How to Check if a Crypto Address Is a Scam Before You Send

By Alexandr Kerya · · 8 min read

TL;DR - Before sending crypto, screen the recipient address against scam, sanctions, and stolen-funds databases, then verify it character by character against the address you were given.

A crypto transfer is final the moment it confirms. There is no bank to call and no chargeback to file, so the only protection you have runs before you press send. Scammers lean on that finality with fake support agents, spoofed payment addresses, and poisoned transaction histories that drop a lookalike address one tap away from your real one. A thirty-second check on the destination is the cheapest insurance in crypto, and it costs nothing to run.

What does it mean to check if a crypto address is a scam?

An address on its own is just a string of characters with no name attached. Calling one a scam means something specific: it shows up in fraud-report databases, an explorer has tagged it for phishing, it sits a short hop from stolen funds or a sanctioned entity, or it simply is not the address you meant to pay. A pre-send check reads public on-chain data and known label sets, then tells you which of those apply before your money moves.

  • Reported scams: addresses that past victims submitted to public abuse and phishing databases.
  • Sanctions exposure: direct or near links to addresses on the OFAC SDN list.
  • Stolen-funds and drainer proximity: hops to clusters tied to hacks and wallet-drainer kits.
  • Phishing labels: addresses that explorers have tagged after confirmed scam reports.
  • Address match: whether the string in front of you is the one you were actually handed.
Pre-send screening flow: paste the recipient address, run the checks, read the verdict.A recipient address is checked against scam reports, sanctions lists, and stolen-funds clusters, producing a clear, caution, or stop verdict before funds are sent.RecipientaddressCheck: scam reports,sanctions, stolenfunds, address matchVerdict beforeyou sendThe check runs on public data, so it costs nothing and reveals no keys.
A pre-send check compares the recipient address against scam reports, sanctions lists, and stolen-funds clusters before any funds move.

How do you screen a crypto address before sending?

The order of steps matters more than any single tool. Most losses happen because the wrong address gets copied in the first place, not because a screen was missing. Run these in sequence and you close both gaps at once.

  1. Copy the destination address from the original request, never from a transaction sitting in your own wallet history.
  2. Read the whole string, not just the first and last few characters, since lookalike addresses are built to match the ends.
  3. Paste it into a screening tool to check sanctions, scam reports, mixer contact, and stolen-funds exposure.
  4. Send a small test amount first on any large or first-time transfer, then confirm it arrived.
  5. Confirm the address with the recipient over a channel you started yourself before releasing the rest.

You can do parts of this by hand. A block explorer such as Etherscan shows an address's history and any phishing label it has earned, and public scam-report sites let you search a string against past complaints. The gap is coverage and speed: you are checking one list at a time, on one chain, while the person on the other end waits. Rather than stitching those sources together by hand, screen the address with Plastron to see sanctions, mixer, scam, and stolen-funds exposure across Ethereum and six EVM chains at once, with no signup and no keys. For a single address you can also run a focused crypto scam check or a broader crypto address screening.

What red flags mark a crypto address as a scam?

Some signals show up in the data, and some show up in how the address reached you. Treat any of the following as a reason to stop and verify before sending.

  • The address arrived through an unsolicited message, a fake support ticket, or a giveaway promising to double your funds.
  • It carries a phishing or fraud label on a block explorer, or it appears in a public scam-report database.
  • Its funds trace back a hop or two to a known drainer, a hacked protocol, or a sanctioned service.
  • It closely resembles an address already in your history but differs in the middle characters, the hallmark of address poisoning.
  • Someone is rushing you, because urgency is the tool that stops people from running the check at all.

No single flag is proof on its own, but a screen turns these from a gut feeling into a result you can read. A clean history with no labels and no proximity to flagged clusters is a reassuring sign; a direct link to a reported scam address is a hard stop.

Why can't you reverse a payment to a scam address?

