USDT Safety Basics: Avoiding Scams, Address Poisoning, and Verifying Addresses
How to verify a USDT withdrawal address, spot address poisoning, and avoid common USDT scams before you receive your forex rebate payout.
By CB-Dogs Editorial6 min read
Disclosure: CB-Dogs earns a commission (IB rebate) from brokers for accounts opened or linked through us and pays part of it back to you as cashback. This does not change your trading costs.
On this page
- Why this matters more than you think
- The golden rule: USDT transfers cannot be reversed
- What is "address poisoning"? (the most important section here)
- Other common USDT scam patterns
- A simple pre-send checklist
- Setting up a saved or whitelisted withdrawal address
- A note on TRX, gas, and why a "free" receiving address still matters
- What to do if you think you've been targeted
- Frequently asked questions
- Ready to receive your rebate safely?
If you've received a forex rebate before, it was probably by bank transfer — where a wrong digit gets caught by the bank, or at worst, reversed. USDT doesn't work that way. There's no bank in the middle to catch a mistake, which makes the few minutes you spend verifying an address before your first withdrawal genuinely worth it.
This guide covers the specific things worth knowing before you receive USDT for the first time: why transfers can't be undone, how "address poisoning" tricks people into copying the wrong address, other common scam patterns, and a simple checklist to run through before you send or register anything.
Why this matters more than you think
Registering a withdrawal address is the one point in the entire rebate process where you specify a destination, rather than a broker or bank routing it for you automatically. Get it right once, and every future payout to that address is fine. Get it wrong, and there's no institution positioned to intervene — which is exactly why this one step deserves more care than it looks like it needs.
The golden rule: USDT transfers cannot be reversed
Once a transaction is confirmed on the blockchain, it's final. There's no chargeback, no "please reverse this," and generally no customer service line that can undo it — because there's no central operator with the ability to do so. This is a basic property of how blockchain transfers work, not a policy choice any single service makes.
The one narrow exception worth knowing: if you mistakenly send to an address hosted by an exchange (rather than a private wallet), that exchange may, at its own discretion, be able to locate and return funds — but this is never guaranteed and depends entirely on that exchange's own policies and cooperation.
What is "address poisoning"? (the most important section here)
Address poisoning is a scam built entirely around a habit most people don't realize they have: only glancing at the first and last few characters of a long address before trusting it matches.
How scammers generate a lookalike address
Using freely available tools, a scammer can generate wallet addresses until they find one that starts and ends with the same characters as an address you've used before — while the long middle section is completely different and belongs entirely to them.
The "dust" transaction that plants a fake address in your history
The scammer then sends a tiny, near-zero amount of USDT from that lookalike address to your wallet. Because most wallet apps show recent transaction history — including addresses you never actually chose to interact with — this "dust" transaction plants their lookalike address directly into your history, sitting right next to the real one you actually intend to reuse.
Why checking only the first/last few characters isn't enough
The next time you go to send USDT and try to save time by copying a previously used address from your history, the lookalike sits there looking identical at a glance. If you only check that it starts with "T" and ends with the characters you remember, you can copy the scammer's address instead of your intended one — and send funds you can't get back.
Other common USDT scam patterns
Fake support messages
Anyone contacting you first — by DM, chat widget, or email — asking you to "verify your account" by sharing your seed phrase, private key, or a one-time code is impersonating support. No legitimate service, including CB-Dogs, will ever ask for these.
Phishing links impersonating rebate or exchange sites
A link in an email or ad that looks like a familiar site's login page, but sits on a slightly different domain, is designed to capture your credentials the moment you type them in. Always navigate to sites you use for financial transactions by typing the address yourself or using a saved bookmark, rather than clicking a link from a message.
"Double your USDT" or fake giveaway schemes
Any offer promising to send back more USDT than you send in — often time-pressured with a countdown — is a scam with no exceptions. There's no legitimate mechanism that multiplies a crypto transfer.
Fake or counterfeit USDT tokens
Because USDT exists on multiple blockchain networks, scammers occasionally create a worthless token designed to look identical inside a wallet interface, on the wrong network or an unofficial contract. Sending or receiving USDT specifically on TRC20 (as covered in our TRC20 vs ERC20 vs BEP20 guide) with a wallet from an official source substantially reduces this risk.
Fake "customer support" accounts on social media
A common variation of the fake-support pattern happens on social platforms: a scammer replies to your own public post asking about a payout, presenting themselves as "official support" and asking you to continue the conversation privately. Legitimate support generally doesn't monitor social media for opportunities to slide into your messages — verify any support contact through the channel listed on the provider's own official site, not through whoever replies first.
A simple pre-send checklist
- Compare the entire address, character by character — not just the first and last few characters, which is exactly what address poisoning is designed to exploit.
- Copy only from a saved contact or your own whitelist, not from transaction history, where a poisoned address might be sitting.
- Send a small test amount first, especially to a new or newly registered address, before sending the full amount.
- Access support and login pages only through a bookmarked, official URL, never through a link sent to you.
Setting up a saved or whitelisted withdrawal address
Many wallets and payout services let you save a verified address as a labeled contact, so future transfers reuse a name you recognize instead of a raw string you have to re-verify every time. This is worth setting up the first time you confirm an address is correct, precisely so you never need to trust a copy-pasted string from memory again.
On CB-Dogs, your payout address works the same way: you register one TRC20 address in your account settings, confirm the change by email, and every payout goes to that saved address. When you change it, withdrawals pause for 24 hours so that a hijacked account cannot quietly redirect your cashback.
A note on TRX, gas, and why a "free" receiving address still matters
Receiving USDT on TRC20 doesn't require you to hold any TRX (TRON's native coin) yourself — that requirement only applies later, if you want to send USDT onward from your wallet to somewhere else, since sending (not receiving) is what consumes network "energy" or bandwidth. This is worth knowing mainly so you aren't tricked by a message claiming you must "activate" your address or send a small amount of TRX first before a payout can arrive — a legitimate payout to a standard TRC20 address needs nothing from you in advance.
What to do if you think you've been targeted
Before sending: if an address in your history or a message looks even slightly off on close inspection, don't use it. Type or paste your own previously verified address instead, or ask CB-Dogs support directly through the official channel you already have.
After sending: if you've already sent USDT to an address you now believe was fraudulent, the transaction is very likely final. There's no reliable recovery pathway for a confirmed blockchain transfer sent to a wallet the sender doesn't control — the honest step at that point is to stop reusing that address anywhere else and treat it as fully compromised, not to expect a reversal.
Frequently asked questions
Generally, no. Once confirmed on the blockchain, the transfer is final and there's no central operator able to reverse it. The narrow exception is sending to an address hosted by an exchange, which may, at its own discretion, be able to locate and return funds — but this is never guaranteed.
Ready to receive your rebate safely?
If you're setting up a wallet for the first time, start with our wallet setup guide or the dedicated Trust Wallet TRC20 walkthrough. Once you're comfortable with your address, register with CB-Dogs to start earning cashback on your trades.
Risk warning: forex and CFD trading carries a high risk of losing money. Cashback does not offset trading losses. Nothing here is investment advice.