{"id":2073,"date":"2026-08-20T13:13:33","date_gmt":"2026-08-20T13:13:33","guid":{"rendered":"https:\/\/icar-global.org\/blog\/?p=2073"},"modified":"2026-08-31T12:29:06","modified_gmt":"2026-08-31T12:29:06","slug":"check-crypto-wallet-address-scam","status":"publish","type":"post","link":"https:\/\/icar-global.org\/blog\/check-crypto-wallet-address-scam\/","title":{"rendered":"How to Check If a Crypto Wallet Is Linked to a Scam | ICAR"},"content":{"rendered":"<p>You can check whether a crypto wallet address is linked to a scam in about five minutes using free public tools, before you send funds, and sometimes even after, if you&#8217;re trying to understand where money you&#8217;ve already sent has gone. This guide walks through the exact steps: reading an address&#8217;s history on a blockchain explorer, cross-checking it against public scam-report databases, screening for sanctions exposure, and understanding what these checks can and can&#8217;t tell you. (This is a companion piece to our Hub article, <em><a href=\"https:\/\/icar-global.org\/blog\/cryptocurrency-investment-scams-how-they-work-in-2026\/\">Cryptocurrency Investment Scams \u2014 How They Work<\/a><\/em>, and our Pillar guide, <em><a href=\"https:\/\/icar-global.org\/blog\/investment-scams-the-complete-guide-for-victims-in-2026\/\">Investment Scams \u2014 The Complete Guide for Victims in 2026<\/a><\/em>.)<\/p>\n<table width=\"100%\">\n<tbody>\n<tr>\n<td><strong>3 Free Tools<\/strong><\/p>\n<p>A blockchain explorer, a scam-report database, and a sanctions check \u2014 the three-step process covers most of what a pre-send screen can tell you<\/p>\n<p><em>Source: Chainabuse (TRM Labs), Etherscan, US Treasury OFAC<\/em><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 counter-hierarchy ez-toc-counter ez-toc-white ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #999;color:#999\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #999;color:#999\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/icar-global.org\/blog\/check-crypto-wallet-address-scam\/#Step_1_Read_the_Addresss_History_on_a_Blockchain_Explorer\" >Step 1: Read the Address&#8217;s History on a Blockchain Explorer<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/icar-global.org\/blog\/check-crypto-wallet-address-scam\/#Step_2_Cross-Check_Against_Public_Scam-Report_Databases\" >Step 2: Cross-Check Against Public Scam-Report Databases<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/icar-global.org\/blog\/check-crypto-wallet-address-scam\/#Step_3_Check_for_Sanctions_Exposure\" >Step 3: Check for Sanctions Exposure<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/icar-global.org\/blog\/check-crypto-wallet-address-scam\/#Step_4_Understand_What_%E2%80%98Proximity_Means\" >Step 4: Understand What &#8216;Proximity&#8217; Means<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/icar-global.org\/blog\/check-crypto-wallet-address-scam\/#A_Worked_Example\" >A Worked Example<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/icar-global.org\/blog\/check-crypto-wallet-address-scam\/#Watch_for_Address_Poisoning\" >Watch for Address Poisoning<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/icar-global.org\/blog\/check-crypto-wallet-address-scam\/#A_Simple_Three-Tier_Framework_for_the_Result\" >A Simple Three-Tier Framework for the Result<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/icar-global.org\/blog\/check-crypto-wallet-address-scam\/#What_These_Checks_Cant_Tell_You\" >What These Checks Can&#8217;t Tell You<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/icar-global.org\/blog\/check-crypto-wallet-address-scam\/#If_Youve_Already_Sent_Funds_to_a_Flagged_Address\" >If You&#8217;ve Already Sent Funds to a Flagged Address<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/icar-global.org\/blog\/check-crypto-wallet-address-scam\/#Frequently_Asked_Questions\" >Frequently Asked Questions<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/icar-global.org\/blog\/check-crypto-wallet-address-scam\/#Does_a_clean_result_mean_the_address_is_definitely_safe\" >Does a clean result mean the address is definitely safe?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-12\" href=\"https:\/\/icar-global.org\/blog\/check-crypto-wallet-address-scam\/#What_is_address_poisoning\" >What is address poisoning?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-13\" href=\"https:\/\/icar-global.org\/blog\/check-crypto-wallet-address-scam\/#Can_a_wallet_address_be_frozen_once_flagged\" >Can a wallet address be frozen once flagged?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-14\" href=\"https:\/\/icar-global.org\/blog\/check-crypto-wallet-address-scam\/#Is_an_address_on_the_OFAC_sanctions_list_automatically_a_scam_targeting_me\" >Is an address on the OFAC sanctions list automatically a scam targeting me?