Reading a Receive Address on Your Hardware Wallet Screen
Address substitution attacks replace a legitimate receive address with an attacker-controlled one. The swap can happen through clipboard malware, compromised browser extensions, or a manipulated QR code on a phishing site. The only reliable defense is confirming the address on your hardware wallet’s physical screen before sharing it or sending funds.
The Verification Ritual
- Open your wallet software and click “Receive.”
- The software displays an address and often a QR code.
- Instead of copying immediately, look at your hardware wallet screen.
- The device should show the same address character by character.
- Compare at least the first six and last six characters.
- Only after matching should you copy or share the address.
Why Partial Comparison Works
Full addresses for Bitcoin and Ethereum are long, but the first and last characters combined with a middle spot-check catch nearly all substitution attempts. Attackers typically change characters in the middle of the address where humans skim.
Common Mistakes
- Trusting the address shown only in desktop software
- Scanning a QR code without device confirmation
- Reusing an address from a previous transaction without re-verifying
- Letting someone else read the address aloud while you type it
Practice During Your Session
At File Summit Core, we make clients perform this verification three times with testnet or small-value addresses before ending the session. The repetition builds muscle memory that survives the stress of a first real transfer.