Accounts opened on WhatsApp in about two minutes | Withdrawals reviewed within 10 minutes | Support in English & Hindi, 24/7
Cricxbet99 logo

Account security · 8 July 2026 · Abhishek

Real APK or Fake Clone: Seven Checks

A repackaged betting app looks exactly like the real one. Same icon, same colours, same login screen. The difference shows up in the file, not on the screen, and these are the seven things worth checking before you tap install.

Member Log In

Enter the credentials your account manager issued.

Try the Free Demo Account

This page is protected by reCAPTCHA. Our Privacy Policy and Terms of Service apply. Strictly 18+.

New here?
Request an ID on WhatsApp
7Checks to run
10 minTime it takes
24/7Support on WhatsApp
1Official source
Android phone showing an APK install warning screen next to a betting exchange app icon
The install prompt is the last moment you get to change your mind. Use it.

Exchange apps do not live on the Play Store. Google will not list a real-money betting client for India, so the file arrives as an APK you install by hand, and that single fact is what the whole clone industry is built on.

Think about what a repackaged app actually is. Somebody takes the genuine file, opens it, adds their own code, signs it with their own key and puts it back online with the same name and icon. It looks right because most of it is the original. The part they added is the part that reads your notifications, or shows you a login screen that sends your password somewhere else.

I have looked at a lot of files people sent me after something went wrong, and there is a pattern. Nobody installed a clone through general carelessness. They were in a hurry, usually twenty minutes before a match, and they tapped the first link a search result gave them.

Ten minutes of checking removes almost all of that risk. Here is what to check, and why each check works.

Source

Where a genuine file actually comes from

There is exactly one route, and it is not a search result.

A real exchange APK reaches you one of two ways. Either your account manager sends the link directly in the WhatsApp thread where you were issued your ID, or you download it from the official web address you were given when the account opened. That is the list.

Not from a Telegram channel you found while searching. Not from an APK mirror site with a download button that opens three tabs. Not from a YouTube description under a video promising a prediction trick. Every one of those is a place where the file has passed through hands you cannot account for.

This matters more than any technical check. If the source is right, the file is almost certainly right. If the source is wrong, inspection afterwards will not fully protect you, because the people building clones are better at hiding than you are at looking.

A useful habit

Save the manager's WhatsApp thread and the official address somewhere you can find them in a hurry. The whole failure mode is being rushed. If the correct link is two taps away, you will not go hunting for a faster one. Our app guide walks through the install itself once you have the right file.

One more thing about links. Clone operators register addresses that read almost correctly, swapping a letter or adding a word like download in front of the name. Read the address character by character. Four seconds, and it catches most of them.

Red flags

What a repackaged clone gives away

None of these are proof on their own. Two together and I would stop.

A bonus that is too good

Clone landing pages advertise numbers the real operator never offers. A 500 percent first deposit bonus is bait, not a promotion.

The icon is slightly wrong

Colours a shade off, letters spaced oddly, a logo that looks stretched. Repackagers rebuild the icon rather than extract it.

Broken English inside the app

The real client is professionally translated. Clone builders edit strings by hand, so menus and error messages read badly.

It asks for an OTP too early

A genuine exchange client does not need a one-time password before you have even logged in. That screen is harvesting.

No update mechanism

Real clients check for a newer build and prompt you. A clone is a dead file that never updates, because nobody is maintaining it.

Payment details change

You are pushed towards a UPI ID or bank account your manager never mentioned. Stop there. That is the whole point of the exercise for them.

The checklist

Seven checks, about ten minutes

Run them in order. Any single failure is a reason to go back to your manager and ask.

Confirm the link with a human

Send the exact link back to your account manager on WhatsApp and ask whether it is theirs. Do not describe it, paste it. A real manager answers this in under a minute and is not annoyed by the question, because a compromised customer is their problem too.

Check the file size against the last build

A genuine exchange client sits in a fairly narrow band, usually somewhere between 20 MB and 60 MB depending on the version. A repackaged file is almost always larger, because the extra code and a second set of assets get bolted on. If the download is 8 MB it is a shortcut wrapper around a website. If it is 140 MB something has been added.

Read the publisher and package name

Before you confirm the install, Android shows you the app name. After installing, open Settings, Apps, then App details, and look at the package identifier. It should be consistent with what your manager tells you it should be. A clone will have a package name that is close but not identical, often with an extra word or a different suffix.

Compare the file hash

This is the only check that is genuinely conclusive. A hash is a fingerprint of the file: change one byte and it changes completely. Install any free hash checker from the Play Store, generate the SHA-256 of your download, and ask your manager for the value of the official build. If they match, the file is byte-for-byte the real one. If they do not, delete it.

Audit the permissions it asks for

A betting client needs internet access and storage for saving statements. That is close to the whole list. If the install wants to read your SMS, access your contacts, record audio or draw over other apps, those are not features of a betting app. They are features of something reading your OTPs, copying your address book or painting a fake screen over your banking app.

Look hard at the first login screen

Open the app but do not type anything yet. Compare the login screen with the one on the official site, which you can see on our login page walkthrough. Check the spacing, the placeholder text, whether the keyboard behaves normally, and whether there is a field asking for something the real screen never asks for. A phishing screen is a picture of a login, and pictures have small errors.

Test with the smallest possible amount

Log in, check that your existing balance shows correctly, and run one deposit of the minimum your manager allows, then a withdrawal of the same amount. If the balance is wrong, or the deposit details differ from what you were given on WhatsApp, you have your answer before any real money is at risk.

