
A pre-exchange check is designed to catch preventable errors before BTC, ETH, or USDT leaves your control. It cannot prove that an exchange is risk-free, guarantee successful processing, or eliminate market, compliance, cybersecurity, and counterparty risks. Its practical purpose is narrower: verify the website, exchange direction, asset, network, address, amount, quoted result, and evidence trail at two separate moments.
This separation matters because cryptocurrency transfers are generally difficult or impossible to reverse after confirmation. Bitcoin guidance recommends verifying the complete receiving address before sending, while Ethereum security guidance warns that a transfer to the wrong address cannot normally be retrieved without the recipient’s cooperation. [1]
Table of Contents
Express Check: Stop Signals Before You Create an Order
Do not proceed to the full checklist if any critical stop signal appears. A professional-looking interface, HTTPS padlock, advertisement, social media profile, or positive comment is not enough on its own to establish that a website is authentic.
| Signal | What to do | Preliminary outcome |
|---|---|---|
| The domain contains extra words, substituted characters, an unusual subdomain, or an unexpected ending. | Close the page. Reopen the known domain from a saved bookmark or independently verified official source. | Stop if the addresses do not match exactly. |
| “Support” asks for a seed phrase, private key, wallet backup, or remote access to your device. | End the conversation without providing information or signing anything. | Stop. A recovery phrase gives control over the wallet, and legitimate support should not request it. [2] |
| The website, representative, or advertisement promises guaranteed returns, risk-free profit, or multiplication of deposited crypto. | Do not transfer funds in response to the offer. | Stop. Guaranteed crypto returns are a recognized scam indicator. [3] |
| The selected blockchain network is unavailable in either the sending wallet or the receiving order. | Do not choose a “similar” network as a substitute. | Stop until both sides explicitly support the same network. |
| The deposit address changes after copying, without an explained order update. | Cancel the transfer and inspect the device for clipboard malware. | Stop. Clipboard malware can replace a copied crypto address with an attacker’s address. [4] |
| The final amount, fee treatment, asset, or exchange direction is hidden until after payment. | Request clarification through a contact channel reached independently from the suspicious message or page. | Clarification required. |
| You are pressured to send immediately because an exceptional rate or account rescue offer will “expire.” | Pause and repeat the domain, order, and address checks from a clean session. | Clarification required or stop, depending on the response. |
How to Interpret the Three Outcomes
- Continue checking: no critical mismatch has been found, and the information needed for the next verification step is visible. This is permission to continue the audit, not proof of safety.
- Clarification required: a field is unavailable, ambiguous, dynamic, or dependent on compliance review. Do not fund the order until the uncertainty is resolved through a verified service channel.
- Stop: a critical field conflicts with an independent source, the website requests wallet secrets, the network does not match, the destination address changes unexpectedly, or the offer relies on guaranteed profit or coercion.
Two-Pass Pre-Operation Verification Card
The first pass checks the context in which the exchange will occur. The second repeats the fields that can cause an irreversible loss immediately before the wallet’s final send or confirm action. Perform both passes even if the order appears straightforward.