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-15\" href=\"https:\/\/icar-global.org\/blog\/check-crypto-wallet-address-scam\/#When_should_I_get_a_professional_investigator_involved_instead_of_using_free_tools\" >When should I get a professional investigator involved instead of using free tools?<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-16\" href=\"https:\/\/icar-global.org\/blog\/check-crypto-wallet-address-scam\/#Related_Reading\" >Related Reading<\/a><\/li><\/ul><\/nav><\/div>\n<h2><span class=\"ez-toc-section\" id=\"Step_1_Read_the_Addresss_History_on_a_Blockchain_Explorer\"><\/span>Step 1: Read the Address&#8217;s History on a Blockchain Explorer<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Every cryptocurrency transaction is public, permanent, and viewable through a free blockchain explorer \u2014 Etherscan for Ethereum and ERC-20 tokens, Blockscout for several EVM-compatible chains, or Blockchain.com&#8217;s explorer for Bitcoin. Paste the wallet address into the search bar and you&#8217;ll see its full transaction history: how old the address is, how much has moved through it, and\u00a0 critically, whether the explorer itself has applied a public label, such as &#8220;Phishing,&#8221; &#8220;Fake_Phishing,&#8221; or a scam-report tag contributed by the community.<\/p>\n<p>What to look for: an address created recently with a sudden spike in inbound transactions from many different sources is a common pattern for a scam collection wallet. A very old address with a long, steady, boring transaction history is generally a better sign, though not a guarantee on its own.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Step_2_Cross-Check_Against_Public_Scam-Report_Databases\"><\/span>Step 2: Cross-Check Against Public Scam-Report Databases<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Chainabuse, backed by blockchain intelligence firm TRM Labs, is a free public database where scam victims and researchers report wallet addresses, domains, and social handles tied to fraud. Search the address directly on chainabuse.com \u2014 if it&#8217;s already been reported, you&#8217;ll see the details other victims submitted, which can also help you recognize the broader scam pattern you may be dealing with.<\/p>\n<p>CryptoScamDB is a similar open-source database worth checking as a second source, and PhishTank is useful specifically if a website URL (rather than just a wallet address) is part of what you&#8217;re trying to verify. None of these databases has complete coverage\u00a0 (a scam address that&#8217;s brand new may simply not have been reported yet) so a clean result on any one of them isn&#8217;t proof of safety on its own.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Step_3_Check_for_Sanctions_Exposure\"><\/span>Step 3: Check for Sanctions Exposure<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Separately from scam reporting, the US Treasury&#8217;s Office of Foreign Assets Control (OFAC) maintains a Specially Designated Nationals (SDN) list that includes specific cryptocurrency addresses tied to sanctioned individuals, entities, and state-linked hacking operations. Several blockchain explorers and screening tools automatically flag direct matches to this list. An address flagged here isn&#8217;t necessarily a scam targeting you personally, but it indicates a serious compliance and legal risk that should stop any transaction on its own.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Step_4_Understand_What_%E2%80%98Proximity_Means\"><\/span>Step 4: Understand What &#8216;Proximity&#8217; Means<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>More advanced tools including visual tracing tools like MetaSleuth, or the professional-grade platforms investigators use, can show whether an address is a close number of &#8220;hops&#8221; away from a known hack, drainer kit, or stolen-funds cluster, even if the address itself has no direct report against it. This is a meaningfully deeper check than the free tools above provide, and it&#8217;s the kind of analysis that becomes necessary once real money is already at stake rather than during a quick pre-send screen.<\/p>\n<p>A practical way to think about hop distance: an address that received funds directly from a wallet already flagged for a hack is one hop away, and represents a serious red flag. An address that received funds from a wallet that itself received funds from a flagged wallet is two hops away \u2014 still worth caution, but meaningfully less certain, since legitimate funds and tainted funds do sometimes mix at exchanges and other high-volume destinations. Free tools generally show you zero hops (direct reports against the exact address) and one hop at most; multi-hop analysis is where professional tracing tools add real value beyond what a five-minute manual check can offer.