Address mistakes in crypto are irreversible. Here's a step-by-step security checklist for verifying your destination wallet — and avoiding the most common mistakes.
There is no undo button in crypto. Once a transaction broadcasts to the network, it cannot be reversed. This makes verifying your destination wallet address one of the most critical — and most underappreciated — steps in any exchange.
Every week, funds are permanently lost due to simple address errors: a typo, a clipboard hijacker, a copy from the wrong tab. This guide covers the checks you should run every time before you create an exchange order.
1. Never trust clipboard alone
Clipboard hijacking malware silently replaces the address in your clipboard with an attacker-controlled address. You copy your Ethereum address, paste it into the form — and it's actually the attacker's address.
After pasting, always visually compare the first 6 and last 6 characters of the pasted address against the original source. Better still, open your wallet and use its QR scanner or "copy address" button directly — never from a website or message.
Check first 6 and last 6 characters. Attackers generate vanity addresses that match the start or end — but rarely both.
2. Verify the network matches
An Ethereum address and a BNB Smart Chain address look identical — they start with 0x and are 42 characters long. Sending ETH to the right address but on the wrong network means your funds land in a contract that may not be able to forward them.
- Open your wallet and confirm the active network matches the 'receive' currency on your exchange order
- For USDT and USDC, check whether you're receiving the ERC-20, TRC-20, or BEP-20 version
- If in doubt, send a small test amount first
3. Use a freshly generated address when possible
Most modern wallets (hardware and software) support generating a new receive address for each incoming transaction. Using fresh addresses reduces address reuse, which is better for privacy — and it forces you to generate and copy the address right before you need it, reducing the clipboard attack window.
4. Double-check on a second device or browser
If you're moving a large amount, open your wallet on a second device and compare the destination address character by character. Browser extensions and malware are device-specific — a second, clean device gives you an independent confirmation.
5. Beware of address shortening
Some interfaces display shortened addresses like 0x1234...abcd. These are for display convenience only — always expand the full address and verify it completely before trusting it. Never approve a transaction based on a truncated address.
What Cambio does on our end
We validate address format against the expected network before allowing order creation. If you enter a BTC address in the ETH receive field, we'll catch the format mismatch. However, we cannot verify that you control the address — that responsibility stays with you.
Take 60 seconds before every exchange to run through this checklist. In a space where mistakes are permanent, those 60 seconds are among the most valuable you'll spend.



