Recently, there have been frequent incidents of user deposit/withdrawal address tampering. This may occur due to users' computers being infected with Trojan viruses by malicious individuals, or usersRecently, there have been frequent incidents of user deposit/withdrawal address tampering. This may occur due to users' computers being infected with Trojan viruses by malicious individuals, or users
新手学院/Cryptocurrency Knowledge/Security Knowledge/How to Safe...s Tampering

How to Safeguard Your Deposits and Withdrawals from Address Tampering

Jul 16, 2025MEXC
0m
4
4$0.011563-3.35%
Checkmate
CHECK$0.01385+5.09%

Recently, there have been frequent incidents of user deposit/withdrawal address tampering. This may occur due to users' computers being infected with Trojan viruses by malicious individuals, or users downloading and using browsers that have been maliciously modified, as well as installing malicious browser plugins. Another potential reason is users downloading MEXC software and third-party chat software from non-official channels. To assist users in preventing these risks, we have compiled some practical tips for checking and prevention. We strongly advise users to remain vigilant, enhance security precautions, and ensure the safety of their deposit/withdrawal operations.

1. Case 1: Is it safe to copy and paste? Beware of Trojan viruses altering your clipboard.


User A received a transfer address from User B via Telegram. However, when User A copied and pasted the address onto the withdrawal page, they discovered that it did not match the address User B had sent them.



1.1 Analysis:


The inconsistent copied and pasted address suggests that the operating system clipboard has been hijacked and tampered with, indicating a possible infection of the system with a Trojan virus.

1.2 How to Check:


In your operating system, copy the test address, then paste it into Notepad or other software. Compare the copied address with the target address. If they do not match, it indicates that your clipboard has been globally hijacked.

1.3 What to Do:


1.3.1 If you find that copying and pasting addresses on your device is consistently being hijacked, there is a high probability that your device has virus software installed. You need to promptly install antivirus software and scan for viruses. Additionally, you should update your system and install system security updates in a timely manner.

1.3.2 If the above steps do not resolve your issue, you may need to perform a system reinstall. Please note that reinstalling the system will result in the loss of all your data. Kindly proceed with caution. We recommend visiting an official offline service center for system reinstallation.

1.4 How to Prevent:


Regularly update your device's operating system (iOS / Android / Windows / macOS), promptly install system security patches, keep your browser version up to date, install antivirus software, and regularly scan for viruses.

2. Case 2: Is it safe to enter the address manually? Browser hijacking is hard to detect and prevent.


User A manually entered the transfer address on the withdrawal page, then clicked to submit. However, on the secondary confirmation page that appeared, they noticed that the address was different from the one they had just entered.


2.1 Analysis:


The address on the secondary confirmation page is not the one you entered because the browser page has been hijacked. Malicious browser software or browser plugins have been monitoring your input content and secretly replacing it.

2.2 How to Check:


When withdrawing from the MEXC platform on your browser, a secondary address confirmation is always performed. Please carefully verify if the confirmed address matches the intended address. If they do not match, it indicates that your browser interface has been hijacked. You can also test this by using a search engine. Enter the test withdrawal address into the search engine and click to search. Check if the address displayed on the search results page matches the test withdrawal address. If they do not match, your browser interface has been hijacked.

2.3 What to Do:


If you suspect that the hijacking issue exists only within the browser, there is a high probability that your browser has malicious plugins installed, or you have downloaded a non-official browser. If you downloaded the browser from an official channel, uninstall any suspicious plugins. If you are uncertain about the safety of any plugins, uninstall all of them. If you did not download the browser from an official channel, uninstall the browser and download it from an official source.

2.4 How to Prevent:


When using different browsers, exercise caution when installing third-party plugins, and avoid installing unreliable plugins from non-official sources.

3. Case 3: Your everyday chat app may be secretly altering your information


User A, using version XX of Telegram, received a message from User B. User B requested a deposit of USDT from User A and provided a deposit address. User A proceeded to make the deposit to the provided address, but User B did not receive the transfer after a long wait. Upon comparing the addresses, they discovered that the address sent by User B did not match the one received by User A.


3.1 Analysis:


The received address does not match the one sent address because a pirated version of Telegram was monitoring the information and altering it.

3.2 How to Check:


In the chat app, send an address to a friend and compare it with the address received on their device. If they do not match, it indicates that the conversation has been hijacked.

3.3 What to Do:


If you suspect that a third-party chat application has been hijacked, please uninstall the software and download the application from the official Telegram website.


3.4 How to Prevent:


Use third-party chat tools downloaded from official channelsand avoid downloading cracked versions, specific language versions, etc., from third-party platforms.

4. Case 4: Security is guaranteed only when you download from official channels.


User A downloaded the MEXC App via a cloud drive or other means, signed up for an account, and generated a deposit address, intending to make a USDT deposit. However, after making the deposit, they noticed that the funds had not arrived. Upon contacting official customer service to verify the situation, User A discovered that the address in their screenshot did not match the address generated by the platform for User A.


