Start your 3-day free trial
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.


To verify a crypto deposit address, generate a fresh instruction inside the authenticated receiving account, match the asset and network, compare the complete address and memo or tag, then confirm a small test is credited before sending the remainder. Never rely on a familiar-looking prefix, a copied screenshot, or a checksum alone.
Key Takeaways
- Treat asset, network, address, and memo/tag as one destination record.
- Obtain that record from the authenticated recipient, not an old message or search result.
- Compare the complete value after every copy-and-paste operation.
- Use a trusted hardware display or independent channel when available.
- A test succeeds only when the intended receiving account credits it.
A blockchain address is not the whole instruction. An exchange deposit often combines four independent fields: the asset, the blockchain network, the destination address, and sometimes a memo or destination tag. A mismatch in any field can produce a transfer that is valid on one chain but unusable by the intended recipient.
| Field | Question to answer | Common failure |
|---|---|---|
| Asset | Is this the exact coin or token the recipient accepts? | Sending a similarly named token |
| Network | Is the sender using the same chain shown by the recipient? | Choosing a cheaper but unsupported chain |
| Address | Does every character match the fresh destination? | Clipboard replacement or stale address |
| Memo/tag | Is it required and tied to this account? | Omission or another user's routing value |
| Amount | Is it above any credited minimum and within limits? | Test too small to appear |
Do not infer network compatibility merely because two networks use similar-looking addresses. Do not assume a token can be recovered because the same private key format exists elsewhere. The receiving service decides which network-and-asset combinations its custody system monitors.
Open the recipient's official app or type its known domain. Authenticate normally, navigate to Deposit or Receive, select the exact asset, and read any network warning. Generate or reveal a fresh deposit instruction. If the recipient is another person, ask them to repeat this process and confirm through a previously trusted channel.
Do not use an address from search results, a social profile, an unsolicited support message, or an old invoice. If an exchange says an address remains valid, a fresh visit still lets you see current network support, memo requirements, holds, and minimums.
Write the pair down before copying the address: for example, “asset X on network Y.” Then select the same pair at the sending wallet. If the sender's network label is ambiguous, stop and use official documentation or support. A fee difference is not evidence that another chain is compatible.
Copy from the authenticated receiving screen and paste into the sender. Compare the full destination, not only the first and last four characters. Group long strings visually and move from start to end. If a QR code is used, compare the decoded value shown by the sending wallet with the receiving screen.
Repeat the comparison after changing the asset, network, address-book entry, browser tab, or device. Clipboard malware can replace copied wallet addresses, and attackers may place look-alike addresses in transaction history to encourage careless reuse. Microsoft's analysis of cryptocurrency-stealing malware describes clipboard monitoring and address replacement as a direct theft technique.[2]
When a hardware wallet or signer provides an isolated display, compare the address or transaction details there before approval. Ledger's security guidance recommends verifying the receiving address on the device display and using a small transfer where appropriate.[1] A trusted display reduces reliance on a potentially altered computer screen; it does not prove that the human recipient controls the address.
For a custodial recipient, a second independent check can be a live confirmation in its official mobile app. For a person, use a known voice or in-person channel and read several nonadjacent groups, the asset, and the network. Do not move the full destination address through an unknown “verification” website.
Choose a test amount that is above the recipient's stated minimum and worth more than the network fee, but small enough that a mistake remains tolerable. Send it with the exact memo/tag. Record the transaction ID.
Wait for the intended receiving account to show the credited asset and usable network. An explorer confirmation alone is insufficient for an exchange deposit. Coinbase's receiving instructions emphasize selecting the asset and network in the account before using the displayed address.[3]
Return to the receiving account and compare the destination again. Some platforms rotate addresses, display a new memo, or change network availability. Confirm that the test and remainder use the same intended route, then send the remainder without modifying the network to save fees.
A checksum can help software reject some mistyped or malformed addresses. It does not authenticate the recipient, attest to a platform account, confirm a network choice, or reveal that malware replaced one valid address with another valid address. Both the intended and attacker addresses may pass syntax and checksum validation.
Think of a checksum as a formatting control, not an identity control. Recipient identity comes from the trusted process used to obtain and confirm the destination. Network compatibility comes from both endpoints' supported-route documentation. Custodial credit comes from the receiving account's ledger.
Stop when the address changes during conversation, the recipient asks you to ignore an app warning, the network name differs, the memo requirement is unclear, or the sender cannot show the full destination before approval. Also stop if someone offers to “activate” an address through an advance payment or asks for your seed phrase.
| Risk level | Signal | Action |
|---|---|---|
| Routine check | Fresh address, matching route, confirmed test | Recheck and proceed within your limit |
| Elevated | Old screenshot, changed address, unclear memo, tiny unsupported test | Pause and regenerate instructions |
| Critical | Secret request, remote access, urgent address switch, bypass warning | Cancel and secure the account |
If a pasted value changes, follow the clipboard hijacking response before using that device again. If the wrong transfer has already been broadcast, use the missing memo or tag guide only when that is the actual error.
An address book reduces typing but creates a change-control problem. Store the asset, network, recipient owner, source of verification, date verified, memo requirement, and an internal approver. Require re-verification after a recipient account change, security incident, custody migration, or long period of inactivity.
For large transfers, separate preparation and approval. One person obtains the instruction; another compares it through an independent channel. Define a value threshold for a test and dual review. Never let urgency remove the final trusted-display check.
No. A look-alike address can share visible groups. Compare the complete value, preferably on a second trusted display.
No. It may detect certain typing errors, but it does not prove identity or ownership.
Only after the recipient's current official instructions confirm it remains valid for the same asset, network, and memo requirements.
The intended receiving account must credit the expected asset on the expected network. Explorer confirmation alone is not enough for a custodian.
Only if both sender and recipient explicitly support that exact asset-network route. Similar address formats do not establish compatibility.
A QR code reduces manual entry but can still contain the wrong destination. Compare the decoded value before approving.
A custodian may use it to route a deposit from a shared blockchain address to the correct internal customer account.
Do not rely on unsolicited social messages. Use the platform's authenticated app or official support domain and retain the case record.
Disclaimer: This article provides general security education, not financial, legal, tax, or investment advice. Blockchain transfers may be irreversible; verify current wallet and platform requirements before sending.
Sources
Sources checked 6 September 2026.
Related Articles:
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.