Safety · address poisoning · read-only

That address only looks right.

Scammers send you a tiny transfer from an address that starts and ends like one you really use, hoping you copy it from your history next time. Paste your wallet to find them.

We never ask for your seed phrase or private key. Only a public address.

Paste a wallet above. We read its 300 most recent transactions and compare every unsolicited sender with the wallets you actually transact with.

How poisoning works

Your history is the bait.

Wallet apps shorten addresses to the first and last few characters. Attackers generate addresses that match those characters and drop a transaction into your history.

Real address you paid last week

72JZMEwqQVNfZvt95eLDae3CPesk25Xor4YSxKhowkT2

Poisoned address that sent you 0.00001 SOL

72JZWJTsC3wq8RGatZy61At3NcwYB5U4rxkaSYdNwkT2

Shortened in a wallet, both read 72JZ…wkT2.

Never copy from history

Copy the address from the source: the exchange deposit page, your contact's message, or a saved address book entry.

Check the middle

Compare the whole address, or at least 6–8 characters in the middle. Poisoned addresses only match the ends.

Use an address book

Save trusted addresses with a name in your wallet and send from there. Use .sol names only if you verify who owns them.

Send a test first

For large amounts, send a small test and confirm with the recipient that it arrived before sending the rest.

Ignore the dust

Tiny incoming transfers cannot hurt you by themselves. Don't interact with them and don't send anything back.

Check before you send

SendCheck compares a recipient against your past counterparties and flags lookalikes before you pay.