next section still apply here - you should absolutely establish who the vendor is before handing them anything. But understand that the recovery position is different and worse. Trades you authorized are not unauthorized transactions, so there is no chargeback and no recall to request. Prevention is close to the entire defense.
How the approach reaches you
Almost nobody finds these platforms by searching for them. The approach arrives, and the channel it arrives through is part of the design.
A message from someone you know. Compromised social accounts are used to message the contact list, because a recommendation carries the trust of the account it came from. The friend whose account it is often has no idea. If someone you know suddenly mentions a trading opportunity, contact them another way and ask.
A long conversation that was never about trading. The approach that takes the largest sums usually begins on a dating or messaging app and spends weeks or months building an ordinary relationship before investing is mentioned at all, framed as something the other person does rather than something they are selling. The duration is the point: by the time money is discussed, doubting the platform means doubting a person you have grown to trust.
Endorsements that were never given. Synthetic video and audio of public figures endorsing trading systems are now cheap to produce and widely circulated through paid advertising. A recognizable face saying the words is no longer evidence that anyone said them. Treat any celebrity endorsement of an investment product as manufactured until the person confirms it on a channel they control.
The common factor is that all three route around your judgment by borrowing credibility from something you already trust - a friend, a relationship, a familiar face. That is why a mechanical checklist works better here than instinct. The checks below do not care who made the introduction.
Nine infrastructure checks you can run in ten minutes
Here is the core of the method. None of these require an account, a download, or any contact with the platform. You need only the domain name. Run them before the first deposit, because afterwards you are no longer evaluating a decision - you are defending one you already made, and that is a much harder thing to do honestly.
| Check | Tool | Established platform | Worth walking away from |
|---|---|---|---|
| Domain age | WHOIS lookup | Registered years before it asked you for money | Registered weeks ago, or an expiry date under twelve months away |
| Registrant identity | WHOIS lookup | A named company matching the one on the site | Privacy shield on a firm that claims to be regulated and audited |
| Server location | IP location | Consistent with the stated head office and license jurisdiction | A different continent from every address printed on the site |
| Hosting network | ASN lookup | Enterprise cloud or a named financial hosting provider | Budget VPS reseller, or a network with a documented abuse history |
| Reverse DNS | Reverse DNS lookup | A dedicated hostname on infrastructure the company controls | A generic provider hostname shared with hundreds of unrelated sites |
| Blacklist status | IP blacklist check | Clean across the major DNSBL feeds | Listed on multiple independent feeds for spam or phishing |
| Mail origin | Email header analyzer | Mail sent from the same domain and infrastructure as the platform | Free webmail, or a sending server unrelated to the brand |
| Mail authentication | DNS lookup | SPF, DKIM and DMARC records published and enforcing | No DMARC record, or a policy set to take no action |
| Domain neighborhood | Reverse DNS and IP location | Few related domains, all belonging to the same brand | Dozens of near-identical sites on one address under different names |
1. When was the domain registered?
Run the domain through a WHOIS lookupand read the creation date. This is the highest-value thirty seconds available to you, because a domain's registration date is recorded by the registry at the moment of purchase and cannot be backdated afterwards.
The test is not that new domains are bad. New legitimate businesses exist. The test is whether the registration date is consistent with the story the site tells about itself. A platform whose About page describes a decade of algorithmic trading experience, operating on a domain registered four months ago, has contradicted itself in a way that has no innocent explanation. Either the company is much younger than it claims or it recently abandoned a previous domain, and both are worth knowing.
Read the expiry date as well, which people usually skip. Businesses that expect to exist in five years register domains for multiple years at a time, because it is cheaper and because losing the domain would be catastrophic. An operation that expects the domain to be burned and replaced buys the minimum term. A creation date and an expiry date exactly twelve months apart, on a company asking for your retirement savings, is a statement about how long they expect this name to last. Our guide to what WHOIS records contain covers the other fields in more depth.
2. Who registered it?
The same lookup shows the registrant. Most domains today sit behind a privacy service, and for an individual that is entirely reasonable - publishing your home address because you own a domain is a bad trade.
But apply it to the claim being made. A company presenting itself as a regulated financial institution, publishing a corporate address and a license number, has already decided to be publicly identifiable. Hiding the registrant contradicts its own positioning. Regulated firms are generally quite happy to be found, because being findable is a precondition of being trusted with money. Where an organization field is present, check that it matches the trading name; a mismatch is not proof of anything by itself, but it is a thread worth pulling.
3. Where is the server?
Resolve the domain and run the address through an IP location lookup. Compare the result against the head office address on the site and the jurisdiction of the license it claims.
