Ilia Zavialov

Wallet checks

Ilia Zavialov on checking a wallet address before you send

English version for the United States.

A crypto transfer is finished the moment the network confirms it, and the string in the destination field decides where the money lands. Most people read the first four characters, glance at the last four and press send. That habit holds until something between the source of the address and the confirmation screen rewrites the middle of the string. This article follows the address from its origin to the payment field, and asks which checks are worth the seconds they cost.

·9 min read·Ilia Zavialov

Ilia Zavialov walking through the steps of checking a wallet address before you send a transfer
Ilia Zavialov walking through the steps of checking a wallet address before you send a transfer

01Where the address in your payment field came from

An address is almost never typed by hand. It arrives in a chat message, an invoice, a QR code, a withdrawal page or an address book entry saved months ago. Each route fails in its own way, and the payment screen carries none of that history. The check starts with the origin of the string, before anyone reads the characters.

An address that arrives in a message inherits the trust of the account that sent it. Accounts get compromised, messages get edited, and the helpful stranger in a project group can be an impostor with a copied avatar. Confirming the string through a second channel, a call to a number you already had, breaks that dependency. A different answer stops the payment there.

Checking a wallet address before you send costs a few seconds, and those seconds are the last point at which a mistake is free. After confirmation the same mistake becomes a report and a wait with no realistic end. The FBI Internet Crime Complaint Center logged 1,008,597 complaints and almost 21 billion dollars of reported losses for 2025, 26 per cent above the previous year. About half of the losses reported in the United States involve cryptocurrency.

02Clipboard swapping, the quiet part of the attack

Clipboard hijacking is simple software. It watches what you copy, recognizes a string shaped like a wallet address and swaps in one the attacker controls. Some versions hold prepared addresses and pick the one whose opening characters match yours. The malware needs no access to your keys, because you sign the payment yourself.

The source stays honest throughout. The invoice, the chat message and the deposit page still show the correct address. The substitution happens between the copy and the paste, and the destination field is the only place it shows. Comparing that field against the source is the whole exercise.

Compare on screen, with the source and the payment field visible at once. Memory keeps the first characters and drops the middle, which is the part the attack relies on. The whole point of checking a wallet address before you send is to catch a substitution made after the address left its source. One wrong paste means the machine stays off transfers until it is cleaned.

Where a payment address comes from, and what checking a wallet address before you send should catch in each case
Source of the addressWhat can go wrongWhat to verify
Message in a chatThe account is compromised or the message was editedConfirm through a second channel, then compare the full string
Paste from the clipboardSoftware swaps the string between the copy and the pasteCompare the pasted value against the source, ends and middle
Scanned QR codeThe code carries an address other than the one printed beside itRead the decoded text on screen before confirming
Withdrawal page on a siteA lookalike domain or a script injected into the pageCheck the domain, then re-read the address inside your account
Saved address book entryThe entry is old or came back from an unverified backupRe-verify after any device change, reinstall or seed restore
Dictated over a callMishearing combined with pressure from the callerAsk for it in writing and run a small test transfer first
Exchange deposit addressThe memo or destination tag is missingConfirm the tag on the same page as the address

03First four, last four, and the middle nobody reads

The habit of reading four characters at each end came from interfaces that display them that way. Generating a key pair whose address begins with a chosen prefix is cheap and ordinary. Matching a prefix and a suffix at once costs more computing time, which a target worth thousands justifies. The result passes the glance test and sends the money elsewhere.

A workable comparison covers both ends and two blocks taken from the middle, read in groups of four. A checksum format rejects an accidental typo, and mixed case carries information the eye tends to normalise. A zero and a capital O, or a lowercase l and a capital I, look identical in many fonts. A monospaced font removes most of that ambiguity.

A routine for checking a wallet address before you send works only when it covers the middle as well as the ends. Reading the address aloud in blocks, or letting the wallet match a saved contact against the pasted value, beats a silent glance. The aim is a comparison that a person in a hurry cannot fake to themselves.

04The test transfer, and what it actually proves

A test transfer sends a small amount first and continues only after the recipient confirms it arrived. It turns an unverifiable string into an observed fact, since the coins either arrive or they do not. Against the sum at risk in the main payment, the test is a rounding error.

The test proves two narrow things. The address is valid on the network you chose, and it sits under the control of the person answering you. It says nothing about that person's intentions, and it expires with this payment, since the address quoted next time may differ.

