Blooket Rip Offs: How to Spot a Fake Blooket Site

Duplicate login forms glowing on a dark screen - spotting fake Blooket sites

Blooket rip offs and fake Blooket sites are a predictable consequence of a popular classroom game: heavy school traffic, a format that is easy to copy, and a large audience of students looking for shortcuts or ways around a school block. This page is about recognising the fakes specifically — the ones designed to be mistaken for the real thing.

For the broader landscape including harmless clones and real competitors, see Blooket knockoffs and off brand Blooket sites.

What a Fake Site Is Trying to Get

Fakes are not built for fun. Each has a payload, and knowing which one tells you how bad the visit was:

  • Ad revenue. The mildest. You see adverts, close the tab, nothing lasting happens.
  • An extension install. Worse than it sounds. An extension with permission to read pages sees every site you visit, including school systems and anything personal.
  • A sign-in. The serious one. A school Google account carries email, coursework and often access to other district systems.
  • A download. The most serious. Running an unknown executable gives it whatever access your user account has.

The Tells

The address is nearly right

One character different, an extra word, an unusual ending. Reading the address bar character by character before typing a password catches almost every fake, and it takes three seconds.

It asks you to log in to do something that never needs a login

Joining a game needs a code and a name. Full stop. Any page requiring a Google sign-in to let you join is asking for something it does not need.

It promises free things

Coins, tokens, blooks, unlimited items, automatic answers. Nothing on the other side of that button is real. The button is the product.

The polish is uneven

Fakes copy the sign-in page carefully and everything else carelessly. Click any other link — about, privacy, help. Dead links across the rest of the site is a strong signal.

You arrived from a link someone sent you

Chat messages, video descriptions and comment sections are the main distribution channels. Typing the address yourself removes most of the risk.

What Happens After a Sign-In

Two things, usually:

  1. The credentials are used or sold. The most common visible symptom is classmates receiving spam from the student’s address, which is how most of these are discovered.
  2. An authorised app is left behind. Sign-in through a phishing flow can leave a third-party app with ongoing access even after the password is changed. Revoking app access is a separate step, and it is the one people forget.

Recovery Steps

  1. Change the password from a device you trust.
  2. Revoke third-party app access in the Google account security settings. This is the step that actually cuts off ongoing access.
  3. Sign out of all sessions from the same page.
  4. Tell school IT. Early reporting is always better received than discovery via spam complaints.
  5. Remove any installed extension.
  6. If a file was downloaded and run, say so. The device needs checking, not just the account.

For Parents

If you have found one of these in a browser history, the useful framing is “that site was trying to take your school account”, not “you tried to cheat”. It is more accurate and it gets a more honest conversation.

Three practical checks: has the school password been changed since, are there unfamiliar browser extensions, and was anything downloaded and run.

For Schools

  • Classify these as phishing, not games. Credential harvesting is the actual behaviour, and phishing categories update far more aggressively than game categories.
  • Do not chase individual domains. New ones appear constantly.
  • Teach the address-bar check once, properly. It is the single most transferable digital-safety skill on this page, and it applies far beyond quiz games.
  • Reduce the demand. A large share of fake-site traffic comes from students trying to get around a school block. Reviewing whether the real site should be blocked at all removes the motive.

Why This Keeps Working

Fake sites succeed because they target a moment of low attention: a student in a rush, on a school device, wanting to join a game before the round starts. Nobody inspects an address bar in that state.

Which is exactly why the habit has to be built before the moment — and why “only ever sign in on the site you typed yourself” is a better rule than any list of domains to avoid.

Frequently asked questions

How do I know if a Blooket site is fake?

Read the address bar character by character, and ask whether a login is genuinely needed. Joining a game requires only a code and a name.

What do fake Blooket sites want?

Ad revenue, an extension install, a Google sign-in, or a download. The sign-in and download versions are the ones that cause lasting harm.

What should I do if I logged in on a fake Blooket site?

Change your password, revoke third-party app access, sign out of all sessions, tell school IT, and remove any extension you installed.

Why is revoking app access necessary if I changed my password?

A phishing sign-in can leave a third-party app authorised on the account, and that access survives a password change until it is revoked.

Do fake Blooket sites give free coins?

No. The promise is the bait. Nothing is delivered on the other side of the button.

How can schools reduce fake site visits?

Classify those domains as phishing, teach the address-bar check, and review whether blocking the real site is pushing students toward lookalikes in the first place.

Keep exploring Gimkit Info

Scroll to Top