Be careful with this one, because it produces false alarms if you read it crudely. Most serious sites sit behind a content delivery network, so the address you resolve is frequently the CDN edge nearest to you rather than anything the company owns. That is normal and is not a finding. The useful question is not whether the location matches the head office but whether the answer is explicable. A CDN edge in your own country is explicable. A single origin server in a jurisdiction with no connection to any address on the site, for a firm claiming a European license, is not. Our explainer on how IP geolocation works and where it goes wrong is worth reading before you lean on this check.
4. Who hosts it?
An ASN lookup resolves the address to the network that operates it. This is more informative than raw location, because it tells you what kind of organization the platform chose to depend on.
Financial platforms that intend to survive have obligations that shape this decision: uptime commitments, data residency requirements, audit trails, and the practical need for a provider who answers the phone. That pushes them toward major cloud providers and specialist financial hosts. An operation that expects to be reported and taken offline optimizes for something else entirely - a provider that is slow to act on abuse complaints and cheap to walk away from. If the ASN belongs to a budget reseller, or to a network with a documented history of ignoring abuse reports, that is a deliberate choice by someone. Our guide to autonomous system numbers explains what the result is actually telling you.
5. What does reverse DNS say?
A reverse DNS lookup asks what hostname an address claims for itself. Organizations that run their own infrastructure generally set a meaningful PTR record, because mail systems and monitoring tools expect one.
What you are looking for is the gap between presentation and substance. A generic hostname assigned automatically by a hosting provider, on a machine shared with unrelated sites, tells you the platform is renting a slice of a commodity server. For a personal blog that is completely appropriate. For a company that claims to hold client funds and execute trades at scale, it describes an operation with no infrastructure of its own - which is difficult to reconcile with the trading operation being described. See how reverse DNS lookups work for the mechanics.
6. Is the address blacklisted?
An IP blacklist check queries DNSBL feeds that track addresses associated with spam and phishing. A listing means an independent operator observed abusive traffic from that address and chose to publish it.
Read this carefully in both directions. A listing on shared hosting may be somebody else's fault, since one bad tenant can get the whole machine listed - which is itself a small argument against trusting money to a company that shares an address with strangers. But a listing across several independent feeds is much harder to explain away, because those operators reached the same conclusion separately. Equally, a clean result proves very little: a platform that has not yet been reported is not the same as a platform that is honest. Our article on what a DNSBL is covers how listings happen and how they are removed.
7. Where does their email actually come from?
When the account manager emails you, open the full headers and run them through an email header analyzer. The display name in your inbox is chosen by the sender and means nothing. The Received chain is added by each server the message passed through and is far harder to forge convincingly.
Two findings matter most. First, whether the message originated on infrastructure connected to the platform at all, or arrived from a free webmail account or an unrelated bulk sender - a firm that cannot send mail from its own domain is not running the operation it describes. Second, whether the Return-Path and the visible From address agree. A mismatch is routine for genuine bulk marketing but is worth questioning when the message is a personal note from someone asking you to move money.
8. Is their mail authenticated?
Use a DNS lookup to query the domain for TXT records and check for SPF, DKIM and DMARC. These records are how a domain owner tells the world which servers may send mail in its name.
The absence of an enforcing DMARC policy on a financial brand is quietly revealing. Real financial institutions publish and enforce it, because without it anyone can send mail that appears to come from them, and being impersonated is one of the biggest risks such a business carries. An operator who has not bothered either lacks the competence you would want in a custodian of your money, or is not worried about brand impersonation because the brand is disposable.
9. What else lives at that address?
Finally, look at the neighborhood. Combining reverse DNS with the address details often reveals what else is hosted alongside the platform.
Shared hosting is common and unremarkable on its own. What you are watching for is a specific pattern: a cluster of near-identical trading or investment sites, under different brand names, sitting together. That is a template farm - one operation running many fronts, so that when one name is reported and burned, the others continue. Finding the siblings of the site you are evaluating is often the most decisive evidence available, because the operator has to keep them running and cannot easily hide the relationship.
Working through an example
Take a fictional platform - call it Quantum Yield Systems, a name chosen precisely because no such company exists - which reached you through a message from an acquaintance. The site claims twelve years of algorithmic trading, a London head office, and a license number in the footer. Here is how the checks compound.
WHOIS returns a creation date seven months ago and an expiry date five months from now. First contradiction: twelve years of history on a domain that will expire before the year is out. The registrant is behind a privacy service, which for a firm publishing a London address and a license number is a second small inconsistency.
IP location and ASN put the origin server on a budget virtual hosting provider with no presence in the United Kingdom, and no CDN in front of it. Not damning alone - plenty of legitimate small companies host cheaply - but it does not describe a firm running trading infrastructure for clients.
Reverse DNS returns a generic provider hostname. The machine is shared. Looking at what else resolves nearby turns up four other investment platforms with different names, different color schemes, and conspicuously similar page structure. This is the finding that ends the evaluation.
