Hong Kong's Securities and Futures Commission has flagged 65 websites impersonating HashKey, one of the city's licensed virtual asset trading platforms, warning that none of the sites have any connection to the real company. The alert was reported by Cointelegraph on August 15, 2026, and points to a single brand being cloned dozens of times over.
The number is the story. A regulator naming one or two suspicious domains is routine. Naming 65 at once, all copying the same licensed operator, shows how cheap and repeatable the clone-site model has become. Duplicating an exchange's front page, its logo, and its login flow takes an attacker minutes. Getting those pages in front of victims through search ads, social replies, and direct messages is the only real cost.
The clone-site playbook
Impersonation scams do not need to break any code. They rely on a user typing credentials, or a deposit address, into a page that looks correct but is not. A cloned site mirrors the genuine interface closely enough to pass a glance, then harvests logins, drains any wallet the victim connects, or simply takes a "deposit" and disappears.
Licensed platforms are the most valuable targets precisely because a real license implies safety. HashKey holds a Hong Kong VASP license, which is a selling point the company advertises and a trust signal that scammers borrow. A victim who has heard the platform is regulated is more likely to lower their guard on a page that carries the same name.
The 65-to-1 ratio also explains why takedowns feel like a losing game. Removing one fraudulent domain does little when the operator can register the next one for a few dollars. Regulators publish alert lists partly for this reason: the goal is not to delete every clone, but to give the public a reference they can check before sending money.
Licensed brands carry the most trust to steal
Hong Kong has spent the past two years pushing exchanges toward its licensing regime, and that regime is doing what it is supposed to do. It gives users a shortlist of vetted operators. The side effect is that the same shortlist tells scammers exactly which brands carry the most trust to steal.
This is not unique to Hong Kong. Any market that publishes a register of approved platforms hands attackers a menu of high-value names to clone. The defense is not less regulation, it is user habit: treating the brand name as necessary but never sufficient, and confirming the actual domain every time.
For anyone who holds assets on a centralized exchange, the episode is a reminder of counterparty and access risk. Even when the real platform is solvent and well run, the path you take to reach it can be hijacked. Bookmarking the genuine URL and refusing to reach an account through an ad, a search result, or a message removes the single most common entry point these scams use.
Practical verification steps
A few habits stop almost all clone-site fraud:
- Type the exchange address yourself or use a saved bookmark. Do not click ads, search results, or links in messages to log in.
- Check the domain character by character. Clones use near-identical spellings, extra words, or unusual endings.
- Cross-check the platform against the regulator's own public alert and licensee lists before funding anything new.
- Treat any "verify your wallet" or "urgent withdrawal" prompt as hostile. Real platforms do not ask you to connect a wallet to a random link to keep your account.
Self-custody changes the shape of the risk rather than removing it. Holding your own keys means no custodian can freeze or lose your balance, but a cloned site or a malicious approval can still drain a wallet you connect. Users who spend from their own wallet trade custodial exposure for signing discipline, and phishing pages are built to exploit exactly that moment of approval.
Overview
The SFC has named 65 websites impersonating licensed exchange HashKey, none of them affiliated with the real platform. The scale, not any single fake, is the point: cloning a trusted brand is cheap, and a published license is the credential scammers most want to borrow. The fix is on the user side. Verify the domain, reach accounts only through saved bookmarks, and check regulator alert lists before moving funds.



