4 Hidden USDT Wallet Risks Your Balance Won't Show

4 Hidden USDT Wallet Risks Your Balance Won't Show

中文版 →


I keep a fair number of wallets on TRON and Ethereum, and for a long time my “security check” was glancing at the balance. Number still there? Fine.

It took me a while to learn that the things which actually cost money mostly don’t show up in the balance. The number looks healthy while the money is already stuck, or already reachable by someone else. These are the four I care about most, each with a free way to check it yourself.

To be clear up front: this is not investment advice. It’s my own checklist.

1. Tether has frozen your address

What it is: USDT on TRON and USDT on Ethereum are both contracts run by Tether, and each contract keeps a blacklist. Once an address is on it, the USDT in that address can’t be sent anywhere.

Why it’s sneaky: The wallet looks normal and the balance still shows. People can even keep sending USDT in; it just can’t get back out. The freeze is per token, so TRX or ETH in the same address still moves, which makes it easy to assume nothing is wrong.

How to check it yourself:

  • TRON: On Tronscan, open the official USDT contract TR7NHqjeKQxGTCi8q8ZY4pL8otSzgjLj6t, go to Contract → Read Contract, find isBlackListed, paste your address and query.
  • Ethereum: On Etherscan, open the USDT contract 0xdAC17F958D2ee523a2206206994597C13D831ec7 and use isBlackListed (or getBlackListStatus) under Read Contract.
  • false means clear; true means frozen.

What to do: Only Tether can lift a freeze; your private key can’t help. If it’s your address, stop sending USDT to it and go through Tether’s official channels. The more useful habit is checking the other side before you pay: USDT sent to a frozen address is stuck there too.

2. Someone else can sign for your wallet

What it is: A TRON account doesn’t have to be controlled by one key. Its account permissions (multi-signature) can list other addresses as Owner or Active signers. On Ethereum, EIP-7702 (live since 2025) lets an ordinary wallet delegate its “code” to a contract, and some wallets are contract accounts outright, where the contract decides who can move funds.

Why it’s sneaky: When an extra key is added, your wallet keeps working exactly as before, so you don’t notice. It just works for them too. A common cause is signing a harmless-looking transaction on a phishing site.

How to check it yourself:

  • TRON: Open your address on Tronscan and look at the account’s permissions. Owner and Active should list only your own address. An unfamiliar address there, or your address missing, means it has been changed.
  • Ethereum: Open your address on Etherscan. A normal wallet has no code. If the page shows it is delegated to a contract, or the address is itself a contract, make sure that’s something you set up.

What to do: If it’s your own multisig or smart wallet, fine. If it isn’t, treat that wallet as compromised and stop funding it. On TRON you can remove an unknown signer if you still hold enough permission, but the safer move is to move what’s left to a fresh wallet.

3. An unlimited approval you forgot about

What it is: When you swap on a DEX or join some on-chain event, the site usually asks you to “approve” its contract to spend one of your tokens. Most approvals are unlimited by default, and they never expire.

Why it’s sneaky: After that one approval, the contract can take that token from your wallet without asking you again. If the contract is later hacked, or was malicious from the start, it can take the whole balance, and again the next time you top the wallet up.

How to check it yourself:

  • Ethereum: Etherscan’s Token Approval Checker lists every approval for an address and how much is exposed.
  • TRON: Open your address on Tronscan and go to the Approval tab.

What to do: Revoke anything you don’t recognise, don’t use any more, or that says Unlimited. Revoking is a transaction signed from the wallet that holds your keys; it costs a small fee and moves no funds. Next time, approve only the amount you actually need, when the site lets you.

4. Address poisoning: the look-alike address

What it is: A scammer generates an address whose first and last few characters match one you pay often, then sends you a tiny or zero-value transfer so it lands in your history. Next time you copy an address from that history and only check the ends, you paste theirs.

This isn’t hypothetical: In May 2024 someone sent 1,155 WBTC, about $68 million at the time, to a poisoned look-alike address (CoinDesk). A hardware wallet can’t stop it: the transfer is perfectly valid. Only the destination is wrong.

I wrote about these tiny unexpected transfers before (in Chinese): 為什麼轉帳後會有少量的免費USDT轉入到你的錢包? (“Why do small amounts of free USDT show up in your wallet after a transfer?”).

How to check it yourself: Scroll your incoming transfers on Tronscan or Etherscan. Look hard at tiny, zero-value, or unfamiliar ones, and compare each against the addresses you really pay, every character, not just the ends.

What to do: Always copy a payee address from your own saved address book or straight from the person, never from your transaction history. Before a large transfer, send a small test first.

App or no app, these four checks are worth running every so often. If you’d rather not check all four by hand, MuWatch (my app, for Mac) checks them for you: media-mu.com/muwatch.html.

GFL