How to Spot and Avoid Phishing Emails Pretending to Be from Coinhako

How to Spot and Avoid Phishing Emails Pretending to Be from Coinhako

Phishing emails are designed to trick users into giving away sensitive information such as passwords, OTPs, or making contact through fake channels. These emails may look like they’re from Coinhako, but they’re actually from scammers. Below are key red flags to help you identify phishing attempts and protect your account.

Common Phishing Red Flags

1. Fake Email Addresses

Check if the sender’s email matches our official Coinhako addresses:
Official Coinhako email domains:
  1. hello@coinhako.com
  2. hello@updates.coinhako.com
  3. announcements@coinhako.com
  4. notifications@coinhako.com
If the sender address doesn’t match the list above — do not trust it. You can also verify any email address using the Coinhako Verification tool to confirm whether it is an official Coinhako channel.
Examples of suspicious sender emails:
  1. mail.service.lk@tourmysystem.com
  2. pipe306333899+MesPTYRH@mail.pipefy.com

2. Requesting Sensitive Information

Legitimate companies — including Coinhako — will never ask for passwords, OTPs, or security codes via email, phone, or SMS.
Phishing emails may ask you to:
  1. Reply with your login credentials
  2. Share OTPs or 2FA codes
  3. Click links to input your password or seed phrase

3. Phone Numbers in Emails — Major Red Flag

  1. Coinhako does not provide customer support via phone.
  2. Legitimate Coinhako emails will never contain phone numbers for support.
  3. Any email that asks you to call a number — no matter how urgent it seems — is a phishing attempt.

Examples from phishing emails:
  1. +65 3159 0283
  2. +65 3159 2186
  3. +65 3159 2233

Scammers often hide malicious URLs behind text or buttons. Before clicking a link:
  1. Hover your mouse pointer over it (without clicking)
  2. Look at the bottom-left corner of your browser to see the actual URL
  3. Check if it leads to coinhako.com — if not, don’t click
  4. Still unsure? Paste the URL into the Coinhako Verification tool to confirm whether it is an official Coinhako website before taking any actions.

5. Suspicious Login Location Alerts

Phishing emails often use fake login alerts to create panic.
Check if the details match your actual activity:
  1. Do you recognize the login location?
  2. Is the IP address familiar?
  3. Does the time zone match your current region?
If the login location shows something unusual (e.g. Havana, Cuba or Mumbai) and you didn’t log in — don't click anything in the email. Go directly to the Coinhako app or website to check.

6. Mismatched Branding

Look for subtle design flaws:
  1. Inconsistent logos or fonts
  2. Poor formatting
  3. Unusual language or grammar
If the email doesn't look exactly like official Coinhako emails you've seen before, don’t trust it.

7. Unexpected Attachments

Coinhako will never send files for you to open in email.
If an email includes a PDF, ZIP, DOC, or any file — treat it as suspicious.

What an Official Coinhako Email Looks Like

A legitimate Coinhako security email will:
  1. Come from a verified Coinhako address
  2. Include accurate location/device/IP info
  3. Never ask you to call support
  4. Direct you to secure actions through official platforms only

Stay Safe: When in Doubt

  1. Never share OTPs or passwords with anyone
  2. Do not click on links or attachments you’re unsure about
  3. Use Coinhako Verification to check whether any website, email, or social media account you received is an official Coinhako channel
  4. When in doubt, verify the information by going directly to www.coinhako.com or reaching out via our official Help Desk
  5. Bookmark this page for future reference and help spread awareness to keep our community safe from scams.