Two details decide how the test is run. Fees vary by network, so a test costs a fraction of a cent on some chains and real money on others. Exchange deposits often need a memo or tag, and a perfect address sent without it lands in a pooled wallet and becomes a support case.

05Irreversibility, and the missing middle

A confirmed transaction has no counterparty who can be asked to reverse it. Validators apply rules and take no view on intentions, and the funds settle under a key belonging to whoever received them. Getting the money back becomes a voluntary act by that person, which is a poor thing to rely on.

Traditional payments keep an institution in the middle. UK Finance counted 248,070 authorized payment cases worth 576.4 million pounds across 2025, and each had a bank that could be asked to look. A crypto transfer has no such middle, so the defense sits entirely in the interface where the payment is prepared.

Checking a wallet address before you send is the only control placed ahead of the point of no return. Everything after it belongs to recovery, which means tracing, reporting and modest expectations. That imbalance is why a twenty second comparison earns its place in every transfer.

06Making the check part of the payment routine

Verified addresses belong in a labeled address book inside the wallet, confirmed once and reused. The label carries the context: the counterparty, the date of confirmation and the channel that confirmed it. A device change, a reinstall or a seed restore resets that trust, because the entries came back from a backup nobody re-read.

A hardware wallet adds an independent screen showing the transaction as it will be signed. Malware on the computer can rewrite the field in the application, and it has no way to rewrite the small display on the device. Comparing the two screens takes a moment and catches exactly the attack clipboard swapping represents.

This is why checking a wallet address before you send belongs inside the payment, at the level of entering the amount. A rule that applies only to large transfers teaches an attacker where the threshold sits. The routine stays identical for a test payment and for a withdrawal of everything.

07Haste as part of the scheme

Address substitution rarely arrives alone. It travels with a reason to hurry: a deposit window closing, an agent waiting on the line, a price moving while you check. The hurry has one function, which is to push the comparison out of the process.

The Federal Trade Commission reports that four impersonation complaints out of five involved no money lost at all, so attempts far outnumber successes. What separates the two groups is usually a pause and a second opinion. Among people aged 60 and over, the FBI complaint center recorded 6,188 reports about crypto ATM schemes and more than 257 million dollars in losses, and those schemes run on urgency.

One rule sends any request to transfer within minutes straight into the full check, including the call to a number you already trust. Nobody with a legitimate claim loses anything when a payment takes ten extra minutes. Pressure to skip the comparison is itself the signal.

08If the money has already left

The first minutes matter for evidence. Save the transaction hash, the destination address, its source, the timestamps and screenshots of the conversation. Paste the address into a block explorer and record where the funds move next, since that trail is the only material an investigator has.

If the funds land on an exchange deposit address, that exchange is the one place where a human decision remains possible. Contact its compliance channel with the hash and the timeline, and file a report with the national fraud body. Expectations stay low, and the report still counts for the pattern it joins.

Then treat the cause. If the address was swapped on the machine, the machine needs cleaning before the next transfer, and every address book entry that passed through it needs re-verification. If the address came from a compromised account, the owner has to know, because their other contacts are receiving the same string.

09Questions and answers

How do I check a crypto wallet address before sending?

Open the source of the address and the payment field side by side, then compare both ends and at least two blocks from the middle in a monospaced font. For a new counterparty, add a small test transfer and wait for confirmation that it arrived.

Is checking a wallet address before you send enough to stop clipboard malware?

It catches the substitution, since the swapped address differs from the one on the source screen. It does not remove the malware, so a machine that produced one wrong paste should be cleaned before it is used for transfers again.

Do the first and last four characters prove the address is correct?

They prove very little on their own, because an attacker can generate an address with a matching prefix and suffix. The middle of the string is the part that has to be compared.

How much should a test transfer be?

Enough to confirm arrival and small enough that losing it changes nothing, which on most networks means a few units plus the fee. The point is the confirmation from the other side, so wait for it before sending the rest.

Can a crypto transfer be reversed if I sent to the wrong address?

A confirmed transaction cannot be reversed by anyone except the holder of the receiving key. If the funds move on to an exchange, that exchange becomes the only realistic point of contact, and the outcome depends on its compliance team.

What should I do straight after sending to a wrong address?

Record the transaction hash, the address, its source and the timestamps, then follow the funds in a block explorer. File a report with the national fraud body and contact any exchange that receives the money, with the hash and the timeline attached.

Monogram of Ilia Zavialov

Written by Ilia Zavialov, digital security consultant. Profile of Ilia Zavialov

10Read next

Back to the blog