Skip to main content

Shepley Capital

WALLETS & SECURITY
Wallets and Security - Cryptopedia by Shepley Capital

How to Verify a Crypto Address Before Sending

Verifying a crypto address before sending funds is one of the most important habits you can develop as a cryptocurrency user. Unlike bank transfers, which have reversal mechanisms and customer support teams, blockchain transactions are final: once confirmed, they cannot be undone by anyone. Sending to the wrong address, whether through a typo, a clipboard hijacking attack, or simply mistaking one address for another, results in permanent loss of your funds.

The good news is that address verification is straightforward and takes only seconds. Developing a consistent verification habit, and understanding the specific risks you are protecting against, dramatically reduces the probability of making the kind of irreversible mistake that has cost crypto users enormous amounts over the years. This guide covers the verification methods, the most common error types, and the practical habits that protect your assets.

 

Why Address Verification Matters

The permanence of blockchain transactions is the fundamental reason address verification is non-negotiable. When you send funds on a blockchain like Bitcoin or Ethereum, the transaction is broadcast to thousands of nodes simultaneously and, once included in a block, is recorded permanently in the blockchain’s history. There is no central authority to appeal to, no transaction reversal button, and no customer service team that can recover funds sent to the wrong address.

The wrong-address problem takes several forms. Typos are the simplest: manually transcribing an address introduces the risk of errors in any of the 30-50 characters that make up a typical crypto address. A single incorrect character creates a different address that likely belongs to nobody, sending your funds to an unspendable void. Even if the typo happens to produce a valid-looking address format, the funds go to whoever controls that address, and recovery is impossible without their cooperation.

Clipboard hijacking malware is a more sophisticated threat. This type of malware sits silently on your computer, monitors the clipboard for crypto address patterns, and automatically replaces any address you copy with an attacker-controlled address. The switch happens invisibly between when you copy the address and when you paste it into your wallet. Without verification of the pasted value, you would not notice until the transaction was already confirmed and the funds were gone.

Network confusion affects addresses on EVM-compatible blockchains. Because Ethereum and all EVM-compatible chains like Polygon, Arbitrum, and BNB Chain use identical address formats, it is possible to send funds to the right address on the wrong network. The recipient’s address is correct, but the funds arrive on a different chain than intended. Recovery is possible if the recipient has access to that chain, but it can require technical knowledge and may not always be practical.

 

Step-by-Step Address Verification Process

The most effective verification process involves multiple independent checks at different points in the transaction flow. Start by obtaining the recipient’s address through a trusted channel: directly from their wallet application, through a secure messaging platform, or by scanning a QR code they present to you in person. Never use an address obtained from an email you decentralised identity not solicit, a social media message from an account you have not verified, or a website you found through an internet search rather than through a direct, known URL.

After copying the address, visually compare the pasted value with the source. Check at minimum the first six and last six characters. These are the positions most likely to differ if clipboard hijacking has occurred, since attackers typically use addresses that match the middle characters but differ at the ends to evade casual checking. For very high-value transactions, check every character in the address.

Confirm the network before proceeding. If you are sending tokens that exist on multiple networks, verify explicitly that your wallet is configured to send on the same network your recipient is expecting. Look for the network name displayed prominently in your wallet’s send interface. Slow down and read this information carefully rather than clicking through the transaction flow habitually.

Send a test transaction first for any transaction above a few hundred dollars. A test amount of $10 to $20 AUD sent first, verified as received by the recipient, provides strong confirmation that the full transaction will work correctly. The fee for a test transaction is a small price for the certainty it provides. Learning to send and receive safely includes this test transaction habit as standard practice.

 

Checksum Verification

Many blockchain address formats include built-in checksum mechanisms that provide automatic error detection. Ethereum addresses use EIP-55 checksums encoded through capitalisation: a correctly checksummed Ethereum address has some letters capitalised and others lowercase in a pattern that encodes a mathematical verification of the full address. If you mistype a character in a checksummed address, most wallets will immediately flag the checksum failure and refuse to proceed.

