Bybit's official site and staying safe

Updated 2026-08-28

This site is not Bybit

You are reading an independent guide. If you intended to reach the exchange itself, type its address into your browser directly rather than following a link from a search result, an advert, a message or an email — including ours.

Check the domain character by character

Read the address from right to left: the part immediately before the first single slash is the real domain. Attackers rely on lookalikes — swapped letters, an extra word, an unusual ending. A padlock icon proves only that the connection is encrypted; it says nothing about who owns the site.

Nobody legitimate needs your secrets

No exchange employee will ever ask for your password, your two-factor codes, your seed phrase or remote access to your screen. Anyone who does is attacking you, no matter how convincing the badge, the ticket number or the urgency.

If you think you entered credentials somewhere

Change the password from a device you trust, revoke active sessions and API keys, re-check the two-factor settings, and contact the exchange through its official support flow. Speed matters more than certainty here.

We do not maintain a scam-domain list

Publishing an unverified list of "scam domains" creates its own harm — a wrong entry defames a legitimate business, and the list is stale within days. We teach the check instead.