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"A_Worked_Example\"><\/span>A Worked Example<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Say you&#8217;re about to send funds to an address a new online contact has provided, claiming it&#8217;s their personal wallet for receiving a trading platform deposit. Paste it into Etherscan: the address was created eleven days ago and has received twenty-three separate incoming transactions from twenty-three different wallets, with almost nothing sent out. That pattern alone (a brand-new address rapidly collecting funds from many unrelated sources) is a strong behavioral signal on its own, independent of whether any explorer label or database report exists yet, since it resembles a collection wallet far more than a personal account. Search the same address on Chainabuse: no reports yet, because the operation may simply be too new. This is exactly the scenario where the address check alone isn&#8217;t sufficient \u2014 the transaction-pattern read from Step 1 is doing more work here than the database lookup in Step 2, which is why treating this as a single combined process, rather than a pass\/fail on any one tool, matters.<\/p>\n<h2><img fetchpriority=\"high\" decoding=\"async\" class=\"alignnone size-large wp-image-2078\" src=\"https:\/\/icar-global.org\/blog\/wp-content\/uploads\/2026\/08\/crypto_wallet_scam2-1024x717.jpg\" alt=\"Crypto Wallet Scam2\" width=\"1024\" height=\"717\" srcset=\"https:\/\/icar-global.org\/blog\/wp-content\/uploads\/2026\/08\/crypto_wallet_scam2-1024x717.jpg 1024w, https:\/\/icar-global.org\/blog\/wp-content\/uploads\/2026\/08\/crypto_wallet_scam2-300x210.jpg 300w, https:\/\/icar-global.org\/blog\/wp-content\/uploads\/2026\/08\/crypto_wallet_scam2-768x538.jpg 768w, https:\/\/icar-global.org\/blog\/wp-content\/uploads\/2026\/08\/crypto_wallet_scam2.jpg 1080w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/h2>\n<h2><span class=\"ez-toc-section\" id=\"Watch_for_Address_Poisoning\"><\/span>Watch for Address Poisoning<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>One increasingly common scam tactic deserves specific mention: address poisoning, where an attacker sends a tiny, near-worthless transaction from a wallet address deliberately crafted to look nearly identical to one you&#8217;ve genuinely transacted with before, matching the first and last several characters, which is what most wallet apps display by default. The goal is that the next time you go to send funds, you copy the poisoned look-alike address from your transaction history by mistake, rather than typing or pasting the real one. Always verify the complete address, not just the first and last few characters, and consider using an address book or saved-contact feature in your wallet rather than copying from transaction history.<\/p>\n<p>This tactic has grown more common precisely because it doesn&#8217;t require tricking a victim into a conversation or relationship at all \u2014 it exploits a purely mechanical habit (copying a recent address from history) that even experienced crypto users fall into. Checking the complete string, not just the visible start and end, takes a few extra seconds and closes off this entire category of mistake.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"A_Simple_Three-Tier_Framework_for_the_Result\"><\/span>A Simple Three-Tier Framework for the Result<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<ul>\n<li>Clean across explorer, scam databases, and sanctions check \u2192 reasonable to proceed, but consider a small test transaction first for any large or first-time send<\/li>\n<li>A faint or indirect link \u2014 a few hops from something flagged, or a database report with limited detail \u2014 \u2192 pause and dig further before sending, or ask a professional to look deeper<\/li>\n<li>Any direct phishing label, scam report, or sanctions match \u2192 stop; do not send funds to this address under any circumstances<\/li>\n<\/ul>\n<h2><span class=\"ez-toc-section\" id=\"What_These_Checks_Cant_Tell_You\"><\/span>What These Checks Can&#8217;t Tell You<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>A clean result across all of these tools is reassuring, but it isn&#8217;t a guarantee, a scam address that&#8217;s brand new, or one used for the first time specifically against you, may simply not be reported anywhere yet. These checks are strongest as a screen against known, previously-reported fraud, and weakest against a scheme that&#8217;s never operated before. If you&#8217;re evaluating a large transaction, a business relationship, or an ongoing &#8220;investment&#8221; platform rather than a one-off payment, the behavioral red flags covered in our Crypto Investment Scams Hub article matter just as much as the address check itself.