The license number, searched on the regulator's register, either returns nothing or returns a real firm whose registered contact details do not match anything on the site. The second outcome is more dangerous than the first and we will deal with it next.
Notice that no single check delivered a verdict. The domain age raised a question, the hosting failed to answer it, and the neighborhood settled it. That is how this works in practice: you are accumulating inconsistencies until the story stops holding together.
What these checks cannot tell you
It would be irresponsible to present the above as a test that produces safety, so here are the limits plainly.
Every one of these signals can be bought. Expired domains with years of history are traded openly, so a patient operator can start with an aged domain. Enterprise cloud hosting is available to anyone with a card. SPF, DKIM and DMARC can be configured correctly in an afternoon. A well-funded operation will pass all nine checks, and well-funded operations are the ones that take the largest sums.
The checks also produce false alarms. A legitimate small broker may use WHOIS privacy, modest hosting, and a shared address, because those are ordinary decisions for a small company. Treating any single signal as a verdict will lead you to reject honest businesses.
What the method genuinely does is raise the cost of the deception. It catches the large, cheap majority - operations running many disposable fronts on minimal infrastructure - and forces anyone else to spend real money and time looking legitimate. A pass means only not disqualified. It never means verified. For that you need the register.
The one check that outranks all the others
If you do nothing else in this article, do this: search the financial regulator's public register in your own jurisdiction, and search it yourself rather than following any link the platform gave you.
| Region | Register to search | What it tells you |
|---|---|---|
| United Kingdom | FCA Financial Services Register, plus the FCA Warning List | Whether the firm is authorized, and whether the FCA has already published a warning about it |
| United States (securities) | FINRA BrokerCheck and the SEC investment adviser search | Whether the firm and the individual advising you are registered at all |
| United States (forex and futures) | NFA BASIC, run by the National Futures Association | Registration and disciplinary history for anyone offering leveraged forex or futures products |
| European Union | The national regulator of the member state named on the license | Whether the license number exists and belongs to the firm quoting it |
| Australia | ASIC Connect, plus the Moneysmart investor warning list | License status and published warnings about unlicensed operators |
| Singapore | MAS Financial Institutions Directory and Investor Alert List | Whether the firm is regulated, or already flagged as impersonating one that is |
Three things about doing this properly.
Search by firm name and by license number separately. A number that returns nothing is the end of the conversation. A number that returns a different company than the one quoting it is worse than nothing, and leads directly to the next point.
Watch for clone firms. This is the technique that catches people who did check. The scammer copies the name, address and license number of a genuinely authorized firm, so the register lookup appears to confirm them. The defense is simple and absolute: take the contact details from the register, not from the website, and use those to make contact. If the phone number, email domain or web address on the register differs from the one you were given, you are not talking to the firm on the register. Regulators publish warning lists of known clones for exactly this reason, and those lists are worth searching too.
Check the right jurisdiction. Authorization in a distant jurisdiction with light oversight does very little for you. What matters is whether the firm may lawfully offer this product to someone in your country, because that is what determines whether you have any compensation scheme or complaints process when things go wrong. A firm that is not registered where you live has left you with no recourse by design.
Red flags that need no tools at all
Some signals require no lookup, only the willingness to take them seriously when they appear alongside a persuasive person.
Guaranteed or fixed returns. No legitimate trading product guarantees a return, because guaranteeing one is not possible. A daily or weekly percentage presented as reliable is not an aggressive strategy; it is a description of something that is not trading.
Urgency attached to a deposit. A closing market window, an expiring bonus, a slot in a fund that is about to fill. The purpose of a deadline is to prevent the ten minutes of checking described above. Treat any time pressure as itself the finding.
The relationship moves to a private channel. Contact that lives entirely in WhatsApp or Telegram, with a personal account manager who becomes friendly, asks about your family, and is available late at night. This is not customer service. It is the construction of a relationship that will later make you reluctant to accuse someone of theft.
Crypto-only deposits. A regulated firm can accept a bank transfer. Insisting on cryptocurrency is a preference for irreversibility.
Any request for remote access. Being walked through an installation of screen-sharing or remote-control software so somebody can help you set up the account means handing over the device you bank on. There is no legitimate version of this request.
A fee required before a withdrawal. Real platforms deduct charges from the balance. Being asked to send new money to release existing money is the defining mechanic of the fraud, and by the time you see it the earlier funds are gone.
A deposit tier that unlocks something. Being told that a higher balance brings faster withdrawals, a better algorithm, a dedicated manager or lower fees is a mechanism for enlarging the loss, not a pricing model. The tier you are on is never the one that works.
