Coin Master Players Warned of Phishing Scam Targeting Reward Links
Mobile gaming giant Moon Active has issued an urgent warning to American Coin Master players following a massive spike in cyberattacks. Cybercriminals are setting up highly realistic phishing websites designed to steal player accounts by exploiting the game’s popular daily reward links.
The alert, sent out in late September 2026, comes after thousands of US users reported losing access to their accounts. Security analysts tracking the wave say the scammers are preying on the game’s core mechanic: the hunt for free spins.
How the Reward Scam Works
For the uninitiated, Coin Master relies heavily on a daily loop. Players spin a virtual slot machine to win coins, raid rival villages, and upgrade their own bases. Because spins are limited, Moon Active regularly posts official “free spin” links on its social media pages. These links are a lifeline for active players.
That is where the scammers step in. They build fake websites that look almost identical to official Moon Active portals. Often, these fraudulent links are distributed through lookalike social media profiles, sponsored Facebook posts, or community forums.
Once a player clicks the fake link, they are prompted to “log in” using their Facebook or Google credentials to claim their rewards. Instead of receiving free spins, players hand their login details directly to hackers. Within minutes, the attackers change the account recovery options, locking the legitimate players out permanently.
Moon Active Responds
“We have observed a sophisticated coordination of malicious domains targeting our US player base over the last week,” Moon Active said in a security statement. “These sites are entirely unaffiliated with Moon Active or Coin Master. We are working actively with cybersecurity partners and domain registrars to take these malicious sites down as quickly as possible.”
The developer emphasized that players do not need to log in or share passwords to claim real daily rewards. Official links should automatically open the Coin Master app on the user’s device and credit the spins or coins directly without asking for external login credentials.
Protecting Your Account
Security experts say this scam succeeds because of how quickly players want to grab rewards before they expire. Cybercriminals rely on this sense of urgency. To stay safe, the studio advises players to follow a few simple rules:
- Use official channels only: Only click links shared directly by the verified Coin Master accounts on Facebook, X, and Instagram. Verified accounts have a blue checkmark.
- Watch the URL: Official links typically redirect users securely within the game app. If a link forces you to open a web browser and asks for your Facebook password, close the tab immediately.
- Enable two-factor authentication (2FA): Since most Coin Master accounts are linked to Facebook, securing your Facebook account with 2FA adds a critical layer of defense.
- Never pay for rewards: Daily reward links are always free. Any site asking for a small processing fee or credit card information is a scam.
A Growing Threat in Mobile Gaming
This is not an isolated incident. Mobile gaming phishing has skyrocketed throughout 2026. As games like Coin Master continue to pull in billions of dollars globally, players become prime targets for digital thieves. Account theft is not just about losing game progress anymore; compromised accounts are often used to spread further scams to the victim’s real-life friends and family on social media.
For now, US players are urged to double-check every link they click. If a deal looks too good to be true, it almost certainly is.