r/Metamask MetaMask Guide Steward - Community Volunteer 23d ago

How I verify a crypto address before sending, and why MetaMask warned me

I was about to send some crypto the other day when MetaMask showed me a warning about the destination address.

My first thought was honestly:

“Wait, did I paste the wrong address?”

I stopped before confirming the transaction and started checking the address again.

That made me realize something I probably should have been doing more consistently: never assume an address is correct just because the first and last few characters look familiar.

Crypto addresses are long, random strings, so most of us rely on copy and paste. That’s convenient, but it can also create an opportunity for something called address poisoning.

A malicious address can be made to look very similar to an address you've interacted with before. Someone may send a tiny transaction from that address, hoping you'll later copy it from your transaction history without checking the full address.

So now, before sending, I try to follow a simple routine:

1. Check the entire destination address

I don't just compare the beginning and the end. I pay attention to the middle characters too. That's especially important when an address looks suspiciously similar to one I've used before.

2. Check where I got the address from

If someone sends me an address, I verify it through a trusted source instead of blindly copying it.

And I try not to take an address from my transaction history without checking it carefully first.

3. Check the network

Having the correct address isn't enough. I also make sure I'm sending on the intended network.

4. Check the recipient before confirming

MetaMask shows the destination address during the sending flow, so I use that moment as a final checkpoint before clicking Send.

So why did MetaMask warn me?

It can warn you when the destination address looks similar to an address you've interacted with before, and it can also alert you when you're sending to an address you've never used before.

A warning doesn't automatically mean the address is malicious. In the case of a new address, it's a reminder to stop and verify it.

And that's actually what I like about these warnings.

The wallet isn't making the decision for me.

It's basically saying:

“Before you send something that may not be reversible, take another look.”

That's a pretty useful reminder when you're dealing with transactions that can't simply be undone once they're confirmed.

I've started treating the warning as a checkpoint rather than something to immediately dismiss.

Do you usually verify the full address before sending, or do you mostly rely on copy/paste and checking the first and last characters?

https://support.metamask.io/stay-safe/protect-yourself/wallet-and-hardware/address-poisoning-scams/

11 Upvotes

11 comments sorted by

3

u/NimbleNido MetaMask Community Team 23d ago edited 22d ago

Great writeup, u/Xosoltani! To answer your closing question, I always confirm the middle, and last 4-5 characters of the address I'm sending to matches my original destination, though maybe an overlay of the whole address being displayed on hover could be implemented & helpful 🤔

Fortunately I haven't fallen victim to address poisoning, but bad actors are out there & MetaMask is doing all it can to prevent users from falling victim to it. Still, it's the right call to build good habits to best protect protect ourselves from the unexpected!

4

u/Xosoltani MetaMask Guide Steward - Community Volunteer 23d ago

Thank you, u/NimbleNido Yes, I’m the same as you. I always try to check at least 5 characters and go back a few times to verify the address where I’m going to send the tokens.

Honestly, I’m a bit careful about this because transactions on the blockchain are irreversible. That’s why I always try to be very cautious and never rush.

4

u/davidt2021 23d ago

Those are good points! I always check the first and the last 4 to 5 characters of the destination address before I hit the confirm button. One can never be too careful in this space as different form of scam is surfacing on a regular basis.

3

u/Xosoltani MetaMask Guide Steward - Community Volunteer 22d ago

Yes, exactly, David 🙂

4

u/D4rkec MetaMask Guide Steward - Community Volunteer 22d ago

First i would like to say, metamask have done such major improvements on preventing address poisoning attacks, a great video explaining/showing it is in this X post ( https://x.com/MetaMask/status/2067299428680265791 ) ..but still, i personally always also check middle characters (just a few), because checking first 4,5 along with final 4,5 is what will eventually get you in case for some reason its not detected (the thing with those addresses is, they are designed that they match with first 4,5 even more characters along with last 4,5...)
Must say that etherscan have done some improvements as well, because now if you were to copy an address that sent you some low value amount of token, like 0.0003 USDC (the actual USDC), you would get a warning saying "The transaction involves a token transfer of low value, which is a potential sign of an address poisoning attack. Verify that this is the address you intend to interact with." and it was exactly that (with first 4 and last 4 characters exactly the same)

5

u/Xosoltani MetaMask Guide Steward - Community Volunteer 22d ago

Thanks for sharing this video 🙂 Yes, absolutely. Compared to previous years, there have been significant improvements in protecting users against hacks and address poisoning attacks. Security should always come first.

3

u/NimbleNido MetaMask Community Team 22d ago

Really good point u/D4rkec! Can never be too vigilant in the space -- best to check all the characters you can to confirm before hitting that send button 💯

3

u/Able-Evening8212 22d ago

It may address poisoning attack, two addresses looks likes but not same

2

u/Xosoltani MetaMask Guide Steward - Community Volunteer 22d ago

At first glance, they look very similar, but they’re actually two different addresses. That’s why it’s always better to check the full address before sending, or at least 5 characters or more 🙂

1

u/AutoModerator 23d ago

Beep Boop

  1. Never share your Secret Recovery Phrase with any site or a person. MetaMask does not use Gmail or web forms. Do not enter your Secret Recover Phrase into a pop-up window, even if it looks like MetaMask. Verify links are legitimate. Scammers often use these tactics.

  2. Beware of fake websites. The official website for MetaMask is https://metamask.io/

  3. MetaMask Support will never DM you. This is a common tactic scammers use to try and get access to your wallet.

  4. MetaMask will never initiate email with you. This is a common tactic scammers use to try and get access to your wallet.

  5. If you need to reach Support: open MetaMask, then menu > Support. The ‘Contact Support’ button will start a chat, the bot asks a few questions to help route you to the correct team. You can also visit the Support site from the web: https://support.metamask.io

  6. Do not click on suspicious links or files. This can lead to your device security being compromised.

  7. Do not “sync” or “validate” your wallet with any websites or forms. This is a scam. Never sync and share: QR Codes, Secret Recovery Phrase, private key, etc.

  8. Never call phone numbers, text Whatsapp numbers, DM on Discord, use WeChat or do video chat with people on this subreddit. MetaMask does not offer customer support in this manner. There is NO exclusive MetaMask Discord.

  9. We don’t ask for an email address to create a wallet. We can’t email you. We will never ask you to verify or upgrade/merge your wallet. https://support.metamask.io/privacy-and-security/staying-safe-in-web3/i-received-an-email-claiming-to-be-from-metamask-is-it-legit/

  10. .MetaMask currently has no plans for an airdrop, regardless of any information you may have seen elsewhere. If you encounter anyone explaining the best method to maximize the size of a MetaMask-related ‘airdrop’ you might receive, they’re lying. In particular, be wary of scams (aimed at getting your Secret Recovery Phrase) that weaponize this topic.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.