Uniformly positive reviews. Real products have unhappy users, and a profile with no criticism has been curated or bought rather than earned. Look at the shape of the reviews rather than the average: a cluster of five-star ratings posted within a short window, in similar phrasing, by accounts with no other history, is a purchase. Read the negative reviews specifically and check whether the complaints gather around withdrawals, because that is the one failure that separates a disappointing product from a fraudulent one. Bear in mind as well that some review platforms allow companies to challenge and remove reviews, so an unblemished record on one site is worth less than it looks.
Payment for bringing other people in. Referral commission is ordinary marketing on its own. The question that separates it from a pyramid structure is where the returns come from: if what you earn depends on new deposits arriving rather than on the strategy performing, then recruitment is the product and the arithmetic requires an endless supply of newcomers. Any scheme with multiple levels of commission deserves that question asked directly.
One traditional warning sign is worth retiring. Poor spelling and clumsy grammar used to be a reliable tell, and it no longer is - generated copy is fluent, and a polished, well-written site now costs nothing. Fluency stopped being evidence of legitimacy some time ago, which is precisely why the checks in this article look at infrastructure rather than presentation.
Our broader guides to how attackers actually obtain data and practical internet security habits cover the social engineering underneath most of these.
If you have already sent money
Speed matters more than anything else here, and the single most important thing is the hardest: stop paying. The release fee is never the last fee. Whatever is already gone is gone, and the only decision still available to you is whether to add to it.
| How you paid | Realistic prospects | Do this first |
|---|---|---|
| Credit card | Best case. Chargeback rights apply and the window is typically measured in months. | Call the number on the card and use the words unauthorized transaction and fraud, not investment loss. |
| Debit card | Weaker than credit but real. Many schemes still allow a dispute. | Contact the bank the same day and ask specifically about chargeback rights on the scheme. |
| Bank transfer | Difficult. Depends on speed and whether the receiving account is still open. | Call the fraud line immediately and ask for a recall request to the beneficiary bank. |
| Cryptocurrency | Effectively irreversible. Nobody can undo a confirmed transaction. | Record every transaction hash and wallet address, then report. Ignore anyone promising to reverse it. |
| Gift cards or vouchers | Very poor, but not always zero if reported within hours. | Contact the card issuer with the receipt and card numbers straight away. |
Preserve everything before you close any tab.Screenshot the dashboard, the chat history, the account manager's profile, every email with full headers, and every transaction reference. Scam sites disappear quickly and access is often revoked the moment you stop cooperating. Investigators need this material and you will not be able to recreate it.
Report it properly.In the United States that means the FBI's IC3 and the FTC; in the United Kingdom, Action Fraud; in Australia, Scamwatch. Report to the financial regulator as well, because regulators use these reports to build the warning lists that stop the next person. It is worth doing even when recovery seems unlikely.
If you installed remote access software, treat every account as compromised. Change passwords from a different device, revoke active sessions, and turn on two-factor authentication on email and banking first, since those are the accounts used to reach the others.
Then expect the recovery approach. Within weeks you may be contacted by a firm offering to trace and recover the funds for an upfront fee, sometimes claiming a connection to a regulator or law enforcement. Legitimate authorities do not charge victims a fee to investigate, and nobody can reverse a confirmed cryptocurrency transaction regardless of what they claim. Treat every unsolicited recovery offer as a second attempt by the same people.
Where a VPN helps, and where it does not
Being straightforward about this matters, because the topic attracts a lot of overselling.
A VPN would not have prevented any part of the scam described above. It does not evaluate platforms, detect fraud, or warn you about a domain. If you deposit money with a fake broker while connected to a VPN, you have lost exactly the same money. Anyone implying otherwise is selling something, and you should be as skeptical of that as of the platform.
What it does do is narrower and still worth having. On an untrusted network - hotel, cafe, airport - it encrypts traffic that would otherwise be visible to whoever runs that network, which matters when you are logging into banking to check what happened. It stops your ISP and the networks in between from building a profile of the financial sites you visit, which is the raw material for targeted approaches later. And it keeps your real IP address away from the sites you are investigating, which is a reasonable precaution when the site may belong to people who collect that sort of thing. That is the honest scope: it protects the connection, not the judgment.
The habit worth keeping
The reason the infrastructure approach works is that it moves the question away from persuasion. Deciding whether a platform seems trustworthy puts you in a contest with people who are considerably better at that contest than you are - it is their full-time occupation, and they have practiced on thousands of people before you. Asking when the domain was registered, who runs the network, and whether the license number appears on the register removes them from the process entirely. Those answers come from registries, routing tables and regulators, none of which have been charmed.
Ten minutes, before the first deposit rather than after the first refused withdrawal. If you want to practice on something harmless, run the checks against a platform you already use and see what a legitimate answer looks like - start with a WHOIS lookup, follow it with an ASN lookup, and get a feel for the shape of a normal result. It is much easier to recognize a wrong answer once you have seen a few right ones.
