Run a lookup

Crypto

How to check a crypto wallet before you send

The chain will tell you almost everything about an address except the one thing you want, which is who holds it.

7 min read The DetectiveCheck team
CryptoGuide
A bank vault door

The short answer

A wallet address returns its balance, its transaction count, when it was first and last used, and a link to a block explorer. It never returns a name, because no blockchain records one. An address created days ago with few transactions is the signal that matters most.

  • Age and transaction count are the two fields worth reading first, in that order.
  • Explorers disagree, and a measured run got three different answers for one address.
  • A clean history proves nothing. Scam addresses are clean right up until they are not.
  • Nothing on the chain names anybody, whatever a service advertises.

What does a wallet address actually tell you?

Everything about the money and nothing about the person.

Paste a Bitcoin or Ethereum address into the box on this page and it goes to six explorers at once. What comes back is the current balance, the total number of transactions, the first and last time the address moved anything, and a link into a block explorer so you can read the transactions yourself.

What never comes back is a name. The chain records addresses and amounts, and identity was never one of the fields. Any service claiming to hand you the owner of an arbitrary address is either selling you an exchange leak or guessing.

That sounds like a limitation and is mostly not one, because the question is usually whether to send rather than who is receiving.

one address inBalanceTransaction countFirst and last seenExplorer linkOwner's nameone address inBalanceTransaction countFirst and last seenExplorer linkOwner's name
One address in, and what the chain publishes about it. The owner's name is dashed because no blockchain has ever held one.

Which fields matter before sending money?

Two, and they are both about time rather than amount.

Age. When did this address first do anything? An address created four days ago, presented as belonging to an established business or a long-standing trader, has contradicted the story. Legitimate operations reuse addresses and accumulate history.

Transaction count. A handful of transactions on an address you were told handles hundreds of customers is the same contradiction in a second form. High counts prove nothing on their own, but low counts plus a big claim is a genuine mismatch.

Balance is the field everybody looks at first and it is the least useful. It changes hourly, it can be inflated deliberately by moving funds in before a conversation, and it says nothing whatever about whether money sent there is coming back.

Why do block explorers disagree?

Because they count different things, and a measured run makes that concrete.

The Bitcoin genesis address 1A1zP1eP5QGefi2DMPTfTL5SLmv7DivfNa, queried through three explorers in the same run, returned three answers: 107.33 BTC with 0 transactions, 107.33 BTC with 64,278 transactions, and 57.32 BTC with 64,262 transactions.

None of them is lying. The 50 BTC gap is the genesis block's own reward, which by a quirk of Bitcoin's earliest code is not in the spendable output set, so explorers differ on whether to count it. The zero transaction count is one API not returning that field rather than an address with no history.

Read at least two, and expect the gap. One explorer is one implementation's opinion. The disagreements are usually definitional, and knowing that stops you treating a gap as fraud.

The ledger is public and permanent. What it never contains is a name, which is the part people assume is in there.

The ledger is public and permanent. What it never contains is a name, which is the part people assume is in there.

Can you tell whether an address belongs to a scammer?

Sometimes, and never from the chain alone.

Reported addresses are collected in public abuse databases, and an address that appears there is settled. But reporting is slow and comes from victims, so the database is a record of what has already happened to somebody else. A fresh scam address is clean by definition.

What the chain does show is a shape. Money arriving from many addresses and leaving immediately to one, over and over, is the pattern of a collection wallet rather than a business. So is an address that receives and forwards within minutes, every time.

Read the movement rather than the balance. A wallet that never holds anything is not a wallet, it is a waypoint, and a waypoint between you and somewhere you were not told about.

What extra does an Ethereum address show?

Token holdings, and they are more revealing than the balance.

A measured run against a published Ethereum address returned 6.63 ETH, the ten most recent transactions with hashes and timestamps, and 6,437 distinct tokens. That last number is not wealth. It is airdrop spam: anybody can send a worthless token to any address, and scammers do it to put a contract address in front of you.

So a long token list is normal for an old address and means nothing about its owner. What is worth reading is whether the tokens with real value match the story you were told.

