Crypto transactions are irreversible. There's no bank to call, no chargeback, no undo — if coins go to the wrong address, they're gone. That single fact makes one habit non-negotiable for every swap: verify the address before you send. And not just by glancing at it — attackers have clever ways to put the wrong address in front of you, including through QR codes that look perfectly legitimate. This guide explains how address deception works and exactly how to check, every time.
This is a safety guide for everyone moving crypto. A few seconds of verification prevents the single most expensive mistake in crypto.
Why the address is the thing attackers target
When you swap, you deal with two addresses: the exchange's one-time deposit address (where you send), and your own payout address (where you receive). Either can be tampered with, and the trick is almost always to get you to send to an address you think is right but isn't:
- Clipboard hijacking. Malware watches your clipboard and silently replaces a copied crypto address with the attacker's. You paste, it looks address-shaped, you send — to them.
- Malicious or compromised pages. A fake or hacked swap site can display a different deposit address than the real service would. Script-heavy pages are especially risky, since JavaScript can alter what's shown on the fly.
- Address poisoning. Attackers send you tiny transactions from a lookalike address (same first and last characters) so it appears in your history; later you copy it from there by mistake.
- QR swaps. A QR code is just an encoded address — and the code can encode something different from the human-readable text printed next to it, or be replaced entirely (including physical sticker scams).
How to verify an address — every time
Make this a fixed routine, not a "when I remember" thing:
- Get the address from the real source. Read the deposit address directly from the exchange on its official site or verified onion — never from a link in a message or an address sitting in your transaction history.
- Check the first and last characters. Compare at least the first 6 and last 6 characters against the source. Don't trust the middle, and don't trust "it starts right" alone — poisoning attacks match the ends, so verify both, and ideally the whole string for large sends.
- Confirm the network. Make sure the address is for the right chain (BTC to Bitcoin, LTC to Litecoin, and so on). Same-looking prefixes across chains are a real trap.
- Re-check after pasting. Immediately after you paste, look again — if clipboard malware swapped it, the pasted value won't match what you copied.
- Send a small test amount first for anything large. Confirm it lands at the right place — a block explorer like mempool.space lets you watch the transaction confirm — then send the rest.
Using a QR code? Still verify it
Scanning a QR feels safer than typing, but it bypasses your eyes — so add this step: after you scan, your wallet displays the address it decoded. Read that decoded address and confirm it against the known-good first/last characters before you approve the send. A QR can encode a different address than the text shown beside it, or be a swapped/printed fake, and you'll only catch it by checking what your wallet actually parsed. Two rules make QRs safe:
- When receiving, generate the QR from your own wallet, so you know it's yours.
- When sending, never trust the QR blindly — treat the decoded address on your screen exactly like a pasted one and verify the characters.
The QR is a convenience for entry, not a substitute for verification. Always know what the address is and confirm it.
What not to do
- Don't reuse an address from your history. Always pull a fresh one from the source — this defeats address poisoning.
- Don't verify only the first few characters. Check both ends.
- Don't approve a send on a script-heavy page without cross-checking the address in your wallet or against the exchange's stated value.
- Don't rush. Attackers rely on you being in a hurry; the irreversibility is on their side, not yours.
Swap with confidence on SwapRaven
Verifying the address is the cheapest insurance in crypto — a few seconds against a total, unrecoverable loss. Pair it with the rest of the routine: reach exchanges through a vetted directory rather than search ads, prefer JS-light, privacy-friendly swaps, and use a test send for large amounts. SwapRaven grades no-KYC instant swaps on trust and transparency so you start from a legitimate site — then it's on you to confirm the address, every single time, before you hit send.

Comments (0)
Leave a comment