Skip to main content

The fake OLX payment link: how sellers get robbed

Published September 16, 2026 · Updated September 16, 2026 · 5 min read

Quick answer

A platform never pays a seller through a link the buyer supplies. If someone sends you a link to receive money and the page asks for your card number, expiry or CVV, it is theft of funds — you cannot receive money by typing card details, only authorise a payment.

This scam is aimed at sellers rather than buyers, which is why it keeps working. The buyer is friendly, quick to agree on the price, and cannot collect in person — a relative will come, or a courier, or they are "out of town". Then, instead of paying cash, they send a link: a page that copies the marketplace's design, titled "secure payment" or "courier payment", where the seller is asked to enter card details to receive the money.

The logic is inverted on purpose. Receiving a transfer needs only an IBAN. A card number, an expiry date and a CVV are what you type when you are the one paying.

The script, line by line

  1. Contact comes through the platform's chat, then moves to WhatsApp or Telegram "because it is faster".
  2. The price is accepted without negotiation, and collection is arranged in a way that never involves meeting the seller.
  3. A link arrives: "enter your card details so the courier can transfer the money when he arrives".
  4. The page shows a convincing error — "the card was declined, try another" — which is how a second card, or a second victim in the household, is collected.
  5. Once a card is authorised, the amount leaves the account in one or more small card-not-present payments before the listing is deleted and the chat is closed.

What a real platform flow looks like

  • Money arrives through the platform's own escrow or "protected payment" feature, visible in your account, or as a normal bank transfer to your IBAN.
  • The buyer never needs your card details, and the platform does not send separate links per transaction.
  • Cash on delivery or cash on collection remains normal on marketplaces — and is what a genuine buyer expects to offer.
  • An offer that suddenly requires your card is a change of direction: your details should only ever travel towards a merchant you chose.

How to check the link in ten seconds

Paste the link into the BaitScan link checker instead of opening it. The checker resolves the real destination, flags the look-alike patterns that copy a marketplace or courier domain, and tells you whether the site is asking for card data or login details. It runs in your browser, so the link is not sent to us or to anyone else.

  • The domain is one character away from the real one, or adds a word: `olx-pay`, `olxsecure`, `olx.ro-livrare.com`.
  • There is no https padlock, or the padlock is there but the domain is wrong — a padlock proves encryption, not ownership.
  • The page has no navigation: no categories, no help, no terms. Real marketplaces are full websites; fraud pages are a single form on a blank page.
  • A countdown or a "link expires in 5 minutes" notice. Real payment flows do not expire to create pressure.

If you already entered the card

  1. Freeze the card in your banking app, then call the bank and request cancellation with a replacement.
  2. Dispute the transactions the same day, stating that the details were entered on a fraudulent payment page.
  3. If you entered your marketplace password on the same page, change it immediately and sign out all sessions — those credentials are resold separately from the card.
  4. Keep the chat and the link. They are the evidence your bank will ask for, and they are what the platform needs to remove the account.
  5. Report the listing and the user inside the platform, then block the number.

Frequently asked questions

The questions this article gets asked most, answered directly.

Can a buyer send me money without my card details?

Yes, and that is the normal case: a bank transfer needs your IBAN, and platform escrow needs your account inside the platform. Card details are only ever needed to take money out, never to put it in.

The page had a valid https padlock and looked official. Does that mean it is safe?

No. A certificate is issued automatically and only proves the connection is encrypted to that domain. It says nothing about who owns the domain, which is exactly what a look-alike will not survive.

I gave my name, phone and address too. What now?

Expect targeted calls and messages using those details, and treat any follow-up that mentions the listing as part of the same operation. Do not confirm codes, and use the phone checker on any number that calls about it.

Why do they insist on WhatsApp instead of the platform chat?

So the conversation leaves the platform's moderation and retention. A chat they control has no report button, and it cannot be handed to the platform's fraud team afterwards.

Written by The BaitScan editorial team

Results are automated risk estimates based on public indicators and heuristics.