Is This Crypto Address Safe? How to Check

On February 21, 2025, hackers drained about $1.5 billion in Ethereum from the exchange Bybit in the largest crypto theft on record. The FBI pinned it on North Korea's Lazarus Group within days, and released 51 Ethereum addresses tied to the laundering. The stolen money moved fast: within 48 hours, a large chunk had already been washed through fresh wallets and swapped across chains. Every one of those destination addresses looked, at a glance, exactly like a normal wallet: a string of characters, no name, no history you'd notice unless you went looking.
That's the problem with crypto addresses. They don't come with a reputation attached. A wallet that belongs to a sanctioned mixer and a wallet that belongs to your new client are the same 42 characters of hex. If you send money to the wrong one, or accept a payment that traces back to a mixer or a stolen-funds cluster, you can't claw it back. So before money moves, it pays to actually look. Here's how I do it, what's free, and where a tool earns its keep.
Start with the warning signs that actually matter
Not every "unknown" wallet is dangerous. Most are just new. The signals worth caring about are specific.
Sanctions hits. This is the one with legal teeth. The US Treasury's OFAC publishes a list of Specially Designated Nationals, and since 2018 that list includes specific crypto addresses. Take Sinbad, a Bitcoin mixer that laundered money for Lazarus Group, including part of the $100 million stolen from Atomic Wallet users in June 2023. OFAC sanctioned it on November 29, 2023, with named addresses on the SDN list, and the FBI and Dutch FIOD seized its site the same day. If an address is on that list, touching it isn't a risk judgment. It's a compliance violation, and OFAC enforces it on a strict-liability basis, meaning intent doesn't save you.
Mixer exposure. Mixers pool funds from many users to break the trail. Tornado Cash is the famous one. Its story got complicated: OFAC sanctioned it in August 2022, the Fifth Circuit ruled in November 2024 that Treasury had overstepped by sanctioning immutable smart contracts, and OFAC formally delisted it on March 21, 2025. So the protocol itself is no longer sanctioned. But money that came straight out of a mixer still reads as a red flag to every exchange and counterparty, because you can't see where it was before. And the un-sanctioning didn't clear the people: on August 6, 2025 a jury convicted co-founder Roman Storm of conspiracy to run an unlicensed money-transmitting business. Delisted doesn't mean clean.
Freshly funded burner wallets. A wallet created yesterday, funded once, with no other history, asking you to send first, is the oldest pattern in the book. Launderers spin these up by the thousand. On its own it's not proof of anything, but combined with pressure to move fast, it should stop you.
Known scam and drainer addresses. Wallet drainers, malicious contracts that empty a wallet once you approve them, took roughly $494 million from about 332,000 addresses in 2024, per Scam Sniffer. Overall on-chain scam revenue reached at least $14 billion in 2025, and Chainalysis expects that number to climb past $17 billion as more addresses get identified. Many of these wallets are already tagged. You just have to check.
The free checks anyone can run
You can get surprisingly far without paying for anything.
- A block explorer. For Ethereum and most EVM chains, Etherscan is the default; Bitcoin has Blockstream and Mempool.space; Solana has Solscan. Paste the address and read it. How old is it? How many transactions? Does the balance and flow look like a real person or a pass-through? Etherscan and its peers also apply public labels. Addresses caught in scams get a bright "Fake_Phishing" tag right on the page, plus warnings on known-bad contracts. If you see that banner, you're done. Walk away.
- The OFAC SDN list. It's searchable for free at sanctionssearch.ofac.treas.gov, and it includes crypto addresses. For a one-off check before a big payment, it takes a minute.
- Community label sites. Chainabuse and similar scam-report databases let you search an address against user-submitted fraud reports. Not authoritative, but a hit is a strong signal.
The catch with the manual route: it's slow, it's chain-by-chain, and it only catches what's already labeled and obvious. It won't tell you an address is two hops from a mixer, or that it received funds from a stolen-funds cluster last week. Reading a block explorer well takes practice, and most people accepting a payment don't have ten minutes to trace a transaction graph by hand.
Where a screening tool saves the time
A screening tool does in one query what would take you an afternoon: it checks the address against sanctions lists across every major chain at once, measures how close it sits to mixers, scam clusters, darknet markets and stolen funds, and returns a risk score with the reasons. The value isn't magic. It's coverage and speed. You get the indirect exposure a manual check misses, and you get it in seconds instead of tabs.
This matters more in the EU now, not less. Under the recast Transfer of Funds Regulation, which has applied alongside MiCA since December 30, 2024, crypto providers must attach verified sender and recipient information to transfers, and for transfers over €1,000 to or from a self-hosted wallet, verify who controls it. The transitional window for legacy providers closes July 1, 2026. Even if you're a freelancer and not a regulated provider, the direction is clear: "I didn't know whose wallet it was" is no longer a good answer.
If you're invoicing clients, the cleanest version of this is screening built into the payment flow, so the payer's wallet gets checked automatically before the money lands and you never have to remember to do it. That's the whole idea behind Constatum's address risk check: paste a wallet, or have it run on the payer behind an invoice, and get a plain answer before you're committed.
The honest takeaway
Screening isn't a guarantee. A clean result today can go bad tomorrow if that wallet does something dumb next week, and a flagged result sometimes just means the address touched something risky three hops back through no fault of its owner. Treat the score as evidence, not a verdict. But given that stolen money moved through fresh wallets in under two days after Bybit, and given that a sanctions hit is a legal problem and not just a bad vibe, the thirty seconds it takes to look is the cheapest insurance in crypto. Look before you send. Look before you accept. The address won't tell you on its own.
Sources
- 1.North Korea Responsible for $1.5 Billion Bybit Hack (Public Service Announcement, Alert Number I-022625-PSA) — FBI Internet Crime Complaint Center (IC3)
- 2.Treasury Sanctions Mixer Used by the DPRK to Launder Stolen Virtual Currency — U.S. Department of the Treasury (OFAC)
- 3.Founder Of Tornado Cash Crypto Mixing Service Convicted Of Knowingly Transmitting Criminal Proceeds — U.S. Department of Justice, U.S. Attorney's Office, Southern District of New York
- 4.Tornado Cash Delisting — U.S. Department of the Treasury (OFAC)
- 5.Van Loon v. Department of the Treasury, No. 23-50669 (5th Cir. 2024) — Justia (U.S. Court of Appeals for the Fifth Circuit)
- 6.Record $17 Billion Estimated Stolen in Crypto Scams and Fraud in 2025 (2026 Crypto Crime Report: Scams) — Chainalysis
- 7.Cryptocurrency wallet drainers stole $494 million in 2024 — BleepingComputer (Scam Sniffer data)
- 8.Regulation (EU) 2023/1113 on information accompanying transfers of funds and certain crypto-assets — EUR-Lex (European Union)
This article is general information, not legal, tax, financial, or investment advice. Crypto carries risk — do your own research and consult a qualified professional before acting. Constatum makes no warranty as to accuracy or completeness and accepts no liability for decisions made based on it.