Two details worth expanding

Permissions and the fake login screen

These are the two places where a clone actually earns its money.

Permissions that make no sense

Android tells you what an app can reach. Most people tap through that list because every app asks for something and it all blurs. Slow down here, because the mismatch between what a betting app needs and what a clone requests is obvious once you look.

PermissionReasonable?What it can be used for
InternetYesLoading odds and placing bets. Unavoidable.
Storage or mediaYesSaving a statement or a screenshot of a deposit.
NotificationsYesBet matched alerts and settlement messages.
Read SMSNoReading the one-time passwords your bank sends you.
ContactsNoCopying your address book for resale or for pressure later.
Accessibility serviceNoWatching and controlling what you tap in every other app on the phone.
Draw over other appsNoPainting a fake screen on top of a real banking app.

The accessibility one deserves emphasis. It exists so screen readers can help people who need them, and it hands whatever holds it near-total control of the device. If a prompt tries to talk you into enabling it, close the app and uninstall.

The login screen that is not a login screen

The most profitable clone does not steal money directly. It steals your credentials and lets you carry on, so you notice nothing for a week. You type your username and password into a screen that forwards them to somebody else, then quietly passes you through to the real site so everything looks normal.

What gives it away is small. The password field lacks the little eye icon you remember. The keyboard opens as a full alphabet where the real one opens numeric. Or, most commonly, the screen asks for your phone number as well as your username, because the operator wants a second identifier.

The defence is boring and it works: never type credentials into an app you installed ten minutes ago without checking it against the official login page in a browser.

Damage control

If you have already installed something suspicious

Order matters here. Do these in sequence, not all at once.

First, put the phone in aeroplane mode. That cuts the app off from whatever it was talking to and buys you a few minutes without anything being sent anywhere.

Second, uninstall the app. If the uninstall button is greyed out, go to Settings, Security, Device admin apps, and revoke its admin rights first. Malware that resists removal is a serious signal, and at that point I would back up your photos and factory reset the phone rather than trust that you got everything.

Third, from a different device, change your exchange password. Not from the phone you are cleaning. Use a laptop or a family member's handset and message your account manager to tell them what happened, so they can watch the account for logins that are not you.

Fourth, deal with the bank side. If you entered any banking detail, or if the app had SMS access at any point, call your bank, tell them you suspect OTP interception, and ask them to flag the account. Change your UPI PIN. This part is more urgent than the betting account, because that is where the real exposure sits.

Do not skip the account review

Once you are back in, open your statement and read every entry for the past week. Look for bets you did not place, small test withdrawals to unfamiliar destinations, and any change to your registered payout details. Report anything odd in the same thread you use for deposits, and keep the screenshots.

Ongoing

Update habits that keep you clean

The install is one day. The next two years are the habit.

Most people get the first download right and then get sloppy three months later, when an update prompt appears at an inconvenient moment. Treat every update as a fresh install, because that is exactly what it is.

Update only from inside the app or from the link your manager sends. Never from a file a friend forwards, however well meant, and never from a browser notification. Run the hash check again on anything you sideload, because the point of the check is catching the one time something changed.

Keep Play Protect switched on. It occasionally complains about the genuine file, which is irritating, but it catches a meaningful share of repackaged builds before they run. And if the app has not needed an update in six months while the desktop site clearly has new features, ask whether your build is current. Silence is not stability.

Then do the boring hygiene. A password used nowhere else, a screen lock, and logging out on any shared device. Most account losses I see are not clever attacks, they are a reused password and a borrowed phone. The registration guide covers the security decisions worth making on day one, and everything here assumes you are 18 or over and have read our responsible gaming notes.

Questions

Frequently asked questions

Why is the app not on the Play Store?

Google does not list real-money betting clients for India, so exchange apps are distributed as APK files you install manually. That is normal for this category and not a warning sign in itself. What matters is where the file came from, which should be your account manager's WhatsApp thread or the official address you were given.

How do I check a file hash on a phone?

Install any free hash checker from the Play Store, open it, point it at the downloaded APK and generate the SHA-256 value. Then ask your manager for the official value and compare them character by character. Matching hashes mean the file is byte-for-byte identical to the real build, and it is the only check that gives you certainty.

Which permissions should make me delete the app?

Read SMS, contacts, accessibility service and drawing over other apps. None of those are needed to show odds or place a bet. Accessibility is the most serious because it grants near-total control of the device, so if an app talks you into enabling it, uninstall immediately and change your passwords from a different phone.

I typed my password into a fake screen. What now?

Put the phone in aeroplane mode, uninstall the app, then change your exchange password from a different device and message your account manager so they can watch for logins that are not yours. If you entered any banking detail, or the app had SMS access, call your bank about possible OTP interception and change your UPI PIN.

Is it safe to update from a link a friend sends?

No, and this is where careful people slip. Update only from inside the app or from your manager's own link, and rerun the hash check on anything you sideload. A forwarded file may be perfectly genuine, but the person forwarding it cannot vouch for the chain it travelled through to reach them.

Get the file from the right place

Ask on WhatsApp, get the current link and the official hash in the same message, and install once with everything checked.

18+ only. Betting involves financial risk and can be addictive. Please play responsibly.

People Also Search For

cricbet99 appcricbet99cricbet99 logincricbet99 idwww cricbet99 com logincricbet99 comcricbet99 registercricxbet99welcome to cricbet99cricbet99 in
Written by Abhishek Cricket Trading Analyst · View full profile
Published 8 July 2026 · Last reviewed 21 July 2026