Blockchains are built to make confirmed transactions permanent. Once a transfer is mined, no central operator can claw it back, which is the same property that makes crypto useful and makes scams so costly. Recovery, when it happens at all, depends on the receiving exchange freezing the funds after you report them, and that only works if the scammer cashes out somewhere with compliance controls.

Stablecoins add one wrinkle that cuts both ways. Issuers like Tether and Circle can blacklist an address at the contract level, which has frozen large sums tied to theft. That power belongs to the issuer acting on law-enforcement requests, though, not to you. It will not return your money on demand, and it can just as easily freeze tainted coins that land in your own wallet. The reliable move is to never send to a flagged address in the first place.

Pre-send decision tiers: send, pause, or stop based on the screening result.Three tiers. A clean history with no labels means send after a small test. A faint indirect link or unverified address means pause and confirm. A phishing label, reported scam, or direct flagged link means stop and do not send.What the screening result tells you to doSENDClean history, nolabels, addressverified.Test with a smallamount first.PAUSEFaint indirect link oraddress not yetconfirmed.Confirm over atrusted channel.STOPPhishing label, reportedscam, or direct linkto flagged funds.Do not send.
Read the screening result as a three-tier decision: send after a test when clean, pause to confirm on a faint link, and stop on any phishing label or reported scam.

How do you avoid address-poisoning lookalike scams?

Address poisoning is the scam that defeats a careless copy-paste. The attacker sends you a tiny or zero-value transaction from an address engineered to share the first and last characters of one you use often. Later, when you copy an address from your own history to repeat a payment, you grab theirs by mistake. The screen would have caught it, but the habit of copying from history is what put you at risk.

The defense is mechanical. Always copy the destination from the original request rather than from a past transaction, verify the full string instead of the truncated ends your wallet shows, and save trusted addresses to an address book so you are selecting a saved label, not re-pasting a raw string. A deeper walk through this specific trap lives in the guide on address poisoning and lookalike addresses, and the broader mechanics sit in what crypto wallet screening checks.

FAQ

Can I check a crypto address for free before sending?

Yes. Public block explorers show an address's history and any phishing label, scam-report databases let you search a string against past complaints, and free screening tools combine those signals into a single risk read. None of these require an account or access to your wallet, since they only read public on-chain data.

Does sending a small test amount actually protect me?

It protects you against a wrong or mistyped address, because you can confirm the test arrived before sending the full amount. It does not protect you against a scam address that genuinely controls the funds, so pair the test with a screening check and an out-of-band confirmation for any large transfer.

What should I do if I already sent crypto to a scam address?

Act fast and document everything. Report the transaction to the receiving exchange if you can identify one, file a report with the relevant authority, and keep the transaction hashes. Recovery is rare and depends on the funds reaching a service that will freeze them, which is why a check before sending matters far more than any step afterward.

Is an address safe just because it has no scam label yet?

Not necessarily. Labels lag behind fresh scams, so a new attacker address can be clean on paper for days. Read the full picture instead of one flag: check how the funds got there, whether the address is close to flagged clusters, and whether it matches the one you were actually given.

Disclaimer: This article is for educational and informational purposes only and is not legal, financial, tax, or compliance advice. Crypto carries risk; you act on this information at your own risk. Always do your own research and consult a qualified professional before making decisions. Views are the author's own and do not constitute financial, legal, or investment advice.

About Plastron

Plastron is a free, non-custodial wallet screening tool. It checks Ethereum and six EVM chains for AML and KYT risk — sanctions exposure, mixer contact, and stolen-funds proximity — and returns a risk report in seconds. It reads public on-chain data only: it never takes custody of funds and never asks for private keys.

How Plastron works and who runs it →

Keep reading

Address Poisoning: The Lookalike Address in Your HistoryWhat Is Crypto Wallet Screening? A Plain-English GuideCan Your Wallet Be Frozen If You Receive USDT From a Scammer?Can Wallet Screening See Through an EIP-7702 Delegation?