How to Verify a Crypto Website, App or Address
Reviewed and updated September 15, 2026 by the SmartCryptoEarnings editorial team · editorial policy
Almost every crypto loss that is not a market loss begins with trusting the wrong destination: a look-alike domain, a cloned app, a copied address, a contract that is not what it claims to be.
This page is a process, not a verdict. We cannot certify that any site, app, token or address is safe, and nobody credible can. What follows is the sequence of checks that catches the overwhelming majority of impersonation attempts, and the order to run them in.
Decision tree: what are you about to trust?
- A website or web app → run the domain checks, then the connection checks.
- A downloadable wallet or app → run the publisher checks before installing anything.
- A token or contract address → run the contract checks on a block explorer.
- A payment address or QR code → run the address checks, and send a test amount first.
- A link from a message, comment, ad or DM → treat it as unverified by default and reach the destination yourself instead.
If any single check fails, stop. A verification process only works if a failed check ends the attempt rather than starting a search for reassurance.
Website and domain checks
- Read the domain character by character, right to left from the top-level domain. Impersonation relies on swapped letters, added hyphens, extra words and unusual endings.
- Reach the site by typing the domain or using your own saved bookmark. Do not arrive through a search advertisement, a social post, a comment or a message.
- Confirm the domain against a source the project controls elsewhere — its documentation, repository, or an official account you already trusted before today.
- Watch for redirects: if the address bar changes to a different domain after loading, treat the destination as unverified.
- Check that the page is served over HTTPS, while remembering that a padlock proves encryption only, never honesty.
Search-ad impersonation is common enough that CISA and the FTC both warn against reaching financial services through sponsored results. Bookmarks beat search boxes.
App and download checks
- Install only from the publisher's own linked download page or the official app store listing it links to.
- Check the publisher name on the store listing, not the app name — impersonators copy the name and icon, not the developer account.
- Treat a wallet that asks for an existing recovery phrase during setup of a 'new' install as hostile unless you deliberately chose the restore flow yourself.
- Be sceptical of an app with a large install count but a short history, or reviews that all arrived in the same period.
- Verify checksums or signatures where the project publishes them for desktop builds.
Token and contract checks
- Get the contract address from the issuer's own documentation, not from a chat message, a chart site comment or a search result.
- Paste the contract address into the block explorer for the correct network and compare it character by character.
- Check the token's transfer history and holder count on the explorer: a contract created hours ago with a handful of holders is not the established asset it may be imitating.
- Confirm the network. The same ticker exists on many networks, and a contract on the wrong one is a different asset.
- Where the explorer shows verified source code, prefer it — unverified code means nobody outside the deployer can read what the contract does.
Address and QR code checks
- Compare the full address, not the first and last four characters. Address poisoning exists precisely because people check only the ends.
- Paste the address into the explorer before sending and confirm the network and the activity look like what you expect.
- Send a small test amount first on any new destination, and wait for it to arrive and be credited.
- Re-check the address in the wallet's confirmation screen immediately before signing — clipboard malware swaps addresses after you copy them.
- Treat a QR code from a screenshot, a printed sheet or a message as untrusted: decode it and read the address it actually contains.
Connection and signature checks
- Read what you are approving. A transfer moves one amount; an approval can grant ongoing permission to move a token.
- Prefer a limited approval amount over an unlimited one where the interface offers the choice.
- If the wallet cannot display what a request does, that is blind signing — decline unless you independently know the contract.
- Use a separate wallet with limited funds for interacting with anything new.
- Review and revoke old approvals periodically rather than leaving permissions open indefinitely.
No legitimate site, support agent, airdrop, wallet or exchange ever needs your recovery phrase or private key. There is no exception to this, and any request for one ends the interaction.
Signals that should stop the process entirely
- Pressure: a deadline, a closing window, a bonus that expires while you hesitate.
- An unsolicited contact who introduced you to the opportunity.
- A request to move to a different platform, app or chat to complete the transaction.
- A promise of a fixed or guaranteed return.
- A requirement to pay a fee before receiving funds — the structure of every advance-fee scam.
- Any instruction to disable a security feature, ignore a wallet warning or bypass an app store.
Frequently Asked Questions
Can a website be proven safe?
No. Verification reduces the chance of impersonation; it cannot certify intent. Treat the checks as a way to eliminate obvious fakes, and keep exposure small on anything new.
Is a padlock icon in the browser a safety indicator?
It indicates an encrypted connection only. Fraudulent sites obtain certificates routinely, so the padlock says nothing about who runs the site.
What is the single most important check?
Reaching the destination yourself, from your own bookmark or typed domain, rather than through a link someone gave you or an advertisement.
Does a test transfer really help?
Yes, on any new destination. It confirms the address, the network and the crediting behaviour for a small amount before the full transfer is exposed to the same assumptions.
Sources
Spotted something out of date? See our corrections policy and fact-checking policy.
Continue reading
Educational information only. Nothing here is financial, legal or tax advice.