Pass One: Verify the Operation Context
| What to verify | Where to obtain independent confirmation | What a mismatch means |
|---|---|---|
| Exact domain: spelling, domain ending, subdomain, and absence of added characters. | Use a previously saved bookmark or compare the address with an official communication located independently. Do not rely on a link received in an unsolicited message. Ethereum’s security materials recommend carefully checking site addresses and bookmarking known authentic websites to reduce phishing exposure. [5] | A different domain is a stop signal. Do not log in, connect a wallet, or create an order. |
| Exchange direction: the asset you send and the asset you expect to receive. | Compare the order screen with your own intended operation and the balance visible in your sending wallet. | A reversed direction can produce the wrong deposit instructions or an unusable order. Correct it before proceeding. |
| Asset identity: BTC, ETH, or the intended USDT representation rather than a similarly named token. | Check the asset name, ticker, network, and, for tokenized assets, the contract information available from the project’s official documentation and the relevant blockchain explorer. A ticker or token name alone is not proof of identity because different contracts can use identical names and symbols. [5] | An unknown or conflicting contract means stop. Selecting the correct ticker on the wrong token contract does not make the transfer valid. |
| Current availability: the requested asset, direction, pair, and network are active at the time of the operation. | Check the live order interface and confirm unresolved availability questions through the service’s verified support channel. | Do not infer availability from a general asset list. The service works with USDT, BTC, ETH, DAI, LTC, BNB, XMR, and TRX and is gradually adding assets, but this does not mean every pair, network, or direction is currently supported. RUB bank-card exchanges are planned rather than an active function. |
| Blockchain network: the network selected for withdrawal exactly matches the network named in the receiving instructions. | Compare three places: the order, the sending wallet or platform, and official documentation for the asset or token. Use the explorer corresponding to that specific network when checking an address or transaction. | A network mismatch is a stop signal. Matching asset names do not make different blockchain networks interchangeable. |
| Memo, Tag, payment ID, or similar routing field: whether the selected route requires one. | Use the order instructions and the destination wallet or platform’s deposit instructions. Confirm any inconsistency with verified support before sending. | If one side requires a routing field and the other omits it, stop and clarify. A transaction may reach a platform address without being automatically attributed to the intended account or order. |
| Order conditions: displayed rate treatment, applicable fees, minimum or maximum constraints, expiration conditions, and the estimated amount to receive. | Read the current order summary and applicable terms shown before payment. Dynamic values must be checked for that specific order rather than copied from an old screenshot or third-party page. | A missing or inconsistent value requires clarification. Do not assume a fee, limit, rate-lock period, or processing time. |
| Verification and compliance requirements: what information may be required for this direction. | Review the conditions displayed before creating or funding the order and use the verified service channel for questions. | Requirements can depend on the exchange direction and compliance results. If the conditions are unacceptable or unclear, do not fund the order. Do not attempt to bypass identity checks, sanctions controls, geographic restrictions, or applicable law. |
| Source hierarchy: which information is authoritative for each field. | Use the order page for order-specific instructions, the wallet interface for the proposed outgoing transaction, official project documentation for asset and network details, and the correct blockchain explorer for on-chain status. | If an advertisement, messenger account, forum post, or old screenshot conflicts with a primary source, treat the secondary source as unreliable and clarify before proceeding. |
| Support identity: whether the contact method belongs to the service rather than an impersonator. | Open support from the independently verified domain. Do not continue a conversation started through an unexpected direct message without separately confirming the channel. | A representative who requests secrets, a “verification transfer,” remote device control, or payment to recover funds is a stop signal. Crypto recovery offers may themselves be scams. [6] |
Pass Two: Repeat the Critical Fields Before Sending
Begin this pass only when the wallet or sending platform shows its final confirmation screen. Do not approve the transfer while distracted, screen-sharing with an unknown person, or following instructions from an unsolicited caller.
