Phishing attempts impersonating MoonPay usually fall into one of four categories: a suspicious email claiming to be from MoonPay, a suspicious website impersonating MoonPay, a domain posing as MoonPay, or an email about unauthorized account activity — such as a phone number change, transaction, or login — that you did not initiate.
Follow these steps to identify what you're dealing with, protect your account, and report the incident.
Important: If you received an email about account activity you didn't request — such as a phone number change, a transaction, or a login — nothing will happen to your account if you didn't request it. These are phishing attempts trying to create urgency. Your account is safe as long as you don't click links or share any information.
How to identify a phishing email
Check the sender's email address: Verify that the email is from an official MoonPay domain. Legitimate MoonPay emails come only from these exact sender domains:
@moonpay.comand@mail.moonpay.com. Any other domain — including one that looks similar, such as @em2.moonpay.com or @help.moonpay.com — is not from MoonPay, even if it contains "moonpay" in the addressCheck the website or domain: If you're unsure whether a website or domain is genuinely MoonPay's, don't enter any login details or personal information on it. Treat any site or domain you don't recognize as suspicious until you can confirm it's official
Look for red flags: Be cautious of emails, websites, or domains that: - Contain urgent or threatening language. - Request personal information or login credentials. - Include links or attachments that you didn't expect
Steps to take if you receive a suspicious email
Do not interact with the email:
- Avoid clicking on any links, downloading attachments, or replying to the emailReport the email:
- Use your email provider’s tools to mark the message as phishing or spamCollect evidence for investigation:
- Take a screenshot of the email, ensuring the sender’s address is visible.
- Download the full email headers as a.emlfile. Most email providers offer options like “Show original,” “View headers,” or “Download message source.” Attach this file when reporting the incidentSubmit a report to MoonPay:
- Use MoonPay's official phishing reporting portal at app.chainpatrol.io/moonpay to submit the suspicious email and collected evidence, including a screenshot and the .eml file. This helps the security team investigate and take action
Securing your account
Verify your account:
- Log in to your MoonPay account directly through the official website or app (not through email links) to check for unauthorized changesUpdate your credentials:
- Change your MoonPay password and enable two-factor authentication (2FA) for added securityMonitor your accounts:
- Regularly review your MoonPay account and email activity for any unusual behavior
Staying safe
Important: MoonPay will never ask for sensitive information like passwords or payment details via email. MoonPay does not offer investment programs or request cryptocurrency for jobs, training, or equipment — any such request is a scam
By following these steps, you can protect your account and help MoonPay combat phishing attempts. For more information on staying safe, visit How to stay safe when using cryptocurrency.
FAQs
Will MoonPay ever ask for my password or payment details by email?
Will MoonPay ever ask for my password or payment details by email?
No. MoonPay will never request sensitive information like passwords or payment details over email.
How do I report a suspicious email to MoonPay?
How do I report a suspicious email to MoonPay?
Use MoonPay's official phishing reporting portal at app.chainpatrol.io/moonpay. Submit a screenshot of the email and, if you received it as an email, the full email headers as a .eml file.
What should I do if I already clicked a link in the email?
What should I do if I already clicked a link in the email?
Log in to your MoonPay account directly through the official website or app (not through the email link), check for unauthorized changes, update your password, and enable two-factor authentication.
