Scam entry · Wallet security · Verifying a contract address

Where should you copy a contract address from? The official site can be fake too

Three places will hand you the same contract address: a block explorer, a price aggregator, and the project's own website. Most guides stop at "copy it from the official site" and never deal with how you arrived at that site. If somebody else laid that path for you, copying carefully changes nothing.

Entry cover: identical token names can only be told apart by contract address
Chain Scam Index · specimen: how a same-name token is checked

Search USDT on a block explorer and more than one contract comes back. On most public chains, issuing a token needs nobody's approval and the name and symbol are fields you fill in yourself, so identical names sit side by side. The one thing that separates them is a contract address.

Nearly every guide gets that far. The trouble starts with the next sentence — "you can find the contract address on the project's website, or ask the project team for it." There is someone camped on both of those roads.

Three sources, three different things being vouched for

There are only a few places a contract address comes from, and it's worth separating what each one is actually standing behind.

A block explorer (Etherscan, BscScan and the like) is really giving you two layers stacked together. One is on-chain fact: who deployed it and how many addresses hold it. That layer doesn't lie. The other is the labels and notes the explorer itself has attached, which are curated by people — so they lag, and they have gaps.

A price aggregator (CoinGecko, CoinMarketCap) gives you a set of details checked at listing time: contract address, official domain and social accounts, all on one page. Its usefulness here is specific — it ties "the address" to "which domain is the official one", and that pairing matters later.

The project's own site and official channels are the most direct source and the easiest one to impersonate. Domains can be registered to look almost identical, accounts can be bought, and even the support staff can be invented.

The three fail in different ways, and that is the entire reason cross-checking works. Sources that fail the same way just show you one error three times.

Explorer labels: UNKNOWN is the default

Etherscan sorts token reputation into six levels: UNKNOWN, NEUTRAL, OK, SUSPICIOUS, UNSAFE and SPAM. The first one is the one that matters. Per Etherscan's own documentation, every token defaults to UNKNOWN — including tokens whose basic details (website, socials, logo) have already been filled in. It means "we can't or haven't decided", nothing more.

So "no warning" and "checked and fine" are two different states. The first is a default. The second requires that somebody actually looked.

The thresholds above it are worth knowing too. NEUTRAL asks for verified source code, a website and official contact email, publicly checkable profiles for the team, and a listing on a major price aggregator. OK works off a set of parallel criteria — any one of them, or a combination — among which are already qualifying for NEUTRAL and whether the token trades on a major exchange with AML/KYC checks. Between SUSPICIOUS and UNSAFE, what the documentation separates is whether the reports are substantial and credible, and whether the contract is already listed in a public scam database.

And the loudest line on that page is Etherscan's own, in the disclaimer: the scores rest on subjective evaluation and community reports, may or may not be accurate, and the site does not endorse, disapprove of or censure any services or projects related to the token contracts.

I tend to skim that field and stop instead at the holder count and the transfer history further down.

Name tags are worth knowing about too. Per the documentation, what Etherscan weighs is whether the owner wants the address displayed publicly, or whether the address is of public interest; for an individual's address, a tag is only shown once that person has publicly declared ownership. In most cases the tag carries a link back to its source. Where needed, the explorer will also put a public note at the top of a page for an announcement or a warning. All of this is the leads-and-hints layer.

"Copy it from the official site" needs a step before it

Back to that worn-out advice. Copying from the official site isn't wrong. What's wrong is that it assumes you already know which site is the official one.

In practice, someone checking a contract address usually heard about the token recently. The route to its website is normally one of four: the first search result, a link somebody sent you privately, a forward in a group chat, or the link in a social account's bio. Not one of those is trustworthy by default — fake exchanges takes apart how those paths get laid. Once you have a domain in hand to compare, the lookalike domain checker compares the characters in your own browser and never calls out.

"Ask the project team" is worse. Where did you find that team? If someone messaged you first, or you asked in a group and a helpful stranger answered, that's the standard script covered in fake support and fake admins — that question is exactly what they were waiting for.

Reverse it: don't use the site to find the address, use the address to confirm the site. A price aggregator's token page lists the contract address and the official domain in the same place, and a domain you got there came through a listing process with no stake in your decision.

Cross-checking only counts when the sources are independent

"Cross-check" is easy to perform without doing. If all three sources were reached by following links from the same person, that is just a lap back to where you started.