4.1 Analysis:


The address page on the official MEXC App clearly displays "Deposit Address Security Verification" and shows the contract address.

4.2 How to Check:


Check whether the installed MEXC App was downloaded from the official MEXC website (https://www.mexc.com/download), Google Play (https://play.google.com/store/apps/details?id=com.mexcpro.client), or Apple Store (https://apps.apple.com/app/mexc-buy-sell-bitcoin/id1605393003).

4.3 What to Do:


If it is determined that the installed MEXC software was downloaded from a non-official source, please uninstall the software and visit the official MEXC website (https://www.mexc.com/download) to download the latest version of the app.


4.4 How to Prevent:


Download the latest version of the app from the official MEXC website (https://www.mexc.com/download).

5. Conclusion


With the widespread adoption of cryptocurrencies, nefarious individuals are constantly devising new methods of stealing funds, resulting in frequent incidents of theft. Therefore, implementing meticulous security measures to protect account safety has become particularly urgent. This article discusses four case studies and their preventative methods, but it is important to note that preventive measures extend beyond these examples. Users can adopt various precautions based on their individual circumstances and requirements. As the cryptocurrency market continues to evolve, continuously enhancing security measures is crucial to staying ahead of malicious actors.

市场机遇
4 图标
4实时价格 (4)
$0.011563
$0.011563$0.011563
-6.71%
USD
4 (4) 实时价格图表

热门加密动态

查看更多
CoreWeave股价多空激辩:1040亿美元在手订单遭遇390亿美元资本开支大考

CoreWeave股价多空激辩:1040亿美元在手订单遭遇390亿美元资本开支大考

概述 作为全球领先的专用人工智能云基础设施服务商,CoreWeave(CRWV)在公开市场引发了机构投资者的激烈多空博弈。根据公司最新披露的运营与财务规划,CoreWeave 累积的未履行商业合同总额(Backlog)已达到惊人的 1,040 亿美元,显示出前沿大模型研发机构与超大规模云服务商对高性能图形处理器(GPU)算力资源的极端渴望。然而,支撑这笔天量订单落地的前提,是公司必须在未来数个财年

Nebius股价为何逆势下挫:50亿美元可转债扩容与AI数据中心扩张背后的股权稀释隐忧

Nebius股价为何逆势下挫:50亿美元可转债扩容与AI数据中心扩张背后的股权稀释隐忧

概述 新兴人工智能云基础设施服务商 Nebius(纳斯达克代码:NBIS)近期在二级市场出现显著下挫,引发了全球科技与资本市场对其高负债扩张模式的广泛讨论。根据公司向监管机构递交的文件,Nebius 决定将其可转换优先票据的发行规模从原计划的 45 亿美元大幅上调至 50 亿美元,如果承销商全额行使超额配售权,整体融资规模最高将达到 57.5 亿美元。所得资金将全额用于采购英伟达等顶级图形处理器(

迈威尔科技(MRVL)股价为何在与谷歌达成 AI 芯片合作后大涨?

迈威尔科技(MRVL)股价为何在与谷歌达成 AI 芯片合作后大涨?

概述 迈威尔科技(Marvell Technology)在 8 月 19 日单日上涨 9.85%,收于 237.27 美元,盘中一度触及 245.49 美元,成交量放大至约 3456 万股。推动这轮跳涨的并不是财报,而是一份提交给美国证券交易委员会的 8-K 文件。文件披露,迈威尔科技已与谷歌就定制半导体产品签署商业协议,并向后者发行了一份最多可购买 58,970,907 股普通股的认股权证。 市

阿里巴巴股价为何财报后重挫:AI云业务暴增45%难掩净利润暴跌75%的资本阵痛

阿里巴巴股价为何财报后重挫:AI云业务暴增45%难掩净利润暴跌75%的资本阵痛

概述 阿里巴巴集团 港股代码 9988 今日盘中一度下跌约 3%,引发全球资本市场对其 AI 转型代价的高度关注。根据公司披露的最新季度财务数据,该季度总营收录得 2,689.53 亿元人民币,同比增长 9%,略超市场预期的 2,688.8 亿元人民币。以 阿里云 为核心的 AI 与计算基础设施板块表现强劲,收入同比增长 45% 至 484.37 亿元人民币,其中 AI 相关产品收入达到 123.