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"If_Youve_Already_Sent_Funds_to_a_Flagged_Address\"><\/span>If You&#8217;ve Already Sent Funds to a Flagged Address<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<ol>\n<li>Don&#8217;t send any further funds, regardless of any request to &#8220;cover fees&#8221; to reverse the transaction \u2014 this is itself a common secondary scam.<\/li>\n<li>If the destination address touches a centralized exchange at any point, contact that exchange&#8217;s support team immediately with the transaction hash \u2014 exchanges can sometimes freeze funds flagged for fraud before they&#8217;re withdrawn.<\/li>\n<li>File a report on Chainabuse with the address and transaction details, this helps both law enforcement and future potential victims.<\/li>\n<li>For losses involving multiple wallets or a significant amount, a professional blockchain tracing investigation can map the fund flow well beyond what free tools show.<\/li>\n<\/ol>\n<h2><span class=\"ez-toc-section\" id=\"Frequently_Asked_Questions\"><\/span>Frequently Asked Questions<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<h3><span class=\"ez-toc-section\" id=\"Does_a_clean_result_mean_the_address_is_definitely_safe\"><\/span><strong>Does a clean result mean the address is definitely safe?<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>No \u2014 it means the address hasn&#8217;t been previously reported or flagged, which is meaningful but not a complete guarantee, particularly for a brand-new scam operation with no reporting history yet.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"What_is_address_poisoning\"><\/span><strong>What is address poisoning?<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>A scam where an attacker sends a near-worthless transaction from a look-alike address designed to match the start and end characters of one you&#8217;ve genuinely used, hoping you&#8217;ll copy the wrong address from your transaction history on a future send.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Can_a_wallet_address_be_frozen_once_flagged\"><\/span><strong>Can a wallet address be frozen once flagged?<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Only in specific circumstances \u2014 some stablecoin issuers like Tether and Circle can blacklist an address at the contract level, typically in response to law enforcement requests, but this isn&#8217;t something an individual victim can request directly or expect on demand.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Is_an_address_on_the_OFAC_sanctions_list_automatically_a_scam_targeting_me\"><\/span><strong>Is an address on the OFAC sanctions list automatically a scam targeting me?<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Not necessarily \u2014 sanctions listing reflects a different kind of risk (links to sanctioned entities or state-linked hacking groups) than a consumer scam report, but it should stop any transaction regardless of the reason.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"When_should_I_get_a_professional_investigator_involved_instead_of_using_free_tools\"><\/span><strong>When should I get a professional investigator involved instead of using free tools?<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Once meaningful funds have already moved, multiple wallets or exchanges are involved, or you need documentation for a law enforcement report or exchange cooperation request \u2014 free tools are excellent for a pre-send screen, but professional blockchain tracing goes considerably deeper once a real loss is in question.<\/p>\n<p><img decoding=\"async\" class=\"alignnone size-full wp-image-1534\" src=\"https:\/\/icar-global.org\/blog\/wp-content\/uploads\/2026\/03\/cropped-logo-2.png\" alt=\"logo\" width=\"512\" height=\"512\" srcset=\"https:\/\/icar-global.org\/blog\/wp-content\/uploads\/2026\/03\/cropped-logo-2.png 512w, https:\/\/icar-global.org\/blog\/wp-content\/uploads\/2026\/03\/cropped-logo-2-300x300.png 300w, https:\/\/icar-global.org\/blog\/wp-content\/uploads\/2026\/03\/cropped-logo-2-150x150.png 150w, https:\/\/icar-global.org\/blog\/wp-content\/uploads\/2026\/03\/cropped-logo-2-270x270.png 270w, https:\/\/icar-global.org\/blog\/wp-content\/uploads\/2026\/03\/cropped-logo-2-192x192.png 192w, https:\/\/icar-global.org\/blog\/wp-content\/uploads\/2026\/03\/cropped-logo-2-180x180.png 180w, https:\/\/icar-global.org\/blog\/wp-content\/uploads\/2026\/03\/cropped-logo-2-32x32.png 32w\" sizes=\"(max-width: 512px) 100vw, 512px\" \/><\/p>\n<p><strong>About ICAR: <\/strong>International