· USDT blacklist · TRON mainnet

How to spot TRON phishing

The tells that show up before a TRON phishing loss: manufactured urgency, cloned domains, approval prompts, permission changes and poisoned address history.

Five tells, in the order you meet them

Phishing arrives as a sequence, and each stage has a signature. The message manufactures urgency and steers you into one channel. The link resolves to a domain that is nearly right. The page asks the wallet for more authority than the task needs. The prompt says approve or update permissions where a plain transfer would do. And your own transaction history quietly contains a lookalike address waiting to be copied. Any one of these should stop you; together they are the whole playbook. None of them requires the attacker to break TRON cryptography, which is why attention at the confirmation screen protects better than any amount of technical hardening.

The message: urgency plus a single channel

Real problems tolerate delay. Phishing does not, because the script depends on you acting before checking. Watch for deadlines measured in minutes, warnings that an account will be frozen, refunds that expire, and airdrops with countdown timers. Notice too that the message always funnels you somewhere specific — a chat handle, a form, a support link — and resists any attempt to move to a channel you already trust. A genuine exchange or wallet team is happy for you to close the message and log in yourself. If the sender objects to that, the objection is the evidence, whatever else the message contains.

The site: nearly right is the whole trick

Cloned front-ends copy the real interface pixel for pixel and differ only in the address bar: an extra hyphen, a swapped letter, a different top-level domain, or a lookalike character from another script. Paid search results and social replies are common delivery routes, so arriving from an ad is itself a risk factor. Type known domains by hand or use your own bookmarks, and never reach a wallet dashboard through a link somebody sent you. Check the certificate name if anything feels off. A padlock only proves the connection is encrypted; it says nothing about who is on the other end of it.

The prompt: what your wallet is really being asked

This is the moment that matters. A payment prompt shows a destination and an amount. An approval prompt names a token and a spender and often an unlimited allowance, which lets that spender move funds later without asking again. A permission update rewrites who controls the account itself, so the seed phrase still opens the wallet while every transaction needs someone else's signature. Read the transaction type in the wallet, not the label on the button in the page. If a claim, a verification or a security upgrade needs anything other than a straightforward transfer, close the tab and verify independently before signing.

The history: poisoned lookalikes and swapped clipboards

After the site and the prompt comes the quiet attack. Dust and zero-value TRC20 transfers seed your transaction list with vanity addresses matching the first and last characters of ones you actually use, in the hope that you copy from history next time. Malware on the device does the same job at paste time. Both bypass every reputation check, because the address you screened is not the address in the field. Compare the entire destination in the confirmation screen, keep a short list of saved recipients in the wallet, and re-verify large payments out of band even when the transfer looks routine.

FAQ

I received a tiny unknown USDT transfer. Is that dangerous by itself?

The transfer itself cannot hurt you. It is bait for address poisoning: the sender wants their lookalike address sitting in your history. Never copy destinations from incoming transactions, and mark the entry as spam if your wallet allows it.

Does a hardware wallet prevent TRON phishing?

It protects the key, not the decision. You can still approve an unlimited allowance or a permission update from a hardware wallet. Its real advantage is showing the transaction details on a screen malware cannot rewrite — but only if you read them.