How to Check If a Crypto Wallet Is Linked to a Scam | ICAR

Crypto Wallet Scam

You can check whether a crypto wallet address is linked to a scam in about five minutes using free public tools, before you send funds, and sometimes even after, if you’re trying to understand where money you’ve already sent has gone. This guide walks through the exact steps: reading an address’s history on a blockchain explorer, cross-checking it against public scam-report databases, screening for sanctions exposure, and understanding what these checks can and can’t tell you. (This is a companion piece to our Hub article, Cryptocurrency Investment Scams — How They Work, and our Pillar guide, Investment Scams — The Complete Guide for Victims in 2026.)

3 Free Tools

A blockchain explorer, a scam-report database, and a sanctions check — the three-step process covers most of what a pre-send screen can tell you

Source: Chainabuse (TRM Labs), Etherscan, US Treasury OFAC

Step 1: Read the Address’s History on a Blockchain Explorer

Every cryptocurrency transaction is public, permanent, and viewable through a free blockchain explorer — Etherscan for Ethereum and ERC-20 tokens, Blockscout for several EVM-compatible chains, or Blockchain.com’s explorer for Bitcoin. Paste the wallet address into the search bar and you’ll see its full transaction history: how old the address is, how much has moved through it, and  critically, whether the explorer itself has applied a public label, such as “Phishing,” “Fake_Phishing,” or a scam-report tag contributed by the community.

What to look for: an address created recently with a sudden spike in inbound transactions from many different sources is a common pattern for a scam collection wallet. A very old address with a long, steady, boring transaction history is generally a better sign, though not a guarantee on its own.

Step 2: Cross-Check Against Public Scam-Report Databases

Chainabuse, backed by blockchain intelligence firm TRM Labs, is a free public database where scam victims and researchers report wallet addresses, domains, and social handles tied to fraud. Search the address directly on chainabuse.com — if it’s already been reported, you’ll see the details other victims submitted, which can also help you recognize the broader scam pattern you may be dealing with.

CryptoScamDB is a similar open-source database worth checking as a second source, and PhishTank is useful specifically if a website URL (rather than just a wallet address) is part of what you’re trying to verify. None of these databases has complete coverage  (a scam address that’s brand new may simply not have been reported yet) so a clean result on any one of them isn’t proof of safety on its own.

Step 3: Check for Sanctions Exposure

Separately from scam reporting, the US Treasury’s Office of Foreign Assets Control (OFAC) maintains a Specially Designated Nationals (SDN) list that includes specific cryptocurrency addresses tied to sanctioned individuals, entities, and state-linked hacking operations. Several blockchain explorers and screening tools automatically flag direct matches to this list. An address flagged here isn’t necessarily a scam targeting you personally, but it indicates a serious compliance and legal risk that should stop any transaction on its own.

Step 4: Understand What ‘Proximity’ Means

More advanced tools including visual tracing tools like MetaSleuth, or the professional-grade platforms investigators use, can show whether an address is a close number of “hops” away from a known hack, drainer kit, or stolen-funds cluster, even if the address itself has no direct report against it. This is a meaningfully deeper check than the free tools above provide, and it’s the kind of analysis that becomes necessary once real money is already at stake rather than during a quick pre-send screen.

A practical way to think about hop distance: an address that received funds directly from a wallet already flagged for a hack is one hop away, and represents a serious red flag. An address that received funds from a wallet that itself received funds from a flagged wallet is two hops away — still worth caution, but meaningfully less certain, since legitimate funds and tainted funds do sometimes mix at exchanges and other high-volume destinations. Free tools generally show you zero hops (direct reports against the exact address) and one hop at most; multi-hop analysis is where professional tracing tools add real value beyond what a five-minute manual check can offer.

A Worked Example

Say you’re about to send funds to an address a new online contact has provided, claiming it’s their personal wallet for receiving a trading platform deposit. Paste it into Etherscan: the address was created eleven days ago and has received twenty-three separate incoming transactions from twenty-three different wallets, with almost nothing sent out. That pattern alone (a brand-new address rapidly collecting funds from many unrelated sources) is a strong behavioral signal on its own, independent of whether any explorer label or database report exists yet, since it resembles a collection wallet far more than a personal account. Search the same address on Chainabuse: no reports yet, because the operation may simply be too new. This is exactly the scenario where the address check alone isn’t sufficient — the transaction-pattern read from Step 1 is doing more work here than the database lookup in Step 2, which is why treating this as a single combined process, rather than a pass/fail on any one tool, matters.

