Guide6 min read

The 7 most common USDT scams and how to spot them

Fake tokens, address poisoning, fake support and infinite approvals: the 7 most frequent USDT scams and the warning signs that give each one away.

Person reviewing a suspicious transaction on their phone
Photo: Daria Nepriakhina epicantus / Wikimedia Commons (CC0)

Almost every USDT scam in circulation doesn’t attack the blockchain — it attacks your hurry. Nobody is breaking TRON’s or Ethereum’s cryptography. They convince you to sign, paste or install something you approve yourself. The good news: these scams reuse the same handful of scripts, and once you know them they get pretty obvious.

Here are the seven we see most often, each with the specific tell that gives it away.

1. Fake tokens: “I got USDT” — except it isn’t USDT

Anyone can deploy a token on TRON, Ethereum or Solana and call it “USDT” or “Tether”. No permission required: the name and symbol are just free text inside the contract. The only thing that makes real USDT real is its contract address.

The classic version: someone “pays” you with a cloned token. Your wallet shows “1,000 USDT”, you hand over the goods or the cash, and later you find out the token can’t be sold anywhere.

How to spot it: before treating anything as received, check the contract on a block explorer (Tronscan, Etherscan, Solscan) and compare it against the addresses Tether publishes on its official site. If the token has no verified label, or you can’t find that contract in any official source, it isn’t USDT. And always be suspicious of tokens that simply appear in your wallet unannounced.

2. Address poisoning

You receive a 0 USDT transfer from an address whose first and last characters match your regular contact exactly. Nothing was stolen — your history was polluted. Next time you send and copy the address “from recent transactions”, you copy the attacker’s.

How to spot it: never copy addresses from transaction history. Use a saved contact, a QR code, or ask for it again through your usual channel. And check the characters in the middle of the address, not just the first and last four — that’s where the trick falls apart.

3. “Support staff” asking for your seed phrase

You post a question in a Telegram group, on X, or in a WhatsApp chat, and within two minutes someone from the “official team” DMs you. They’re friendly, competent, and at some point they ask for your 12 or 24 words “to validate your wallet”, or send a link to “sync” it.

How to spot it: this one is foolproof — no legitimate support ever asks for your seed phrase. Not partially, not “just the first six”, not typed into a web form. Anyone who asks is robbing you. Full stop. If you’re unsure what a seed phrase is or how to store it, start with our seed phrase guide.

4. Infinite approvals on lookalike sites

Many web apps ask you to “approve” your USDT before trading. That approval is a standing permission for a contract to move your tokens, and by default it’s usually unlimited. A cloned site — with a domain nearly identical to the real one — asks for that signature, and from then on it can drain your USDT whenever it likes, even weeks later.

How to spot it: be suspicious of any signature request that isn’t a plain transfer. Read what you’re approving and which contract gets the permission. If you use your wallet only to hold, send and receive stablecoins, simply never sign approvals — you don’t need them.

5. Fake payment receipts in P2P trades

You’re selling USDT for a bank transfer. The buyer sends a screenshot of the payment: flawless, with your name and the exact amount. You release the USDT. The money never lands — the screenshot was edited, or the payment came from a third-party account that later gets reversed as fraud.

How to spot it: never release funds against a screenshot. Only against money credited and available in your own banking app. And refuse payments arriving from an account whose name doesn’t match the buyer’s — that’s the signature of triangulation with stolen funds.

6. Fake apps, installers and browser extensions

You search for your wallet, click the first result — which is an ad — and download an installer that looks identical to the real thing. Or you install a browser extension with great reviews. The wallet works perfectly… until it drains your funds, or until a clipboard hijacker silently swaps the address you paste when sending.

How to spot it: always download from the official domain, typed by hand in the address bar — never from an ad or a link someone sent you. And after pasting a destination address, read it again on screen before signing. If it changed, you have malware.

7. “Investment” platforms where withdrawals get stuck

The most expensive one on this list. Someone reaches out — a new friendship, a romance, a signals group — and walks you into a platform showing growing USDT returns. Small withdrawals work at first. When you try to take everything out, a “tax”, a “release fee” or a “verification” appears, demanding a further deposit.

How to spot it: guaranteed returns are always a lie, and being asked for new money in order to withdraw your own money is the unmistakable signature of fraud. No legitimate system works that way.

What your wallet should be doing for you

A good wallet doesn’t replace judgment, but it does shrink the attack surface. Three things worth demanding: that it be genuinely non-custodial (keys on your device — what that actually means), that it show you the network and the full cost before you sign, and that it not force you into odd detours just to move your money, like buying TRX only so you can send USDT.

That last point matters more than it sounds: a lot of scams get in precisely through that detour, while you’re scrambling for gas in an improvised P2P group. Vexo Wallet is non-custodial, requires no account and no KYC, and lets you send USDT on TRON without holding TRX, USDC on Polygon without POL, and stablecoins on Solana without SOL. Fewer steps, fewer people in the middle, fewer openings for someone to slip in.

Frequently asked questions

How do I know the USDT I received is real? Check the contract address on a block explorer and compare it with the one Tether publishes officially. The name and symbol shown on screen prove nothing.

I received a token I never asked for — what now? Nothing. Don’t sell it, don’t swap it, and don’t visit the site named in it: that’s the bait. Just ignore or hide it.

Can USDT sent to a scammer be recovered? No. Blockchain transactions are irreversible and nobody has the power to undo them. That’s why the entire defense lives in the moment before you sign.

Is it safer to leave my USDT on an exchange? It’s a different risk, not a smaller one: you’re protected from your own mistakes, but exposed to a third party’s solvency and policies — including a frozen account.

Are gasless transfers safe? Yes, as long as you sign them yourself on your device with your own keys. The service only fronts the network toll; it can’t move your funds or access your seed phrase.