A workable order looks like this:

  1. Open a price aggregator first and find the token with its own search box. Don't arrive through anyone's link. Write down two things: the contract address, and the official domain it lists.
  2. Paste that address, whole, into a block explorer. Look at three things — whether the source code is verified, whether there's a name tag or public note, and the order of magnitude of holders and transfers.
  3. Only now open the website, and open it by typing the domain yourself. Check that the address it publishes matches the first two steps.
  4. Any mismatch ends it. You don't have to work out which one is right. Three sources that disagree is already your answer.

The order isn't interchangeable. Starting at the website and verifying outward from it lets the first link decide everything downstream — if that site is the fake one, every address you copy afterwards will match perfectly.

Editorial verification note

The six reputation levels, their thresholds and the disclaimer, along with how name tags, labels and public notes are assigned, all come from two public pages in Etherscan's information centre, verified 2026-09-06. The page fields named in this piece — verified source code, project domain label, holder count, contract address — were confirmed the same day by opening the public token pages on that explorer and on CoinGecko in a browser. The desk has not looked up any specific contract on anyone's behalf and does not rule on any contract a reader is holding. We also publish no "safe token list", because a list like that becomes the next thing worth impersonating.

The part most worth pulling out is that disclaimer. A line like that, sitting in the disclaimer on a platform's own scoring page, is not something many readers ever reach — and it happens to answer the question they came with, which is whether that one field is enough to decide on. It isn't, and the platform is the one saying so.

Orders of magnitude are the hardest part to fake

A token genuinely in circulation accumulates holder addresses and transfers over years. A checkable example: on 2026-09-06, the Tether USD contract on Ethereum mainnet showed on the order of 15 million holder addresses on Etherscan (these move daily; treat the page's current display as authoritative). An impersonating contract with the same name can't manufacture that — it would take a great many real wallets interacting over a long stretch of time.

A rough reference: a freshly deployed impersonating contract often sits in the low hundreds of holders, while a stablecoin in real circulation is in the tens of millions. Everything between those has no clean line, so this field only speaks up when the gap is several orders of magnitude.

This test runs one way only. Numbers that don't add up are strong negative evidence. Numbers that look good are not positive evidence. Holder counts can be padded with bulk addresses and transfer counts can be wash-traded. Honeypot tokens are exactly that shape: busy on chain, easy to buy into, impossible to sell out of.

With three sources agreeing and the numbers holding up, the conclusion you've earned is a narrow one: this address is the contract behind that name. Whether the project itself is worth touching is a separate question, and not one this entry answers.

Taking coins in a person-to-person trade adds another layer on top, covered in over-the-counter and person-to-person trades.

A few things people still ask

If I buy on a centralised exchange, do I still need to check the contract address?

Buying spot on an exchange normally doesn't ask you for an address — the platform already picked the asset. The cases that need your own check are different ones: searching for a token by address on a decentralised exchange, adding a token to your wallet by hand, landing on a trading interface through a link somebody sent you, and taking coins in a person-to-person trade. The dividing line is simple. If at any point a string of characters gets pasted in by you or by the other party, that string needs checking.

A token showed up in my wallet on its own. If the address checks out, is it real?

A matching address only tells you which contract issued it. Who sent it to you, and why, is beyond what an address can answer. Treat unrequested tokens as bait by default: the usual play is to pull you toward a site that will "swap it into USDT" for you, or to get you to sign an approval first. Look it up if you want, ignore it if you prefer — but don't interact with it just because the address resolves.

The explorer says the source code is verified. Does that mean it's safe?

Verified means the source the publisher uploaded compiles to the bytecode that is actually on chain, so anyone can read what it does. What it guarantees is readability, and only that. Fully public source code can still contain a rule that only certain addresses are allowed to sell. Verification makes scrutiny possible; somebody still has to do the scrutinising.

The address differs only in the last few characters. Could it be another official contract?

It could be — projects do run several contracts, across chains, for staking, or after a migration. The problem is that generating an address with matching leading and trailing characters is cheap now, and human eyes only scan the ends. So there is one method and no shortcut: copy the whole string and compare it, or paste the full address into the search box. One character off is a different contract. There is no "it's probably the same one".

2026-09-06 · Entry created, with the reputation levels and name-tag policy checked against two public Etherscan Information Center pages and the checkable fields confirmed on public token pages the same day.