TRON phishing address checker
Check a TRON address against Tether’s official USDT blacklist, and learn the approval, permission and address-poisoning tricks that no list can catch on its own.
What the phishing screen returns
Paste the destination and the free check asks whether Tether has blacklisted it on the USDT TRC20 contract. Phishing on TRON almost never breaks cryptography. It persuades the account holder to authorise something — a transfer, an unlimited token allowance, or a change to the account's own permissions. That distinction matters for what you do next, because a plain payment and an approval need very different remedies. The screen answers one narrow question about USDT blacklist status; the sections below cover the tricks that leave no address to look up at all.
Approvals: the drain that needs no seed phrase
TRC20 tokens let a contract spend on your behalf once you approve an allowance, and phishing sites request unlimited allowances behind buttons labelled Claim, Verify or Enable. Nothing leaves immediately, which is exactly why the trick works — the wallet looks fine for hours or weeks, then a sweep empties the token balance the moment a deposit arrives. If a site asks you to approve rather than send, stop and read the token and spender in the wallet prompt. Existing allowances can be inspected and revoked from your address page on a block explorer, and revoking is the first thing to do after any suspected phishing interaction.
Permission hijack is TRON's own variant
TRON accounts carry an owner permission and one or more active permissions, and an AccountPermissionUpdate transaction can hand those keys to someone else. Victims of fake support and fake staking dashboards are walked through signing exactly that, usually described as activation, verification or multi-signature security. Afterwards the seed phrase still opens the wallet, but the account no longer obeys it: every outgoing transaction needs the attacker's signature, and incoming funds are swept on arrival. Check the permissions tab of your address on a block explorer if a wallet has started behaving strangely. Recovering control is often impossible, which makes this the one prompt never to sign for a stranger.
Poisoned history and hijacked clipboards
Address poisoning targets the habit of copying a destination out of transaction history. An attacker generates a vanity address that matches the first and last characters of one you use, sends a zero-value or dust TRC20 transfer so it appears in your list, and waits for the wrong line to be copied. Clipboard malware does the same job on the device, swapping a T-address the instant you press paste. Both defeat every blacklist, because the address you check and the address you send to are not the same string. Compare the full destination — not just the ends — in the wallet's confirmation screen, every time, including on repeat payments.
Screen, revoke, then decide
A practical order of operations: look up the destination here, read the category if there is a hit, then check your own address for open allowances and unexpected permission entries before moving anything. Move remaining balances to a wallet whose seed has never touched a browser prompt if you interacted with a suspicious site. Report the receiving address wherever the community collects reports, since coverage only improves when victims file. When the exposure is large or the counterparty is unfamiliar, the optional deep scan adds multi-hop context and entity labels after one wallet confirmation — network fee only, and no seed phrase is ever requested.
FAQ
I approved a contract but did not send anything. Am I safe?
Not yet. An unlimited allowance lets the spender move that token later, including funds you receive afterwards. Revoke the allowance from your address page on a block explorer, then treat the wallet as suspect until the balance is clear.
Can a phishing site steal TRX just because I visited it?
No. Something has to be signed in your wallet — a transfer, an approval or a permission update. The danger begins at the confirmation prompt, so read what the prompt asks for rather than what the page claims it does.