How Do You Keep Your Crypto Wallet Safe and Compliant?

How to keep a business crypto wallet safe and compliant: avoid flagged funds, screen every address, and beat address poisoning and look-alike scams.

To keep a crypto wallet safe and compliant, transact only through licensed exchanges or trusted providers, screen every address before you send or receive, and avoid sanctioned, high-risk and politically exposed sources. Then verify every address and every payment yourself before you release goods. Most losses come from user error, not hacking.

This guide is based on Shield’s Digital Asset Security Guide. It is for operational purposes only and is not financial advice.

What types of wallets and accounts are there?

Not every way of holding crypto carries the same risk. The biggest difference is who controls the private keys, and whether anyone is screening the funds.

Type Who controls the keys Compliance and screening Main risk
Unverified broker (Telegram contacts, friends, informal brokers) The broker None. They cannot verify whether funds are safe Flagged funds and serious banking or business issues. Avoid.
Custodial wallet (centralized exchange, e.g. Coinbase or Binance) The provider Often built-in compliance and monitoring You rely on a third party to secure your assets
Self-hosted (un-hosted) wallet You, usually via a seed phrase Your responsibility You act as your own bank and bear full responsibility
Cold / physical wallet You, keys stored offline on a device Your responsibility A compromised phone or computer can still create risk

Trusted providers: Gemini, Kraken, Binance, Shield, Bitso, Coinbase, OKX. Use these instead of unverified brokers.

A cold wallet is one of the most secure options against online attacks. Store the device in a secure location, keep backups safe and separate, and use only trusted devices when you interact with it.

How does a crypto wallet get flagged? Keeping your crypto wallet safe and compliant

Almost every transaction on the blockchain is traceable. If your wallet interacts with high-risk or sanctioned wallets, it can become flagged, even if the funds passed through several steps before reaching you. It is guilt by association.

Diagram: a sanctioned wallet sends funds through an intermediary wallet to Wallet B, and both ends are flagged, leading to account restrictions, rejected transactions and banking issues

A flagged wallet can lead to:

  • Rejected transactions
  • Account restrictions
  • Banking issues

Enterprise blockchain analytics tools trace funds across multiple “hops.” If tainted funds move through several intermediary wallets before reaching yours, the exposure travels with them. The chain is only broken when funds pass through a verified, regulated entity, like a licensed centralized exchange that runs proper AML and onboarding procedures.

Risk also runs in both directions. Every wallet has sending and receiving exposure, and sending funds to a tainted address can contaminate your wallet just as receiving from one can. Screen addresses before you send. Do not skip this step.

Which sources of funds should you avoid?

The source of the funds matters as much as the person paying you. These are the main risk categories, and where to check them.

Risk What it means Where to check
High-risk jurisdictions Countries with loose AML rules. Funds from these regions can automatically flag your wallet FATF black and grey lists
Unregistered entities Businesses not registered to operate legally in the US FinCEN MSB registrant search and FinCEN’s public announcements
Politically exposed persons (PEPs) Royal family members, judges, government contractors and others with political ties. In some cases sports leagues and clubs too Your provider’s screening. Even clean funds carry PEP exposure
Sanctioned persons and entities May be legal at home but sanctioned internationally, whether licensed or not OFAC (US), UN Security Council, EU sanctions, OFSI (UK), DFAT (Australia), NBCTF (Israel)
Blacklisted addresses Specific addresses frozen by token issuers like Tether (USDT) or by exchanges at law enforcement request Your provider’s screening tools
Blacklisted entities Platforms named on regulator warning lists. If a platform is on one, do not accept its funds e.g. the FCA Warning List (UK)

Location risk goes further than where a company is licensed. Funds from an exchange in a sanctioned jurisdiction will most likely be flagged, even indirectly. A wallet with clean funds can still be flagged if its transactions are broadcast from a sanctioned jurisdiction, through its device and network (IP/ISP) or wallet DNS seed lookups.

Two examples show how this works:

  • Iran. Funds from an exchange in a sanctioned jurisdiction like Iran will be flagged. Nobitex, Iran’s largest digital asset exchange, was designated by OFAC on June 2, 2026 (US Treasury). If Nobitex funds go to a personal wallet in Germany and then on to a wallet in Australia, both of those wallets are flagged.
  • Russia. Wallets in Russia or Russian-occupied areas carry sanctions exposure. If funds pass through an OFAC-sanctioned paramilitary group in the Donbas, the wallet that receives them carries location risk.
World map of location risk: funds from Nobitex in Iran (OFAC) flag wallets in Germany and Australia, and a wallet in Russia linked to a sanctioned paramilitary group in the Donbas carries location risk

As a US FinCEN-registered MSB, Shield can’t serve fully embargoed jurisdictions like Iran, or the Russian-occupied regions of Crimea, Donetsk and Luhansk. For the rest of Russia, US sanctions target specific people and companies on OFAC’s SDN list and key sectors like banking, energy and defense, so any Russia-linked funds need extra screening. See OFAC’s Russia sanctions and Ukraine-/Russia-related sanctions pages.

What are the most common crypto wallet scams?