Crypto Wallet Scam2

Watch for Address Poisoning

One increasingly common scam tactic deserves specific mention: address poisoning, where an attacker sends a tiny, near-worthless transaction from a wallet address deliberately crafted to look nearly identical to one you’ve genuinely transacted with before, matching the first and last several characters, which is what most wallet apps display by default. The goal is that the next time you go to send funds, you copy the poisoned look-alike address from your transaction history by mistake, rather than typing or pasting the real one. Always verify the complete address, not just the first and last few characters, and consider using an address book or saved-contact feature in your wallet rather than copying from transaction history.

This tactic has grown more common precisely because it doesn’t require tricking a victim into a conversation or relationship at all — it exploits a purely mechanical habit (copying a recent address from history) that even experienced crypto users fall into. Checking the complete string, not just the visible start and end, takes a few extra seconds and closes off this entire category of mistake.

A Simple Three-Tier Framework for the Result

  • Clean across explorer, scam databases, and sanctions check → reasonable to proceed, but consider a small test transaction first for any large or first-time send
  • A faint or indirect link — a few hops from something flagged, or a database report with limited detail — → pause and dig further before sending, or ask a professional to look deeper
  • Any direct phishing label, scam report, or sanctions match → stop; do not send funds to this address under any circumstances

What These Checks Can’t Tell You

A clean result across all of these tools is reassuring, but it isn’t a guarantee, a scam address that’s brand new, or one used for the first time specifically against you, may simply not be reported anywhere yet. These checks are strongest as a screen against known, previously-reported fraud, and weakest against a scheme that’s never operated before. If you’re evaluating a large transaction, a business relationship, or an ongoing “investment” platform rather than a one-off payment, the behavioral red flags covered in our Crypto Investment Scams Hub article matter just as much as the address check itself.

If You’ve Already Sent Funds to a Flagged Address

  1. Don’t send any further funds, regardless of any request to “cover fees” to reverse the transaction — this is itself a common secondary scam.
  2. If the destination address touches a centralized exchange at any point, contact that exchange’s support team immediately with the transaction hash — exchanges can sometimes freeze funds flagged for fraud before they’re withdrawn.
  3. File a report on Chainabuse with the address and transaction details, this helps both law enforcement and future potential victims.
  4. For losses involving multiple wallets or a significant amount, a professional blockchain tracing investigation can map the fund flow well beyond what free tools show.

Frequently Asked Questions

Does a clean result mean the address is definitely safe?

No — it means the address hasn’t been previously reported or flagged, which is meaningful but not a complete guarantee, particularly for a brand-new scam operation with no reporting history yet.

What is address poisoning?

A scam where an attacker sends a near-worthless transaction from a look-alike address designed to match the start and end characters of one you’ve genuinely used, hoping you’ll copy the wrong address from your transaction history on a future send.

Can a wallet address be frozen once flagged?

Only in specific circumstances — some stablecoin issuers like Tether and Circle can blacklist an address at the contract level, typically in response to law enforcement requests, but this isn’t something an individual victim can request directly or expect on demand.

Is an address on the OFAC sanctions list automatically a scam targeting me?

Not necessarily — sanctions listing reflects a different kind of risk (links to sanctioned entities or state-linked hacking groups) than a consumer scam report, but it should stop any transaction regardless of the reason.

When should I get a professional investigator involved instead of using free tools?

Once meaningful funds have already moved, multiple wallets or exchanges are involved, or you need documentation for a law enforcement report or exchange cooperation request — free tools are excellent for a pre-send screen, but professional blockchain tracing goes considerably deeper once a real loss is in question.

logo

About ICAR: International Cyber Asset Recovery (ICAR) is a UK-based forensic investigation and asset recovery firm operating across the UK, US, Canada, Australia, Singapore, and Hong Kong. ICAR works alongside official fraud reporting  providing blockchain tracing, OSINT investigation, and exchange cooperation services that complement law enforcement and bank fraud processes. Free initial case assessments, complete case form or contact support via WhatsApp   

Related Reading

→ Cryptocurrency Investment Scams — How They Work

→Investment Scams — The Complete Guide for Victims in 2026

 

 

 

5 1 vote
Article Rating
Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted
0
Would love your thoughts, please comment.x
()
x