Skip to content
SpendTheBits

Security & recovery · 4 min read

How to spot a fake token or scam transfer

Short answer

A fake token is a worthless contract given the name and symbol of a real one and airdropped to your address so that a scam looks like a balance. SpendTheBits quarantines inbound transfers from unverified contracts instead of counting them as funds, and flags them clearly. Treat anything that arrives unexpectedly as bait: the goal is almost always to get you to visit a site and sign something.

The second common variant is address poisoning. An attacker sends a tiny transfer from an address engineered to share its first and last few characters with one you use often, hoping you will later copy the wrong entry out of your own transaction history.

Both attacks are cheap to run at scale and cost the attacker almost nothing per target, so being uninteresting is not protection.

Check something suspicious

  1. 1

    Check whether the app has quarantined the token.

    Quarantined tokens are flagged and excluded from your balance. That flag is the app telling you the contract is not a verified one.

  2. 2

    Never visit a site named in a token's name or a transfer memo.

    The payload is the site, not the token. The transfer exists only to get the URL in front of you.

  3. 3

    Copy addresses from a contact or a fresh QR, never from your transaction history.

    This single habit defeats address poisoning entirely.

  4. 4

    Verify the full address, not the first and last four characters.

    The middle is exactly what the attacker is counting on you not reading.

  5. 5

    Hide the token and move on.

    You cannot refuse an inbound transfer on a public blockchain. Hiding it is the correct and complete response.

Good to know

  • No legitimate party ever needs your recovery phrase. Every request for one — support, an airdrop claim, a wallet migration — is theft.
  • Recipient addresses are screened against sanctions and risk lists before a send can be signed, and the broadcast is bound to the screened recipient so it cannot be swapped afterwards.
  • The AI Copilot can brief you on scam risk, but it can only ever prepare actions. It cannot move funds, so a compromised assistant cannot spend for you.

Frequently asked

You cannot stop anyone sending you a token, so its presence means nothing about its value. If it is quarantined, treat it as hostile, hide it, and never interact with any site it points to.

Receiving it is harmless. The danger comes later, if you copy the sender's lookalike address out of your history and pay it. Always copy from a contact or a QR.

No. Blockchain transfers are final for everyone. This is why the defences are all placed before signing — screening, clear-signing, guardrails and quarantine — rather than after.

Get SpendTheBits

A fully non-custodial wallet for 13 chains, free on iOS and Android. Your keys never leave your phone.