Attackers today rarely “hack” passwords. They manipulate your workflow so you send funds to the wrong address, or believe a payment went through and ship goods too early. They often combine these three attacks.

Attack How it works Countermeasure
Address poisoning (the “dust” attack) An attacker creates a look-alike “vanity address” and sends a tiny amount (e.g. 0.001 USDT) so it appears at the top of your recent transactions Never copy from history. Check the first 4, middle 4 and last 4 characters. Use whitelisted, clearly named addresses
Clipboard hijacking Malware watches your clipboard and swaps the address you copied for the attacker’s Keep devices updated. Compare the pasted address to the source. Clear your clipboard after every transaction
Homoglyph (look-alike) attack Non-Latin characters, like Cyrillic, that look identical to normal letters. A photoshopped or dynamic QR code can point to a different address than the one shown Verify new addresses on a block explorer like Tronscan. If it has no history or does not resolve, stop

Address poisoning. A real address might read TY9q…4hF…x1z while the attacker’s reads TY9q…999…x1z. The mistake is copying from your history and matching only the first and last few characters. Save trusted addresses with clear names (e.g. “Supplier A – Primary”) and only send to saved contacts.

The three-point check for address poisoning: verify the first 4, middle and last 4 characters of every address to keep your crypto wallet safe and compliant.

Clipboard hijacking. Do not trust that what you copied is what you pasted. After a transaction, copy a neutral piece of text, like “not today amigo,” to clear the memory. A password manager can also clear your clipboard automatically after a set time (for example ProtonPass, Bitwarden, Keeper, NordPass, Kaspersky, 1Password or KeePass).

Homoglyph attacks. The human eye cannot reliably detect these differences, so never rely on visual inspection alone. Use a dedicated burner or offline phone for scanning QR codes. If the address from a QR code does not match the text version you were sent, do not interact further.

Look-alike character attack: a real and a fake wallet address that differ only by a changed letter case, Cyrillic look-alike characters and an added space

These threats are not unique to crypto. Be careful with links, downloads and QR codes in any online context.

How do you verify a crypto payment before you ship?

A screenshot is not proof of payment. Screenshots can be easily faked with editing tools and AI, so check the balance in your actual account portal before you release anything.

Proof of payment: a client screenshot saying 2000 USDT is unreliable; verify the deposit in your own account portal before shipping

Watch for the decimal trap. An attacker sends 2.15510 USDT, which is worth about $2.15, and hopes you read it as 215,510. Never ship goods based on a displayed amount. Verify the USD value independently.

The decimal trap: an attacker sends 2.15510 USDT, the victim reads it as 215.510 USDT and ships goods, losing the shipment for $2.15
Proof Reliable?
Screenshot or “Payment Successful” message from the client No
Amount as displayed in a notification No, check the decimal point
Deposit showing in your own account portal or on the blockchain Yes

Trust the blockchain, not the screenshot.

What is the Shield Protocol?

At Shield, we manage risk while our partners manage custody. Shield is a FinCEN-registered money services business (MSB) and has processed over $600M. To keep your operation compliant and your funds clean, follow these golden rules:

  • Do not share your address with the public or unverified parties
  • Do not transact with suspicious entities without proper vetting
  • Do not release goods or services until payment is verified and received
  • Do not scan QR codes from unknown sources
  • Do not click suspicious links
  • Do contact Shield immediately about any concerns or suspicious activity

“User error is your biggest threat. Always check and verify.” That is the advice of Nathan Gaidai, author of the guide, a Certified Cyber Crime Investigator (National White Collar Crime Center), Certified Financial Crime Specialist and Digital Assets Compliance Specialist (Association of Certified Financial Crime Specialists).

Related reading on the Shield blog: How to Keep Your Bank Account While Accepting USDT, How US Wholesalers Accept USDT Payments Legally and The Real Risks of Crypto Payments for Businesses.

Further reading

Address poisoning
– MetaMask Support: How to avoid address poisoning
– Ledger Academy: What are address poisoning attacks in crypto and how to avoid them?

Clipboard hijacking
– Bitdefender: Hackers are infecting crypto enthusiasts with clipper malware, warns Binance

Homoglyph attacks
– IronGeek: Homoglyph and IDN homograph attacks

Official fraud advisories
– FBI: On the internet, be cautious when connected
– Internet Crime Complaint Center (IC3): Cryptocurrency
– Ledger: The state of crypto scams
– Nasdaq: FBI warns Americans against using non-KYC crypto money transmitting services

Self-custody best practices
– How to keep your wallet backup (recovery seed) safe
– Setting up the Trezor Keep Metal 20-word: a step-by-step guide
– Ledger Academy: Addressing self-custody’s greatest misconceptions
– Crypto wallets: hot wallet vs cold wallet vs exchanges (explained)

For more information and support, visit getshield.xyz or contact our security team.

This article is for operational and informational purposes only and does not constitute financial advice. It does not endorse or mandate the use of any specific provider. Shield is not a bank.

Open your US account in minutes

Join the wholesalers and exporters getting paid in USD from buyers anywhere.

Read more from Shield