| What to verify | Where to obtain independent confirmation | What a mismatch means |
|---|---|---|
| Destination address: compare the complete address, not only the first and last few characters. | Compare the final wallet confirmation screen directly with the address displayed inside the current order. If a hardware wallet displays the destination, compare its screen as well. Bitcoin safety guidance specifically recommends checking the entire receiving address. [1] | Any unexplained character difference means stop. Delete the pasted address, do not send, and investigate possible clipboard substitution. |
| Address continuity: the address remains the same from the order screen through the final wallet prompt. | Reopen or refresh the active order through the verified domain and compare it with the final transaction details. | An unexplained change means stop. Do not decide which address “looks more plausible.” Obtain clarification through verified support. |
| Selected network: the wallet’s final network label matches the order exactly. | Check the network name, wallet account, native fee asset, and destination instructions together. | A different network means stop, even if the destination format appears compatible. |
| Memo or Tag: required value, exact characters, and correct destination field. | Compare the final wallet screen with the active order instructions. | A missing, altered, or misplaced value requires clarification before sending. |
| Amount sent: the wallet’s outgoing amount matches the amount required by the active order. | Compare the amount in the order with the amount on the final wallet confirmation screen. Account for whether a sending platform deducts its withdrawal fee separately or from the entered amount, using that platform’s displayed preview. | If the amount expected to arrive is uncertain or falls outside the order’s displayed conditions, do not confirm. |
| Amount expected to arrive: the current order still displays the result you have accepted. | Use the current order summary, not search snippets, promotional material, cached pages, or an earlier quote. | A changed result is not automatically evidence of fraud because rates and network conditions may be dynamic, but it requires a fresh decision. Stop if the change is unexplained or the displayed terms are incomplete. |
| Fee and total debit: the wallet’s total deduction is understood. | Read the final wallet or platform preview, including the network or withdrawal fee shown there. | An unexpected total, unusual authorization, or request for an additional unrelated transfer means stop and investigate. |
| Transaction type: a normal transfer is being approved rather than an unrelated contract permission or unlimited token allowance. | Read the wallet’s final action label and transaction details. Ethereum guidance recommends reviewing transaction messages before signing and limiting token spending permissions to what is necessary. [2] | If the wallet asks for an unexplained signature, contract interaction, or broad spending approval, reject it and clarify the required operation. |
| Order state: the order is still active and ready to receive the payment. | Check the status on the verified service page immediately before confirming the wallet transaction. | An expired, cancelled, completed, or replaced order means stop. Do not send to an old address without explicit confirmation for that specific order. |
| Final device check: no unexpected extension, pop-up, remote-control session, or clipboard anomaly is present. | Compare the address on a second trusted display when possible and review active applications or browser extensions if anything behaves unexpectedly. | Unexpected replacement or redirection means stop, disconnect the session, and scan the device before attempting another transfer. |
After completing both passes, one possible next step is to check the currently available exchange conditions. Reconfirm the pair, network, requirements, and order details shown at that moment rather than assuming that a previous route remains available.
Optional Small-Amount Test: What It Can and Cannot Prove
If the service and selected route permit it, and the displayed limits and fees make it practical, a small preliminary transfer can help detect an operational error in the address, network, or routing field. It does not establish the provider’s solvency, guarantee processing of a later transfer, remove compliance risk, or prove that malware will not modify a subsequent address.
A test transfer must receive the same two-pass verification as the main transfer. Never send an arbitrary amount below the displayed minimum, and never assume that a successful historical transaction makes a newly displayed address authentic.
Control Route Before, During, and After the Exchange
| Stage | Control actions | Evidence to retain |
|---|---|---|
| Before payment | Complete both verification passes. Record the order identifier, selected assets and network, displayed amount, destination address, required Memo or Tag, and the order state. Avoid recording unnecessary personal data. | Order identifier, timestamp, non-secret order details, and a screenshot or export of the final terms if permitted. |
| Immediately after sending | Copy the transaction identifier, or txid, from your own wallet or sending platform. Open it in the explorer for the network actually used. Confirm that the destination and amount correspond to the transaction you approved. | Txid, network, sending wallet status, and the time of broadcast. |
| While waiting | Distinguish between wallet broadcast, blockchain confirmation, service detection, compliance review, and exchange completion. These are separate stages and may not update simultaneously. | Explorer confirmation state and service status messages. Public blockchains can provide a persistent transaction record, although interpretation must use the correct network and transaction. [7] |
| After completion | Verify the incoming transaction in the destination wallet and the appropriate explorer. Compare the asset, network, destination address, and received amount with the completed-order record. | Incoming txid, completed order status, and any non-sensitive support correspondence related to discrepancies. |
If the Status Is Delayed, the Amount Differs, or Data Changes
A delay or discrepancy does not identify its cause by itself. Diagnose the stage before contacting support or attempting another transfer.
- Confirm that the transaction was broadcast. Locate the txid in the sending wallet or platform. A local “submitted” message without a txid may mean the transfer has not yet reached the network.
