
A legitimate cryptocurrency exchange operation requires a destination address and, in some cases, a Memo or Tag. It does not require the seed phrase or private key that controls your wallet. This pre-operation check helps you identify that boundary, verify the transaction details twice, and stop when a request could expose your funds. It reduces avoidable mistakes but cannot remove every risk, including phishing, malware, address substitution, network errors, volatility, or blockchain finality.
Express check: stop signals before you prepare the transfer
- Stop if a website, support agent, chatbot, form, browser extension, or exchange counterparty asks for your seed phrase, recovery phrase, private key, wallet backup, or a screenshot containing any of them.
- Stop if you are told that revealing a secret is necessary to “connect,” “validate,” “synchronize,” “unlock,” “repair,” or “verify” your wallet. A seed phrase can provide control over all accounts derived from it, while a private key controls the corresponding account. Anyone who obtains the relevant secret may be able to move the assets. [1]
- Stop if an unexpected message directs you to a site where you must import or restore your wallet. Phishing pages commonly imitate real services and ask visitors to enter wallet secrets. [1]
- Stop if someone promises guaranteed returns, risk-free profit, or a multiplied payment after you send cryptocurrency. Guaranteed-profit claims are a recognized sign of fraud. [2]
- Clarify before continuing if the asset, exchange direction, receiving network, amount, fees, expected result, compliance requirements, or Memo/Tag instructions are missing or have changed.
If none of these signals appears, you may continue the verification process. That is not a declaration that the operation is safe; it only means that an obvious reason to stop has not yet been found.
Why an exchange does not need control of your wallet
Your wallet uses a private key to authorize transactions. A seed phrase is commonly used to recover a wallet and may restore multiple private keys and accounts. The receiving party needs only the public transaction information required for the transfer, such as the deposit address and any destination identifier explicitly assigned to the operation. It does not need the secret that authorizes spending.
Entering a seed phrase into an exchange form is not comparable to entering a one-time code or account password. A password may protect an account at one company; a seed phrase can restore the wallet itself. Changing the exchange account password afterwards does not cancel a leaked seed phrase. Ethereum’s official security guidance describes the recovery phrase as the wallet’s master key and states that legitimate services and support agents should not request it. [1]
Do not send wallet secrets in a support ticket, email, messenger conversation, cloud document, or screenshot. Online copies may be exposed through phishing, account compromise, malware, automatic cloud synchronization, or unauthorized remote access. Bitcoin security guidance also warns that backups exposed to a network are vulnerable to theft. [3]
Two-pass pre-operation verification card
Complete the first pass while preparing the exchange. Complete the second pass immediately before approving an irreversible wallet action. Obtain information from the service interface you reached independently, your own wallet, the relevant network’s official documentation, and a suitable blockchain explorer. Do not rely only on values copied from a message or supplied by an unknown person.
Pass one: verify the operation context
-
Domain and entry point
What to verify: Confirm that the domain is spelled correctly, uses the expected secure connection, and was not opened from an unexpected advertisement, email, direct message, or support reply.
Independent confirmation: Compare it with a previously saved bookmark or an official channel reached independently. Check for substituted letters, added words, unusual subdomains, redirects, and unexpected wallet-import forms.
What a mismatch means: A spelling difference, unexplained redirect, or request for wallet secrets is a reason to stop. Close the page rather than using a link supplied by the person who contacted you.
-
Exchange direction and supported asset
What to verify: Confirm which asset you are sending and which asset you expect to receive. The service supports assets including USDT, BTC, ETH, DAI, LTC, BNB, XMR, and TRX, while adding assets gradually. This does not mean that every pair, network, or direction is currently available.
Independent confirmation: Check the live exchange form and the current conditions shown before creating the request.
What a mismatch means: If the selected asset, pair, or direction is unavailable or different from your plan, do not substitute another network or token merely because its ticker looks similar. Clarify availability or choose a supported operation.
-
Blockchain network
What to verify: The sending network in your wallet must match the receiving network stated in the exchange request. Pay particular attention to assets that can exist on more than one network.
Independent confirmation: Compare the network label in the request with the withdrawal or send screen in your wallet and, when needed, the asset issuer’s or network project’s official documentation.
