The single highest-leverage habit in self-custody is to never send crypto to an address you haven't checked. It takes four seconds. It will save more money over your lifetime than any other security habit.
What "checking a wallet" actually means
A wallet address (0x... on EVM chains, bc1... or 1... on Bitcoin, T... on Tron) is a public ledger entry. Every transaction it has ever sent or received is visible to anyone. "Checking" means asking three questions:
- Has this wallet been reported as a scam, theft, or sanctions target?
- What is its on-chain risk profile — is it linked to mixers, darknet markets, or known phishing drainers?
- Does its behavior match what I'd expect from the person I'm sending to?
The four-layer free stack
### Layer 1: GACS Wallet Checker
Paste any EVM, Bitcoin, Tron, or Solana address. Cross-checked against: - 250k+ entity scam blacklist - OFAC SDN list - Reported pig-butchering deposit wallets - Reported drainer & approval-phisher addresses - Linked addresses (one hop out)
Four seconds, no signup. Lives at /wallet-checker.
### Layer 2: Etherscan / BscScan / Tronscan / Solscan
The block explorer for the chain. Look at:
- First transaction date — a wallet created 2 hours ago is high-risk.
- Total inbound USD — if it's received $4M in the last 30 days from many small senders, it's a deposit funnel.
- Linked labels — Etherscan tags many known phishing wallets, hacked-contract drains, and OFAC entities directly.
- Approval activity — if the wallet's address shows up in many setApprovalForAll events from victims, it's a drainer.
### Layer 3: Chainalysis / TRM Labs free tools
Both companies offer free public-facing sanctions checks. Useful for confirming OFAC/UN/EU sanctions exposure if GACS hasn't flagged it.
### Layer 4: Social and reputation
Google the address in quotes. Search Reddit, Twitter, Bitcointalk, and scam-tracking forums. If anyone has been scammed by this wallet in the last 24 months, there is almost always a post about it.
What "safe" actually looks like
A genuinely safe wallet usually shows:
- Months or years of organic transaction history
- A mix of inbound and outbound transactions to known reputable services (exchanges, well-known dApps)
- No links within one hop to mixers (Tornado, Sinbad, ChipMixer) or known scam wallets
- Owner identity confirmed through an independent channel (their verified domain, a signed message, a known ENS)
The red flag patterns
- Fresh wallet, instant high volume. Created today, already received 200 deposits. Deposit funnel.
- Money-in only, never money-out. Either cold storage (fine if it matches the use case) or a frozen scam account.
- High percentage of inbound TXs from many one-time senders. Classic pig-butchering pattern.
- Outbound only to mixers or sanctioned addresses. Money-laundering wallet.
- The same address advertised by multiple unrelated "investment opportunities." It's the operator's pooled deposit address.
The address-poisoning trap
Even if the wallet itself is clean, attackers now poison your transaction history with a fake address that has the *same first and last four characters* as one you've sent to before. You copy from your history thinking it's the same recipient. The funds vanish.
Defense: always verify the middle characters of any address, not just the first/last four. Better: use ENS names, signed payment requests, or your wallet's address-book feature.
The four-second habit
Before any send over $100, paste the address into the GACS Wallet Checker. Four seconds. Free. Catches the vast majority of scam, sanctioned, and drainer wallets before the click that can't be undone.
The transactions you don't reverse are the ones you never sent.