Cyber Asset Recovery (ICAR) is a UK-based forensic investigation and asset recovery firm operating across the UK, US, Canada, Australia, Singapore, and Hong Kong. ICAR works alongside official fraud reporting\u00a0 providing blockchain tracing, OSINT investigation, and exchange cooperation services that complement law enforcement and bank fraud processes. Free initial case assessments, complete <span style=\"color: #3366ff;\"><strong><a style=\"color: #3366ff;\" href=\"https:\/\/tally.so\/r\/NpVNlp\">case form <\/a><\/strong><\/span>or contact support via<a href=\"https:\/\/wa.me\/447426426707\"><strong><span style=\"color: #3366ff;\"> WhatsApp\u00a0<\/span>\u00a0\u00a0<\/strong><\/a><\/p>\n<h2><span class=\"ez-toc-section\" id=\"Related_Reading\"><\/span>Related Reading<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p><em>\u2192<strong> <span style=\"color: #3366ff;\"><a style=\"color: #3366ff;\" href=\"https:\/\/icar-global.org\/blog\/cryptocurrency-investment-scams-how-they-work-in-2026\/\">Cryptocurrency Investment Scams \u2014 How They Work<\/a><\/span><\/strong><\/em><\/p>\n<p><strong><em>\u2192<span style=\"color: #3366ff;\"><a style=\"color: #3366ff;\" href=\"https:\/\/icar-global.org\/blog\/investment-scams-the-complete-guide-for-victims-in-2026\/\">Investment Scams \u2014 The Complete Guide for Victims in 2026<\/a><\/span><\/em><\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>You can check whether a crypto wallet address is linked to a scam in about five minutes using free public tools, before you send funds, and sometimes even after, if you&#8217;re trying to understand where money you&#8217;ve already sent has gone. This guide walks through the exact steps: reading an address&#8217;s history on a blockchain explorer, cross-checking it against public scam-report databases, screening for sanctions exposure, and understanding what these checks can and can&#8217;t tell you. (This is a companion piece to our Hub article, Cryptocurrency Investment Scams \u2014 How They Work, and our Pillar guide, Investment Scams \u2014 The Complete Guide for Victims in 2026.) 3 Free Tools A blockchain explorer, a scam-report database, and a sanctions check \u2014 the three-step process covers most of what a pre-send screen can tell you Source: Chainabuse (TRM Labs), Etherscan, US Treasury OFAC Step 1: Read the Address&#8217;s History on a Blockchain Explorer Every cryptocurrency transaction is public, permanent, and viewable through a free blockchain explorer \u2014 Etherscan for Ethereum and ERC-20 tokens, Blockscout for several EVM-compatible chains, or Blockchain.com&#8217;s explorer for Bitcoin. Paste the wallet address into the search bar and you&#8217;ll see its full transaction history: how old the address is, how much has moved through it, and\u00a0 critically, whether the explorer itself has applied a public label, such as &#8220;Phishing,&#8221; &#8220;Fake_Phishing,&#8221; or a scam-report tag contributed by the community. What to look for: an address created recently with a sudden spike in inbound transactions from many different sources is a common pattern for a scam collection wallet. A very old address with a long, steady, boring transaction history is generally a better sign, though not a guarantee on its own. Step 2: Cross-Check Against Public Scam-Report Databases Chainabuse, backed by blockchain intelligence firm TRM Labs, is a free public database where scam victims and researchers report wallet addresses, domains, and social handles tied to fraud. Search the address directly on chainabuse.com \u2014 if it&#8217;s already been reported, you&#8217;ll see the details other victims submitted, which can also help you recognize the broader scam pattern you may be dealing with. CryptoScamDB is a similar open-source database worth checking as a second source, and PhishTank is useful specifically if a website URL (rather than just a wallet address) is part of what you&#8217;re trying to verify. None of these databases has complete coverage\u00a0 (a scam address that&#8217;s brand new may simply not have been reported yet) so a clean result on any one of them isn&#8217;t proof of safety on its own. Step 3: Check for Sanctions Exposure Separately from scam reporting, the US Treasury&#8217;s Office of Foreign Assets Control (OFAC) maintains a Specially Designated Nationals (SDN) list that includes specific cryptocurrency addresses tied to sanctioned individuals, entities, and state-linked hacking operations. Several blockchain explorers and screening tools automatically flag direct matches to this list. An address flagged here isn&#8217;t necessarily a scam targeting you personally, but it indicates a serious compliance and legal risk that should stop any transaction on its own. Step 4: Understand What &#8216;Proximity&#8217; Means More advanced tools including visual tracing tools like MetaSleuth, or the professional-grade platforms investigators use, can show whether an address is a close number of &#8220;hops&#8221; away from a known hack, drainer kit, or stolen-funds cluster, even if the address itself has no direct report against it. This is a meaningfully deeper check than the free tools above provide, and it&#8217;s the kind of analysis that becomes necessary once real money is already at stake rather than during a quick pre-send screen. A practical way to think about hop distance: an address that received funds directly from a wallet already flagged for a hack is one hop away, and represents a serious red flag. An address that received funds from a wallet that itself received funds from a flagged wallet is two hops away \u2014 still worth caution, but meaningfully less certain, since legitimate funds and tainted funds do sometimes mix at exchanges and other high-volume destinations. Free tools generally show you zero hops (direct reports against the exact address) and one hop at most; multi-hop analysis is where professional tracing tools add real value beyond what a five-minute manual check can offer. A Worked Example Say you&#8217;re about to send funds to an address a new online contact has provided, claiming it&#8217;s their personal wallet for receiving a trading platform deposit. Paste it into Etherscan: the address was created eleven days ago and has received twenty-three separate incoming transactions from twenty-three different wallets, with almost nothing sent out. That pattern alone (a brand-new address rapidly collecting funds from many unrelated sources) is a strong behavioral signal on its own, independent of whether any explorer label or database report exists yet, since it resembles a collection wallet far more than a personal account. Search the same address on Chainabuse: no reports yet, because the operation may simply be too new. This is exactly the scenario where the address check alone isn&#8217;t sufficient \u2014 the transaction-pattern read from Step 1 is doing more work here than the database lookup in Step 2, which is why treating this as a single combined process, rather than a pass\/fail on any one tool, matters. Watch for Address Poisoning One increasingly common scam tactic deserves specific mention: address poisoning, where an attacker sends a tiny, near-worthless transaction from a wallet address deliberately crafted to look nearly identical to one you&#8217;ve genuinely transacted with before, matching the first and last several characters, which is what most wallet apps display by default. The goal is that the next time you go to send funds, you copy the poisoned look-alike address from your transaction history by mistake, rather than typing or pasting the real one. Always verify the complete address, not just the first and last few characters, and consider using an address book or saved-contact feature in your wallet rather than copying from transaction history. This tactic has grown more common precisely because it doesn&#8217;t require tricking a<\/p>\n","protected":false},"author":1,"featured_media":2077,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"pagelayer_contact_templates":[],"_pagelayer_content":"","site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"default","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"set","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[9,10],"tags":[],"class_list":["post-2073","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-online-safety","category-scam-prevention"],"_links":{"self":[{"href":"https:\/\/icar-global.org\/blog\/wp-json\/wp\/v2\/posts\/2073","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/icar-global.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/icar-global.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/icar-global.org\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/icar-global.org\/blog\/wp-json\/wp\/v2\/comments?post=2073"}],"version-history":[{"count":11,"href":"https:\/\/icar-global.org\/blog\/wp-json\/wp\/v2\/posts\/2073\/revisions"}],"predecessor-version":[{"id":2191,"href":"https:\/\/icar-global.org\/blog\/wp-json\/wp\/v2\/posts\/2073\/revisions\/2191"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/icar-global.org\/blog\/wp-json\/wp\/v2\/media\/2077"}],"wp:attachment":[{"href":"https:\/\/icar-global.org\/blog\/wp-json\/wp\/v2\/media?parent=2073"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/icar-global.org\/blog\/wp-json\/wp\/v2\/categories?post=2073"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/icar-global.org\/blog\/wp-json\/wp\/v2\/tags?post=2073"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}