What a mismatch means: Similar address formatting does not prove network compatibility. If the names differ or the service does not clearly identify the network, the operation needs clarification. Do not send until both sides explicitly match.
-
Conditions, checks, and source of instructions
What to verify: Review the current amount limits, displayed fees, expected result, rate conditions, required confirmations, and any verification requirements presented for this particular direction.
Independent confirmation: Use the current request interface and official support channel reached from the verified domain. Verification requirements can depend on the transaction direction and the outcome of compliance checks, so they should be reviewed before creating the request.
What a mismatch means: If a messenger contact gives different conditions, pressures you to bypass the normal form, or asks for secrets, stop. If the interface itself contains incomplete or inconsistent information, clarify it before proceeding.
-
Receiving details
What to verify: Confirm that the service has generated or displayed the receiving address for your specific request. If a Memo, Tag, payment ID, or similar field is required, confirm its exact value and purpose.
Independent confirmation: Read the details directly from the verified request page rather than from a forwarded screenshot or message.
What a mismatch means: An address received only through chat, or a required destination identifier that is absent or inconsistent, is not ready for payment. Request clarification without disclosing the contents of your wallet.
Pass two: repeat critical checks before approving the transaction
-
Destination address
What to verify: Compare the complete destination address displayed by your wallet with the address in the active request. Do not check only the first and last few characters.
Independent confirmation: Return to the verified request in a separate trusted view. If you copied the address, check it again after pasting because malicious software can replace clipboard contents.
What a mismatch means: Any changed character means stop. Clear the field, investigate the source of the replacement, and do not approve the wallet transaction.
-
Memo, Tag, or other destination identifier
What to verify: If the request states that an additional identifier is required, make sure it appears in the correct wallet field and matches exactly.
Independent confirmation: Compare the wallet’s final confirmation screen with the active exchange request and the relevant wallet instructions.
What a mismatch means: A missing or different identifier may prevent automatic allocation of the deposit. Pause and clarify; do not guess or place it in an unrelated field.
-
Asset and network on the final wallet screen
What to verify: Confirm the exact asset and network again. The final approval screen, not your earlier intention, determines what the wallet will broadcast.
Independent confirmation: Compare the wallet’s final network label with the request’s network label.
What a mismatch means: Cancel the approval. Reopen the operation and select the correct network only if it is explicitly supported for that exchange direction.
-
Amount and network fee
What to verify: Confirm the amount being sent, the asset denomination, the network fee shown by the wallet, and whether the wallet subtracts that fee from the entered amount or charges it separately.
Independent confirmation: Compare the wallet’s final debit with the amount required by the active request.
What a mismatch means: If the amount would fall outside the displayed conditions or differ from the required deposit, cancel and recalculate. Do not assume the service will automatically correct an underpayment or overpayment.
-
Expected amount to receive
What to verify: Review the result currently displayed by the request, including any stated rate behavior or deductions. Cryptoasset prices and network conditions may change, and the final result may depend on the terms presented for that operation.
Independent confirmation: Use the current request summary, not an older screenshot, advertisement, or quoted message.
What a mismatch means: A material unexplained difference requires clarification before sending. It is not a reason to reveal a seed phrase or grant remote access to “fix” the quote.
-
Final secret check
What to verify: Make sure the process has required only transaction data and ordinary account verification relevant to the operation—not a seed phrase, private key, wallet backup, or remote control of your device.
Independent confirmation: Consult the official security documentation for your wallet or blockchain. The person holding a private key or seed phrase can control the corresponding wallet, and confirmed blockchain transactions generally cannot be reversed by a support agent. [1]
What a mismatch means: Stop immediately. Do not continue even if the request appears under a support logo or is described as a temporary verification step.
After completing both passes, a practical next step is to check the current exchange direction and its conditions. Availability and requirements should be confirmed for the specific asset and network before a request is created.
How to interpret the result
You may continue checking
This outcome applies when the domain and source are consistent, the operation is available, the asset and network match, all required fields are present, and no one has requested a wallet secret. Continue with the final wallet review; this status is not a guarantee against malware, service disruption, volatility, or user error.