Ethereum addresses can also carry an ENS name, and that is the one route from an address to a human, because the owner chose to publish it.

Can you get the money back?

Almost never by yourself, and the recovery services that say otherwise are a second scam.

A confirmed transaction is final. There is no reversal, no chargeback and no authority that can undo it. What can occasionally happen is that funds reaching a regulated exchange get frozen, which needs the exchange and law enforcement rather than a firm that found you.

So the useful action is fast and unglamorous: record the address, the transaction hash and the time, then report to your national fraud body. In the United States that is IC3, and the address is the single most useful thing you can give them.

Nobody legitimate contacts you offering recovery. Recovery scams target people who have already lost money, using victim lists from the first scam. An upfront fee to recover crypto is the tell.

Yes. Blockchain data is published by design and reading it needs no permission from anybody.

The rules apply to what you do next, exactly as they do elsewhere. In the United States, using a result in a decision about credit or employment falls under the Fair Credit Reporting Act. In the EU and the UK, an address tied to a known person becomes personal data and needs a lawful basis.

That second point catches people out. An address by itself is not personal data; the moment you link it to a name it is, and the link is the thing you were trying to build.

Checking an address somebody asked you to send money to sits comfortably inside all of this. Building a running ledger of a named person's transactions is a different activity using the same public data, and the difference is purpose rather than technique.

Common questions

How do I check a crypto wallet address before sending money?

Paste it into a lookup that queries several block explorers. Read the age first, then the transaction count, then the balance. An address created days ago that was presented as belonging to an established business has contradicted the story, and that mismatch is the most useful signal available before you send.

Can you find out who owns a Bitcoin address?

No. The chain records addresses and amounts, and identity was never one of the fields. Services claiming to name the owner of an arbitrary address are selling an exchange leak or guessing. Ethereum is the partial exception, where an owner may have published an ENS name themselves.

Why do block explorers show different balances?

Because they count different things. One measured run against the Bitcoin genesis address returned 107.33 BTC with 0 transactions, 107.33 with 64,278, and 57.32 with 64,262. The 50 BTC gap is the genesis block reward, which is not in the spendable output set, so explorers differ on counting it.

How do I know if a wallet address is a scam?

Check public abuse databases, which settle the question when the address appears. They lag, though, because reports come from victims, so a fresh scam address is clean by definition. The chain shows shape instead: money arriving from many addresses and forwarding out within minutes is a collection wallet, not a business.

What does a large token list on an Ethereum address mean?

Usually nothing. A measured run returned 6,437 distinct tokens on one address, and almost all of that is airdrop spam: anyone can send a worthless token to any address, and scammers do it to put a contract in front of you. A long list is normal on an old address.

Can a crypto transaction be reversed?

No. A confirmed transaction is final, with no chargeback and no authority that can undo it. Funds reaching a regulated exchange are occasionally frozen, but that needs the exchange and law enforcement. Record the address, the transaction hash and the time, then report it.

Are crypto recovery services real?

Almost never. Recovery scams deliberately target people who have already lost money, working from victim lists generated by the first scam. Any upfront fee to recover cryptocurrency is the tell. Nobody legitimate contacts you unprompted offering to get your money back.

Is it legal to look up a wallet address?

Yes. Blockchain data is published by design and reading it requires no permission. The limits are on use: an address by itself is not personal data, but the moment you link it to a named person it becomes personal data under the GDPR, and that link is usually what you were trying to build.

In short

Read age and transaction count before balance. An address created last week, presented as an established business, has already answered the question you were asking.

Explorers disagree for definitional reasons, so read more than one. And no chain holds a name, whatever a service selling wallet-to-identity lookups tells you.

Written by the DetectiveCheck team

We build the lookup engine this site runs on, so the numbers in these guides are the ones our own reports use: 71 sources against an email address, 71 platforms against a username, 13 registers against a name, and 8 against a phone number. Where a module is thin, we say so rather than round it up.

Run one yourself

Create an account and the first report is a couple of minutes away. Nobody you look up is told.

Create my account

Plans from $15 a month. Cancel in one click. Or read a sample report first.

Try it on something you already have