- Use the correct blockchain explorer. Search by txid on the explorer for the network actually selected. Do not use an Ethereum explorer to diagnose a token transfer sent on another compatible-looking network.
- Check the on-chain destination and amount. Compare them with the saved order data. If the on-chain address differs from the address you intended to paste, stop using the device until clipboard malware and browser compromise have been investigated.
- Review the confirmation state. A pending transaction, confirmed transaction, failed transaction, and transaction absent from the explorer require different follow-up actions. Do not repeatedly resend merely because the order page has not updated.
- Check the Memo or Tag. If the destination required an additional routing value, determine whether it appears in the outgoing transaction or platform withdrawal record.
- Compare gross and net amounts. Review whether the sending platform deducted a withdrawal fee from the entered amount and whether the order’s displayed conditions addressed that situation.
- Document changed data. If the order address, expected result, or status changed, retain the old and new non-secret records with timestamps. Do not send to either address until the verified service channel explains which order state applies.
- Contact verified support with diagnostic data. Provide the order identifier, txid, network, timestamps, and a concise description of the mismatch. Never provide a seed phrase, private key, wallet backup, password, or remote access.
- Do not pay an unsolicited recovery agent. No diagnostic result guarantees that funds can be returned, especially after a confirmed transfer to the wrong address or network. Offers to recover crypto for an upfront payment can be a second scam. [6]
Threats Directly Relevant to an Exchange Operation
Phishing and Service Impersonation
Phishing pages can closely reproduce a legitimate exchange interface while changing the order destination, collecting credentials, or prompting a malicious wallet action. Open the service through a verified bookmark, inspect the complete domain, and treat links from advertisements, direct messages, emails, and search results as navigation hints rather than proof of identity. Near-perfect copies of authentic crypto sites are a documented attack pattern. [5]
Clipboard Address Substitution
Clipboard malware monitors copied text and replaces a wallet address before it is pasted. The strongest operational defense at the point of transfer is to compare the complete pasted address with the current order and, where available, with the address displayed by a hardware wallet. If the values differ, do not make repeated copy-and-paste attempts on the same device; disconnect the session and investigate the device first. [4]
Wrong Network or Token Contract
BTC, ETH, and USDT are not interchangeable network labels. USDT may be represented on different blockchains, and matching ticker symbols do not establish that two token contracts or deposit routes are compatible. Verify the exact network on both sides and use official project information when a token contract must be identified. [5]
Seed-Phrase or Private-Key Disclosure
An exchange order should not require a self-custody wallet’s seed phrase or private key. Anyone with that information can control the associated wallet. Do not enter it into an exchange page, support form, screen-sharing session, cloud document, or chat, and do not store screenshots of it with transaction records. [2]
Guaranteed Profit Claims
A crypto exchange performs an asset conversion; it cannot guarantee that the received asset will rise in value. Promises of fixed profit, automatic multiplication, zero risk, or guaranteed returns are unrelated to legitimate order verification and should be treated as stop signals. Crypto prices can also change rapidly, so an exchange decision carries volatility risk even when the technical transfer is completed correctly. [3]
Safe Transaction Record Protocol
Keep only the information needed to trace the operation and explain a discrepancy. A practical record can include:
- order identifier;
- creation and payment timestamps;
- assets and exchange direction;
- selected blockchain network;
- public sending and receiving addresses where necessary for reconciliation;
- Memo or Tag if it is not secret and is required to identify the transfer;
- sent and received amounts;
- outgoing and incoming txids;
- order status and relevant non-sensitive support messages;
- screenshots of order terms with unnecessary personal information redacted.
Do not include seed phrases, private keys, wallet backup files, passwords, authentication codes, card details, identity-document copies, or unrelated personal records in the transaction log. Store the record according to its sensitivity and local legal requirements, which vary between countries.
The operation should proceed only when both passes show no critical mismatch and every ambiguous field has been clarified. If the domain, network, full address, asset identity, routing field, amount, or order state cannot be reconciled with an independent source, the correct next action is not another transfer—it is to stop before the transaction becomes irreversible.