Bitcoin’s newer Bech32 and Bech32m address formats also include error correction capabilities. The encoding standard can detect and in many cases correct single-character errors, providing a safety net against transcription mistakes. Legacy Bitcoin addresses starting with 1 also include a four-byte checksum, though it is less capable than the newer formats. Most wallets automatically validate the checksum and warn you if an address fails verification.

When an address fails checksum validation, do not try to guess the correct address by making changes until the checksum passes. Instead, go back to the source and re-obtain the address from scratch. A checksum failure means the address as entered is incorrect, but it does not tell you where the error is or how to fix it. The only safe response is to start fresh with a verified copy of the correct address.

The checksum protection that makes addresses safer to verify also means that not all random strings that look like addresses are valid. This is why you cannot accidentally send to a random-looking string: the checksum mechanism rejects most nonsense inputs. However, checksum validation only verifies that the address is internally consistent: it does not verify that the address belongs to the intended recipient or even that it is reachable on the intended network.

 

Using Wallet Address Books and Trusted Contacts

Most quality wallet applications allow you to save verified addresses to an address book with labels. This is one of the most practical security features available: once you have verified an address and saved it, you can send to that contact repeatedly without repeating the full verification process. The risk of error is concentrated in the single initial verification step rather than spread across every transaction.

When adding an address to your address book, use the full verification process: obtain the address from a trusted source, compare it character by character with the source address, and only save it after confirming it is correct. The effort invested in that one thorough verification protects every future transaction to that recipient. Label addresses clearly enough that you cannot accidentally select the wrong contact in a list of similar entries.

Enterprise and high-frequency transaction users can implement additional controls like whitelisting, which restricts outgoing transactions to a pre-approved list of addresses. Some wallets and custody solutions support this feature, preventing any transaction to an address not on the approved list regardless of what is pasted or entered. This eliminates the clipboard hijacking risk entirely for any address that requires prior whitelisting approval.

For businesses and individuals who regularly receive crypto from many parties, providing a dedicated receiving address for each counterpart or purpose makes incoming transaction monitoring and reconciliation much simpler. Rather than sharing the same address with every sender, using distinct addresses preserves the ability to attribute incoming transactions to their source and to detect any unexpected activity associated with a specific address.

Address verification is the single most important habit that stands between careful crypto users and irreversible transaction errors. The few seconds required to verify an address before every transaction are an insignificant cost compared to the potential consequence of sending funds to the wrong place. Build this habit early and maintain it consistently. Explore comprehensive crypto safety practices in the Cryptopedia Wallets and Security library, and stay informed through the Capital Nexus newsletter.

 

How Address Poisoning Attacks Work

Address poisoning is a sophisticated social engineering attack designed to exploit the common habit of copying a wallet address from recent transaction history rather than from a secure original source. In this attack, a malicious actor sends a small dust transaction to your wallet from an address that visually resembles a wallet address you have previously interacted with. The attacker designs their address to match the first four and last four characters of a legitimate address you frequently use.

Because most wallet interfaces display only the first few and last few characters of long addresses due to screen space constraints, a casual glance at the transaction history may not reveal that the address in the poisoning transaction is different from the legitimate one. If a user copies the address from their transaction history and pastes it into a new send transaction without carefully verifying the full address, they may unknowingly send funds directly to the attacker.

Awareness of this attack vector changes how you approach your transaction history. Rather than treating your history as a convenient address book, you should maintain a separate, verified list of addresses you frequently send to, stored in a secure location and verified character-by-character against the original source. Never use a transaction history address as the sole reference for a new send, particularly for large amounts.

 

Building a Verified Crypto Address Book

A personal crypto address book is a secure, curated list of addresses you frequently send to, each one verified against its original source and labelled clearly. Building this address book takes a small upfront investment of time but pays dividends in reduced risk and increased confidence every time you prepare a transaction.

