Security · Phone-first

Fake crypto apps — how to spot them before they empty your wallet

Nigeria is a mobile-first crypto market, which makes the app the attack surface. Cloned exchange apps and fake wallets circulate through Telegram links, WhatsApp forwards and sideloaded APK files, and they are built to do exactly one thing: capture your login or your seed phrase.

APK risk8 signsVerify methodIf infected

How a fake app reaches a Nigerian phone

Almost never through a search on the official store. Nearly always through a link somebody sent you.

RouteHow it is framedRisk
APK file shared in a group"The Play Store version doesn't work in Nigeria, use this"Highest. A sideloaded APK bypasses every store check.
Link from a "support agent""Install our verification app to unlock your account"Very high. No exchange has a second app for verification.
Cloned store listingSame icon, near-identical name, a few thousand fake reviewsHigh. Store review catches most but not all.
Sponsored search resultAn ad above the real result, on a lookalike domainHigh. Check the domain character by character.
QR code in a Telegram group"Scan to connect your wallet"High. Wallet-drainer sites, not apps.
Progressive web app prompt"Add to home screen for the full app"Moderate. Looks like an app, is a website.

Never install a crypto app from an APK file. There is no legitimate reason for a real exchange to distribute one to a Nigerian user. Every genuine platform we review is on the Google Play Store and the Apple App Store, and the "Play Store doesn't work in Nigeria" line exists solely to get you to sideload.

Eight signs an app is not genuine

  1. It asks for your seed phrase

    A wallet app generates a seed phrase for you, or imports one you already have — during setup, on your device. It never asks for one to "verify", "sync", "upgrade" or "unlock". This alone is conclusive.

  2. The developer name is wrong

    Check the publisher on the store listing against the name on the exchange's own website. Fakes use plausible variants — extra words, a different legal suffix, a hyphen.

  3. The install count is far too low

    A major exchange has millions of installs. A hundred thousand on an app claiming to be Binance is a fake.

  4. The reviews are recent and identical

    Hundreds of five-star reviews in the same week, in similar phrasing, with no substance. Read the one-star reviews — that is where victims post.

  5. It requests permissions it cannot need

    SMS access, accessibility services, screen overlay, or "install unknown apps". Accessibility permission in particular lets an app read and control your screen.

  6. Deposits work and withdrawals do not

    The classic fake-exchange pattern: a balance that rises on your screen and a withdrawal that always needs one more fee.

  7. No official web presence that matches

    Open the exchange's real website, in a browser, typed by hand, and follow its own app link. If the listing you were sent is not the one it links to, it is not the app.

  8. The name is subtly off

    Binamce. Bybit Pro. Trust Wallet Plus. MetaMask Wallet Pro. Read it character by character.

Fake wallets are worse than fake exchanges

A fake exchange app steals your login, and your exchange can often freeze the account and stop the withdrawal. A fake wallet app steals your seed phrase, and a seed phrase is the asset itself. There is no account to freeze, no support to contact, and no recovery. Funds are typically moved within minutes of the phrase being entered.

The most impersonated wallets among Nigerian users are Trust Wallet, MetaMask, Phantom, Exodus and Ledger Live. Install these only from the links on their own official sites: Trust Wallet, MetaMask, Phantom and others, Exodus, Ledger.

The fake Ledger Live pattern. A convincing desktop or mobile "Ledger Live" asks you to type your 24-word recovery phrase to "restore" or "verify" your device. A real Ledger device never requires you to type your recovery phrase into a computer or phone — the phrase is entered on the device itself, and only when restoring the device.

How to install the real app, every time

  1. Type the exchange's domain into your browser by hand

    Not from a message, not from a search ad. Check the spelling.

  2. Use the download link on that site

    It will take you to the correct store listing. This one step defeats almost every fake.

  3. Confirm the publisher name matches

    Cross-check against the site's own footer or legal page.

  4. Check the install count and read one-star reviews

    Ten seconds, and it catches clones.

  5. Never enable "install unknown apps"

    If a crypto app requires it, it is not a crypto app you want.

  6. Set up 2FA immediately after install

    Authenticator app, not SMS. SIM-swap fraud is a real Nigerian risk.

  7. Whitelist your withdrawal addresses

    So even a stolen login cannot send funds somewhere new.

You already installed one. Act in this order.

  1. Disconnect from the internet, then uninstall

    Turn on airplane mode first so the app cannot transmit while you remove it.

  2. If you entered a seed phrase, move funds now — from a clean device

    That wallet is permanently compromised. Create a new wallet on a different, clean device and move everything immediately. Do not "change the password" — there is no password to change.

  3. If you entered exchange credentials, secure the account

    From a clean device: change the password, reset 2FA, revoke all API keys, remove any whitelisted address you did not add, and contact support to flag the account.

  4. Check for lingering permissions

    Review accessibility services and device-admin permissions on Android. Malware often survives an uninstall through these.

  5. Change your email password too

    Account recovery runs through email. If that is compromised, nothing else is secure.

  6. Report it

    Report the listing to the store, the fake domain to the real exchange, and the loss to the EFCC.

Do not reuse a compromised seed phrase. Not for a different coin, not on a different chain, not "after cleaning the phone". Once a phrase has been typed into an untrusted app, every address it will ever generate is compromised for good.

Why Nigerian users are targeted specifically

Three structural reasons, none of them about carelessness. Nigeria is one of the largest retail crypto markets in the world by user count, so the addressable set is enormous. Adoption is Android-first and sideloading is culturally normal here, because many genuinely useful apps have been distributed by APK. And a real history of platform outages and regional restrictions makes "the official app doesn't work in Nigeria" a claim that sounds credible rather than absurd.

That last point is the leverage. The defence is a rule that does not require you to judge credibility: the app comes from the official store, reached from the site you typed yourself. Always.

Frequently asked questions

How do I know if a crypto app is fake?

The decisive test is whether it asks for your seed phrase — a genuine wallet never does after setup. Then check that the publisher name matches the exchange's own website, that install counts are in the millions for a major platform, and that recent reviews are not a burst of identical five-star entries.

Is it safe to install a crypto app from an APK file?

No. There is no legitimate reason for a real exchange to distribute an APK to Nigerian users, and sideloading bypasses every store security check. "The Play Store version doesn't work in Nigeria" is the standard line used to get you to install a clone.

What happens if I entered my seed phrase into a fake app?

Assume the wallet is permanently compromised and that funds will be moved within minutes. From a clean device, create a new wallet and move anything remaining immediately. Never reuse that phrase for any coin or chain again.

Which crypto apps are most commonly faked in Nigeria?

Trust Wallet, MetaMask, Phantom, Exodus and Ledger Live among wallets, and the major exchange apps among platforms. Fake Ledger Live is particularly dangerous because it asks you to type your 24-word phrase, which a real Ledger never requires.

Can a fake app steal from an exchange account?

Yes — it captures your login and 2FA codes as you enter them. This is more recoverable than a stolen seed phrase because the exchange can freeze the account, so contact support from a clean device immediately, reset credentials and revoke API keys.

How do I install the real exchange app safely?

Type the exchange's domain into your browser by hand, then use the download link on that site to reach the store listing. That single step defeats almost every fake app in circulation.

Last reviewed: 2026-09-09. We update this page whenever Nigerian rules, fees or platform availability change. Nothing here is financial, tax or legal advice — see our editorial policy.

Open a CEX.IO account in 5 minutes

Licensed exchange supporting NGN, BVN/NIN KYC and instant naira-to-USDT conversion.

Start with CEX.IO →