How it works
This is the typosquat's quieter cousin. Instead of misspelling the name, the scammer keeps the exact shape of "coinbase" but builds it from characters that only look like the real ones. A digit stands in for a letter, so c0inbase.com uses a zero where the o belongs. Or a non-Latin letter that renders identically in most fonts takes the place of an ASCII one, which lets the domain look pixel-for-pixel like coinbase.com in your inbox while pointing somewhere else entirely. Coinbase is a favorite target because crypto payouts cannot be reversed, so these often ride in on a fake "creator reward," "giveaway partner," or "brand ambassador" pitch. The whole point is that you cannot catch it by reading, because there is nothing misspelled to catch.
The tell-tale signals
- The domain looks perfect but the letters are not all standard ones. Paste it into a plain-text editor or a tool that shows raw ASCII and the fake characters reveal themselves.
- The address may appear in your client as coinbase.com yet resolve to a different registered domain once you read the real headers.
- Crypto, wallet, payout, or giveaway language shows up early, which real Coinbase creator outreach does not lead with.
- The domain behind it is usually newly registered and thinly authenticated.
What to do
Never judge a crypto-adjacent domain by how it looks. Select the sender address, copy it, and paste it somewhere plain to see the real characters, or open the message source and read the return-path domain. Go to coinbase.com directly and use their official affiliate or partnerships channel to confirm any offer. Assume any first-contact email that mentions a payout in crypto is a scam until proven otherwise, and never send funds, connect a wallet, or enter a seed phrase based on an emailed request. A homoglyph domain is not something anyone registers by accident, so a hit here is a hard stop.