For each address in your book, record the label for who or what the address belongs to, the full address verified character-by-character against the original source, the blockchain network the address is valid for, and the date on which you verified it. Some addresses change over time, particularly for contacts who rotate wallets for privacy reasons, so including a verification date reminds you to re-confirm old entries.

The most important practice when adding a new address to your address book is to verify it through the most direct channel possible. If you are adding a business contact’s wallet address, call them directly to confirm it rather than relying on an email or message that could have been intercepted. For exchange deposit addresses, generate a new one directly within the exchange interface rather than reusing a previously recorded address, as some exchanges rotate deposit addresses periodically.

Hardware wallets add a critical verification step to the address confirmation process that software wallets cannot replicate. When you initiate a transaction using a hardware wallet connected to a software interface, the hardware device displays the destination address on its own screen for you to physically confirm before signing. This confirmation step happens on the device itself, which means that even if your computer has been compromised by clipboard hijacking malware that replaced the destination address in the software interface, you will see the attacker’s address on the hardware device screen rather than the legitimate one. This is one of the most important reasons why hardware wallets are recommended for any significant crypto holdings: the physical confirmation step on a separate trusted device catches address substitution attacks that purely software-based wallets cannot detect.

 

Further Learning

Expand your crypto knowledge with these related Cryptopedia resources:

hardware wallet guide | hot wallet explained | seed phrase storage | self-custody crypto | two-factor authentication

MetaMask security guide | Ledger wallet setup | multisig wallets | custodial vs non-custodial | crypto phishing protection

token approvals | Etherscan guide | exchange custody risks | crypto wallet backup | software wallets

paper wallet explained | cold storage setup

For structured crypto education, explore the full Cryptopedia library at Shepley Capital, Australia’s most comprehensive crypto education hub.

Frequently Asked Questions

Why is it critical to verify a crypto address before sending?

Cryptocurrency transactions are irreversible: once confirmed on the blockchain, funds sent to the wrong address cannot be recalled or reversed by any authority. Verifying every address before sending is the single most effective prevention against costly mistakes and address-swapping malware.

What is clipboard hijacking malware?

Clipboard hijacking malware silently monitors your clipboard and replaces any copied cryptocurrency address with the attacker's address the moment you paste it. The substituted address typically looks similar to the original, making it difficult to spot without careful character-by-character verification.

How should I verify a cryptocurrency address?

Always check at least the first six and last six characters of a pasted address against the original source, as clipboard malware usually targets the middle characters. Better still, scan a QR code directly rather than copying and pasting an address at all.

What is address poisoning and how can I protect against it?

Address poisoning is an attack where an attacker sends a tiny transaction from an address visually similar to one in your transaction history, hoping you will copy the poisoned address when making a future payment. Always copy from the original confirmed source, never from your own transaction history.

Should I send a small test transaction before a large transfer?

Sending a small test transaction before a large transfer is a widely recommended practice that confirms the destination address is correct and accessible. The cost of the test transaction is a small insurance premium against an irreversible large transfer error.

How do QR codes help with address verification?

Scanning a QR code eliminates manual typing and copy-paste steps entirely, removing the attack surface exploited by clipboard malware. Always ensure you scan QR codes from verified official sources, as malicious actors also create fake QR codes that redirect to attacker-controlled addresses.

What should I do if I accidentally send crypto to the wrong address?

Recovery is generally impossible once a transaction is confirmed. If the address belongs to a known exchange, contact their support immediately as they may be able to assist. If sent to a random blockchain address, the funds are permanently lost with no recourse available.

How do ENS and similar naming services reduce address errors?

Ethereum Name Service (ENS) and similar naming systems let you send to human-readable names like 'alice.eth' instead of long hexadecimal addresses. While they reduce manual errors, you must still verify the name resolves to the intended address before each transaction.

WRITTEN & REVIEWED BY Chris Shepley

UPDATED: AUGUST 2026

Grow your crypto portfolio with the latest insights, straight to your inbox!

Join 10,150+ CEOs, Business Owners, Parents, Students, & more receiving actionable crypto insights to grow their portfolios.