Why options traders are high-value targets
Options traders move size around expiries, funding windows, and liquidations. That creates predictable urgency: “your account is limited,” “claim the airdrop before expiry,” “verify wallet to keep margin,” “support will help you cancel a bad transaction.” Attackers manufacture the same urgency with fake messages and lookalike sites.
On-chain venues add a second hook: wallet connect is normal UX. A phishing page that only needs one reckless signature can drain allowances or assets without ever learning your password. CEX users face parallel scams around fake KYC portals, fake deposit addresses, and fake API “upgrade” pages.
OptionsMatch is a research layer — venue profiles, geo notes, education, and multi-venue desks. It should never ask for a seed, private key, or custody of funds. Any page that does while wearing OM branding is malicious.
Common attack patterns
Fake exchange or venue support in Discord, Telegram, and X/Twitter DMs: “Your account is limited — verify here.” Fake airdrop and points claim sites that request wallet connect for no product reason. Typosquat domains and near-miss spellings of Paradex, Derive, Deribit, Thalex, and bridges. Paid search ads that bid on venue names and land on clones.
Malicious “options calculator,” “GEX tool,” or “free terminal” pages that demand wallet connect before showing charts. Research tools do not need your keys to display public market data. Fake mobile apps with similar icons in third-party stores. Clipboard malware that swaps deposit addresses after you copy.
Recovery-seed scams remain common: forms that ask you to “sync,” “validate,” or “import” a phrase to unlock higher limits. Legitimate venues and OptionsMatch never need your seed on a web form.
Verification habits that actually work
Type the URL or use a bookmark you created after verifying official documentation and social accounts. Check the full domain carefully — subdomains and hyphenated lookalikes fool fast readers. Prefer HTTPS, but remember HTTPS alone does not prove legitimacy; thieves also use TLS.
Hover desktop links before click; on mobile, long-press to inspect the destination. Be especially suspicious of anything “urgent” that demands wallet action in the next few minutes. Real liquidations and margin calls are handled inside the official venue UI you already bookmarked, not inside a DM.
When you need venue facts — fees, product shape, geo narrative — start from OptionsMatch /venue and country pages, then hop to the official site from a trusted path. Use /education/wallets for security process; use the terminal under /t for multi-venue marks and books. Keep research and execution mental models separate so a random link cannot rush both at once.
After a bad click (before you sign)
If you opened a suspicious page but did not connect or sign, close the tab, do not enter credentials, and clear the moment of adrenaline before continuing. Open venues only from bookmarks. Run a quick mental inventory: did the page ask for a seed, download a file, or push an extension install?
If you installed anything, remove it from a calm state and assume the browser profile may be tainted. If you only viewed the page, you are likely fine — but do not reuse passwords you typed into it, and do not return via history.
If you connected a wallet or signed anything, stop reading this section and follow the right-away security guide: revoke approvals, move funds if safe, and treat exposed seeds as burned.
Building a personal anti-phishing routine
Maintain a short allowlist of official domains for the venues you actually use. Store them as bookmarks named clearly (for example “Paradex official,” “Derive official”). Never “update” those bookmarks from a DM. Re-verify domains only from documentation you trust offline or from previously saved sources.
Keep a dedicated trading browser profile, hardware for size, and small hot balances. Review token allowances on a schedule. Share this routine with teammates if you run a desk so social engineering against one person does not become culture-wide panic clicking.
OptionsMatch can help you slow down: compare venues, read education, and check multi-venue chains before you deposit. Research-first is itself an anti-phishing control — urgency is the attacker’s favorite feature.