You need clarification
Use this outcome when conditions are incomplete, a network label is ambiguous, the expected result has changed, a Memo or Tag requirement is unclear, or the request details differ between official service screens. Do not send while the uncertainty remains. Contact support through the verified domain and provide only the minimum non-secret information needed to identify the request.
Stop
Stop when anyone requests a seed phrase or private key, the address changes after copying, the domain appears imitated, the selected network conflicts with the receiving network, or you are pressured with guaranteed returns or an artificial deadline. Closing the page and declining the transaction is safer than attempting to test whether the requester is genuine.
Control route before, during, and after the exchange
Before sending
Create the request only after checking availability and current conditions. Keep the seed phrase offline and away from cameras, screen-sharing software, cloud notes, and support chats. Verify the address, network, amount, and any Memo or Tag using the two-pass card. If the wallet shows an unfamiliar authorization or asks you to import another wallet, cancel rather than approving experimentally.
While waiting
Record the transaction ID, then check the transaction through a blockchain explorer appropriate for the network. Distinguish between a transaction that has not been broadcast, one that is pending, and one that has received confirmations. Use the request status page reached through the verified domain. Do not follow an unsolicited “recovery” link or pay an extra cryptocurrency fee to a person claiming they can release the transaction.
After confirmation
Compare the completed request with the recorded asset, network, sent amount, transaction ID, and received amount. If the result is consistent with the displayed terms, close the request and retain only the operational record you may reasonably need. If something differs, preserve evidence before refreshing or deleting messages, but do not store wallet secrets with the record.
Recovery steps when the status is delayed or details change
If no transaction ID exists: Check your wallet activity and whether the send action was actually approved. Do not repeat the payment solely because a chat message says the first one failed.
If a transaction ID exists but the request has not updated: Open the transaction in the correct network’s blockchain explorer. Confirm the destination address, amount, network, and confirmation status. A valid transaction ID is diagnostic information; it does not prove that the address or network was correct.
If the sent amount differs: Compare the wallet’s total debit, the transferred amount, and the network fee. Save the request identifier and transaction ID, then contact the verified support channel. Do not assume that a mismatch can be refunded or corrected.
If the request address or conditions changed after payment: Preserve screenshots of the request status, timestamps, and transaction details. Do not send a second payment until the discrepancy has been explained through the verified channel.
If you disclosed a seed phrase or private key: Treat the corresponding wallet as compromised. Stop using the exposed wallet for new deposits, disconnect from the suspicious site, and follow the official security instructions provided by your wallet manufacturer or project. Moving remaining assets may require creating a new wallet with a new recovery phrase on a trusted device, but the correct response depends on the wallet, network, and whether an attacker is already active. Never ask an unknown “recovery specialist” to perform this task with the exposed secret; recovery scams may target people who have already lost funds. [4]
Threats directly relevant to an exchange operation
- Phishing: A copied service page may collect login data or wallet secrets. Reach the service independently and reject any form asking for a seed phrase.
- Address substitution: Malware or a manipulated page may replace a copied destination. Compare the complete address after pasting and again on the wallet’s approval screen.
- Wrong network: The correct token name does not by itself establish network compatibility. Match the sending and receiving network labels exactly.
- Seed phrase or private-key exposure: Disclosure can transfer effective control of the wallet. No exchange rate, support procedure, or identity check justifies sharing these secrets.
- Guaranteed-return promises: An exchange converts assets under stated conditions; it cannot guarantee investment profit. Claims of certain income or multiplied deposits are stop signals, not exchange terms. [2]
Safe operation record
Keep a concise record containing the request identifier, transaction ID, asset, network, sent amount, received amount, relevant timestamps, and the final status shown by the service. A copy of the non-secret request terms may also help diagnose a discrepancy.
Do not store a seed phrase, private key, wallet backup, password, one-time code, identity document, or unnecessary personal conversation in the same record. The purpose of the record is to trace the operation without creating a second source of wallet exposure.
The simplest boundary is also the most important: an exchange may need you to send cryptocurrency to a verified address, but it does not need the secret that gives it control over everything in your wallet.