When you are managing your digital assets, your first line of defense isn't just a password—it's your awareness. Scammers are constantly finding new ways to try to get into your Webot account by pretending to be us. This is known as phishing.
To keep your crypto safe, you need to know exactly what these traps look like and what to do if you encounter one.
What is phishing?
Phishing is a "social engineering" attack. Instead of hacking a computer system, the scammer tries to "hack" the human. They disguise themselves as a trusted source (like Webot) to steal your username, password, or security codes through electronic communications, such as SMS or email.
How a phishing attack can reach you?
• The Contact: You receive an email, SMS, or DM that looks like it’s from Webot.
• The Hook: The message creates a sense of urgency, claiming your account is "locked," "outdated," or "at risk."
• The Trap: They ask you to click a link or download an attachment.
• The Breach: If you click, you might land on a fake login page that records your keys, or you might accidentally download "spyware" that monitors your device activity.
What a phishing attack looks like
Most scams follow a pattern. If you see threatening language or "scare tactics" intended to make you act without thinking, stop immediately.
Threatening Language: "Your account will be deleted in 24 hours if you don't click here." We don't use fear to talk to our users.
Suspicious Links: The text might say
pionex.us, but if you hover your mouse over it, the real destination might be something likewww.p1on3x.us.The "From" Address: Scammers use lookalike domains. If the email is from
support@p1onex.usor a random@gmail.comaddress, it is not us.
Other types of phishing
• Smishing (SMS Phishing): Scams sent via text message containing malicious links.
• Vishing (Voice Phishing): A phone call from someone pretending to be a bank or Webot "agent" to get your info.
• Twishing (Twitter/X Phishing): Fake support bots or accounts reaching out via social media DMs with fraudulent links.
• Spearphishing: A highly targeted attack where the scammer uses your name or specific details they found about you to gain your trust.
Phishing examples
Smishing example
Fake websites
Fake websites
Fake website
Things to check before clicking any links
Were you expecting to receive a message from Webot?
We generally won’t send you an email with a link for you to follow, unless you were going through a specific process in your Webot, such as account recovery, asset recovery, etc.
Is the website that you’ve been directed to secure?
Webot website will always have a padlock icon displayed in your browser’s address bar to indicate a secure HTTPS website.
If it does not have the padlock, you are not on the Webot website. If it does have the padlock, still make sure that you are on www.webot.com
Is the link shortened (for example bit.ly/…)?
Webot doesn’t hide or shorten the links we send you using third-party URL shorteners like Bitly or TinyURL. You should be able to tell exactly where the link will take you before you open it.
Are you really on Webot website, or is it an imposter site that looks the same?
We strongly advise that you never click on any suspicious links, but if you do, check that the website URL is www(dot)webot(dot)us and will always be the same domain. If you have clicked on a phishing link, immediately disconnect your device from the internet, back up your files, scan your device for malware, delete the attachments, and change your usernames and passwords across all your accounts.
Does the message pushes you to take certain action?
Phishing messages will often scare you into thinking that you’ll lose all your funds, your account will be deactivated, or your account will be compromised if you don’t follow the link. These messages are designed to make you stressed and frightened, which may lead you to lose focus on the facts.
Is the sender requesting sensitive information?
This could include your bank account details, one-time PIN, 2FA code, or password. Webot will never request these details from you. Don’t ever sign in to your account without first checking you’re really on www.webot.com
How do I know if it’s really Webot contacting me?
Webot oftenly contact you via email. To be sure that it’s coming from us, here is a list of the types of information you can check:
If you receive an email, be sure to look for the sender's address to verify that it’s legitimate. All email correspondence from us will always come from a @pionex.us or @webot.com domain, and never from @gmail.com or any other domains.
Here are some of the email addresses Webot uses:
If you open a link to Webot, be sure to look for the padlock icon (🔒) in your browser's address bar, and the URL will always come from a @pionex.us or @webot.com domain, and never be www.p1onex.us or www.pion3x.us or any other domains.
Here are some of the official Webot URLs:
Webot will not ...
Ask for your password
We never require your password as we have access to our system records to verify your account details. Please always keep your password confidential.
Ask for your 2FA or OTP codes
These codes are strictly for your use when logging into our websites. We do not ask for these codes during any support procedures.
Ask for your banking details
In rare cases, such as processing refunds or troubleshooting USD withdrawals, we may request your bank details or a screenshot of your bank transaction. Outside of these situations, we do not ask for your banking information.
Send you a shortened link
We do not use third-party URL shorteners like Bitly. Our official communications include full or hyperlinked URLs.
Force an upgrade
While platform upgrades or rebranding may occur, these do not impact you unless we notify you through our official announcement channels or in-app notifications.
How do I protect myself right now?
Secure Your Email
While we do offer 2FA options like Google Authenticator for your Webot account, it's crucial to ensure your Email account is secured with the highest level of protection. This is because your Email often serves as the primary login credential for many accounts, and if a hacker gains access to your Email, they can easily access all linked accounts. Please consider your Email as the first line of defense against cyberhacking.
Enable 2FA (Google Authenticator)
We strongly recommend using an app-based authenticator such as Google Authenticator, though you may use any preferred alternative, as this security layer makes it nearly impossible for a scammer to access your account or withdraw your assets even in the event that your password is compromised.
User the steps below to manage your 2FA,
Don't Trust Attachments
Unless you have specifically requested a file or the support team is attaching files in official responses, please avoid opening PDFs or Zip files from emails that you do not recognize.
Check "Have I Been Pwned"
Visit "haveibeenpwned.com" to see if your email address was leaked in a previous data breach elsewhere. If it was, change your passwords immediately.
What if I already clicked a link?
If you think you’ve been targeted or accidentally clicked something:
Turn off your internet/Wi-Fi to stop spyware from sending data.
Run a deep malware scan on your device.
Change your passwords from a different, "clean" device.
Contact Webot Support immediately so we can restrict your account to protect your assets from being withdrawn by the scammers.
Report phishing texts to Webot
If the phishing message was sent via text message or SMS, please submit a screenshot of the phishing text to service@webot.com. You can also reduce the likelihood of receiving messages like this in the future by copying and pasting the contents into a new SMS message and sending it to 7726 (SPAM).
When we receive your report, our security team will investigate your submission and take prompt action to shut down any malicious sites targeting Webot customers.
Report phishing to your mobile provider
If you use a US-based cell phones carrier like AT&T, Verizon, Sprint, or T-Mobile, you can help reduce phishing attacks by sending the contents of suspicious SMS messages to 7726 (SPAM). This free service allows mobile carriers to detect and block malicious messages on their network.
Disclaimer
Links to third-party websites will open new browser windows. Except where noted, Webot accepts no responsibility for the content on third-party websites.
