
Baited
Catch fake emails, texts, URLs
0 ratings
Free
About
Every phishing message you've ever fallen for looked completely normal. Baited trains the part of your brain that notices before you click.
A message appears — an email, a text, a login page, a bare URL. Swipe left if it's phishing, right if it's legit. You have 60 seconds for ten cards. Miss one and you'll see exactly what gave it away.
HOW IT WORKS
• Swipe left for phishing, right for legit — or tap the buttons
• Every answer shows 2-3 specific tells: the lookalike domain, the reply-to mismatch, the pressure tactic
• Build streaks for score multipliers, and a speed bonus for trusting your gut
• Share your result as an emoji grid when you're done
25 ROUNDS THAT GET HARDER
The campaign runs from obvious bait to genuinely difficult, and it remembers where you stopped. Early rounds are misspelled bank pages and prize-giveaway texts. Later rounds are punycode domains, reply-chain hijacks, and phishing hosted on real Google and Microsoft infrastructure.
WHAT'S IN THE DECK
264 cards drawn from real-world attack patterns: credential harvesting, invoice fraud, gift card scams, delivery notices, tech support callbacks, crypto drainers, CEO fraud, MFA fatigue, romance scams, and AI-era attacks like deepfake wire fraud and voice cloning.
THE LEGIT ONES ARE THE HARD PART
Half the deck is real. Genuine order confirmations, actual bank alerts, authentic security notices — including the ones that look wrong but aren't. Learning what to trust matters as much as learning what to avoid.
FIND YOUR BLIND SPOT
Per-category accuracy shows where the bait keeps working on you. Most people discover they're excellent at spotting fake prizes and terrible at invoice fraud.
Built by a security professional. Every tell is technically accurate — real short codes, real domain structures, real attacker tradecraft. No filler, no "looks suspicious."
No ads. No account. No tracking. Nothing leaves your phone.
Show more
+1
What's New in Baited
1.0
August 6, 2026








