For anyone about to connect a wallet or send funds

Before you connect your wallet, check the domain.

A token sale, an airdrop claim or a ‘connect wallet to mint’ page that looks slightly off deserves a check first. On-chain transactions cannot be reversed, so the check happens before, or not at all.

Fake token sales, wallet-drainer pages and imitation exchange sites all depend on the same thing: a web address that looks close enough to a real one. The transactions they trigger cannot be reversed, which makes checking before connecting a wallet or sending funds unusually important.

What makes this different

In most fraud there is a recovery route — a bank recall, a chargeback, an insurer. Here there generally is not. A transaction confirmed on-chain is final, and a wallet approval granted to a malicious contract can be drained afterwards without any further action from you. The check happens before, or not at all.

  • On-chain transactions cannot be reversed
  • A wallet approval can be used later, not only at the moment you grant it
  • There is usually no institution able to intervene on your behalf

The patterns worth knowing

The pages differ but the setup rarely does. A recognisable brand, a reason to hurry, and a request to connect a wallet or send funds to an address supplied in the message.

  • Imitation exchange or wallet sites on lookalike addresses
  • Airdrop or claim pages that require a wallet connection to 'verify' eligibility
  • Presale and mint pages promoted through a compromised or impersonated account
  • Support accounts that appear after you post a problem publicly and offer to help in a private message

Before you connect a wallet

Check the address you are actually on, not the one you meant to be on. Reach it by a route you control rather than a link you were sent, and treat any urgency as a reason to slow down rather than hurry.

  • Type or bookmark the address; do not follow links from messages or social posts
  • Check the domain before connecting anything
  • Review what an approval actually grants, and revoke approvals you no longer need
  • Genuine support will not contact you first in a private message

Common questions

Does a clean result mean a token or project is legitimate?

No. This checks the domain, not the project, the token or the people behind it. A site can be technically unremarkable and still be a fraud, and nothing here is an assessment of an investment.

I have already connected my wallet. What should I do?

Review and revoke any approvals you have granted, and move remaining funds to a wallet whose keys have never touched the site. Approvals can be exercised long after they are granted, so revoking is the priority.

The site looked identical to the real one. How?

Copying a website is trivial — the appearance carries no assurance at all. The address is the part that cannot be copied exactly, which is why checking the domain rather than the design is the useful step.

Advisory only. This checks externally observable signals about a web address. It is not financial advice, not an assessment of any token, project or investment, and it cannot recover funds already sent.

Start free — 5 domains, no card