热门新闻

查看更多
特斯拉2026年第一季度财报回顾:交付量反弹,但利润率质量仍是真正的考验

特斯拉2026年第一季度财报回顾:交付量反弹,但利润率质量仍是真正的考验

特斯拉于2026年4月22日美国股市收盘后公布了其2026年第一季度的财务业绩。该公司本季度交付了358,023辆汽车,创造了224亿美元的总营收,并报告归属于普通股股东的GAAP净利润为4.77亿美元。总GAAP毛利率提升至21.1%,而营业利润率达到4.2%。 核心信号不仅在于特斯拉的交付量从去年同期的疲软基数中恢复。更重要的问题是:更高的交付量、FSD相关营收、更低的单车成本以及改善的汽车毛

苹果 2026 财年第二季度财报回顾:iPhone 营收与服务业务增长维持 EPS 预期

苹果 2026 财年第二季度财报回顾:iPhone 营收与服务业务增长维持 EPS 预期

苹果于 2026 年 4 月 30 日发布了 2026 财年第二季度财报,涵盖截至 2026 年 3 月 28 日的季度。总营收达到 1112 亿美元,同比增长 17%,摊薄后每股收益(EPS)增长 22% 至 2.01 美元。苹果表示,该季度创下了公司 3 月份季度的总营收、iPhone 营收和 EPS 纪录,同时服务业务营收也创下历史新高。 这不仅仅是一份常规的硬件周期财报。苹果第二季度的业绩

Hyperliquid 未平仓合约达 115 亿美元:链上永续合约是否正扩展至美国股市?

Hyperliquid 未平仓合约达 115 亿美元:链上永续合约是否正扩展至美国股市?

Hyperliquid的未平仓合约量已达到约115亿美元,创下2026年新高,其中HIP-3市场贡献了近40亿美元。与标普500指数挂钩的合约已成为最大的HIP-3市场,而追踪SK海力士和美光科技的合约则反映了对人工智能和半导体相关敞口需求的不断增长。

Coldcard Mk3 警告紧随 3800 万美元 Bitcoin 被扫荡事件,但原因仍未确认

Coldcard Mk3 警告紧随 3800 万美元 Bitcoin 被扫荡事件,但原因仍未确认

比特币硬件钱包制造商Coinkite已警告用户,Coldcard设备存在种子生成问题,影响从4.0.1版本起的所有Mk3固件版本。该警告是在安全研究人员调查一起涉及594.48 BTC(约合3,800万美元)的协同转移事件时发出的。然而,目前尚无公开的技术证据证实Coldcard的问题导致了这些转账。

相关文章

查看更多
MEXC 可用和受限国家/地区说明

MEXC 可用和受限国家/地区说明

MEXC 致力于为用户打造一个便捷高效安全的交易平台,助力全球加密爱好者探索加密世界。同时 MEXC 坚持最高标准的监管合规性,以负责任的态度履行对用户的承诺,积极为区块链行业的可持续发展贡献力量。您可以通过我们的用户协议,阅读查看当前受限的国家/地区,确认自己所处区域是否支持使用 MEXC 服务。1. 禁止使用的国家/地区名单目前,MEXC 不向以下国家/地区提供服务,也不接受用户注册或交易申请

如何识别短信钓鱼

如何识别短信钓鱼

短信钓鱼是一种利用短信(SMS)作为媒介进行的欺诈行为,旨在窃取用户的敏感信息(如钱包私钥、登录凭据)或骗取加密货币资产。这种钓鱼行为通常通过伪装成可信赖的实体(如交易所、钱包服务商或政府机构)来诱骗受害者。1. 常见的短信钓鱼类型1.1 伪装成交易所的钓鱼链接骗子发送一条短信,声称来自知名交易所(如 MEXC 等),并附上一个链接。短信内容可能会警告用户账户有异常活动,需要立即登录。点击链接后,

貔貅币防范指南

貔貅币防范指南

加密货币交易新兴项目和币种层出不穷,由于潜在的高收益特点,对投资者来说同时隐藏着巨大风险。“貔貅币”这一说法,主要是投资者用来调侃那些只进不出、无法提现或流动性极差的加密货币的形象化称呼。在这个快速变化的市场中,了解“貔貅币”的特征和风险,成为每个投资者的必修课。1. 什么是貔貅币貔貅币(Honeypot Token)通常被用来形容那些具有“只进不出”特性的加密货币或项目。它通常有以下几类情况:无

什么是网络钓鱼攻击?

什么是网络钓鱼攻击?

在加密货币交易市场中,网络钓鱼攻击是一种常见的欺诈手段,攻击者通过伪装成合法的加密货币平台或客服提供虚假务,诱骗用户提供敏感信息,如登录凭据、私钥或财务信息。1. 网络钓鱼攻击类型伪造网站:创建与合法交易所或钱包极为相似的网站,诱导用户输入信息。虚假电子邮件:发送看似来自官方机构的邮件,要求用户点击链接并输入个人数据。社交媒体骗局:在社交平台上冒充可信的交易平台或个人,诱骗用户泄露信息。2. 网络

注册MEXC账号
注册 & 获得高达10,000 USDT奖金
您的稳定币真的安全吗?
您的稳定币真的安全吗?您的稳定币真的安全吗?
了解 USDT、USDC、OpenUSD 及 USD1 的风险