Security5 min

How to spot a fake Privnote site

The most common Privnote incident has nothing to do with cryptography. It is a look-alike domain that stores every note in plaintext and, in crypto scams, rewrites wallet addresses on the fly.

Why Privnote clones work so well

Privnote has no login and no branding you must recognise, so users judge legitimacy by the page layout alone. A clone that copies the layout inherits that trust instantly.

Checks before you paste into a Privnote

Three seconds of verification defeats the entire attack class.

  • Read the domain character by character, including hyphens and lookalike letters
  • Type the Privnote address yourself instead of following a link
  • Distrust any Privnote page that asks for an account, email or payment
  • Never trust a wallet address received through a Privnote you did not request

What to do if you used a fake Privnote

Assume the content is public: rotate the password, revoke the token, warn the recipient and, for financial data, contact the bank. Speed matters far more than certainty here.

Verify the Privnote domain before typing, not after — a clone is indistinguishable once you have pasted.

Related Privnote guides

This Privnote topic in other languages

Back to the Privnote guide