Sanctuary Research

To check a TRON address for scam links, paste it into a screening tool that reads the address against sanctions designations, darknet and fraud clusters, and wallets already reported for scam and phishing — the verdict comes back in seconds and tells you whether anything is known against it. In Sanctuary's label set as of August 2026 that record carries phishing 16,591 and scam 6,759 labels, on top of 191,446 entity labels on TRON itself. Labels describe what somebody has already reported, so the other half of the answer is behaviour: what the address does, and how the person handing it to you behaves. Both halves fit inside a minute, and the first one is free — 3 free checks a day in the Sanctuary Telegram bot, no registration, a verdict in about 60 seconds.
It shows what the address is tied to and what has been reported against it. Not a name and a passport — what the wallet is: a deposit address at an exchange, an exchanger's settlement wallet, a payment processor, a gambling cashier, or an address that already sits in fraud reports. A block explorer shows you transfers. A lookup names the counterparty behind them, and that is the part a decision rests on.
Three things come back when you check a TRON address for scam history. What the address is attributed to, which is usually the sentence that ends the discussion — an address presented to you as "my personal wallet" that resolves to a known exchanger's hot wallet is a different conversation than the one you were having. What is reported against it: scam and phishing reports, darknet and ransomware exposure, sanctions designations. And the company the money keeps — where funds reaching that address came from, because that history travels with the coins into your balance and then into your exchange deposit.
The reason to run this rather than eyeball the explorer is that the explorer has no memory of what happened to other people. It will happily show you a wallet with hundreds of ordinary-looking transfers and never mention that some of the counterparties on the other side of them sit in fraud reports. Our record spans 10 chains at full AML depth and 20+ intelligence sources, so the same check answers the same question when the deal's other leg is BTC or ETH.
Rarely one sign on its own. Scam addresses are built to look ordinary, and most of them are ordinary right up until the moment they are not. What gives them away is a stack — two or three of these together is enough to stop a deal, and the list is roughly ordered by how often each one decides the case in P2P.
Checking a TRON address for scam exposure is one paste, and it costs nothing. @sanctuaryapp_bot returns a verdict in seconds: 3 free checks a day, no registration, buttons instead of commands — there is nothing to type and nothing to install. Behind the verdict sit the same classes of source an exchange's own screening reads: OFAC sanctions designations, darknet market clusters, ransomware lists, reported scam and phishing wallets, and exchange and deposit-address attribution, drawn from 20+ intelligence sources across 10 chains at full AML depth.
Desks that check every incoming order rather than one deal move to a paid plan, where the same screening runs in a web workspace with PDF reports you can attach to a support ticket, monitoring that tells you when something changes on a settlement address you already took money from, bulk checks, and an API for deposit flows — from $199 a month for 1,000 checks. Check an address free in the Telegram bot.
It settles the record. What the address is tied to, what has been reported against it, and whether the funds around it touch the kind of history that gets a deposit held on the other end. What it does not settle is the person: nothing on-chain proves that the account in the chat is the one holding the keys to the wallet it sent you. A check reports what is known at the moment you run it, which is the honest limit of any screening product, ours included.
| The question you actually have | What the check answers | What stays with you |
|---|---|---|
| Who am I paying? | What the address is attributed to — exchange deposit, exchanger, processor, gambling cashier, or a wallet carrying scam and phishing reports | Confirming that the person in the chat controls that address |
| Has anyone been burned here already? | Whether reported fraud, darknet, ransomware or sanctions exposure sits on the address or one hop away | Reporting it if you do get burned, so the next trader sees it |
| Will my exchange accept this coin later? | What the venue's own screening is likely to be looking at when it arrives | The venue's policy and thresholds, which are its decision and not ours |
| Is this address new? | How long it has been active and how it behaves | Deciding whether a fresh wallet is acceptable for the size of this deal |
For the mechanics of the token layer — contracts, transfers, what a TRC-20 result means field by field — how to check a USDT TRC-20 address is the longer version of this step.
A clean result is a fact about the address, not a character reference for the person. Every scam address is clean once: the label arrives after somebody loses money and reports it, which by definition is later than your deal. So a clean verdict is permission to continue carefully, not permission to stop reading.
Four habits do most of the work here. Stay inside the platform's escrow, because the whole point of the "let's do it directly, I release faster" line is to get you outside it. Keep the record while it exists — order ID, counterparty handle, timestamps, the chat, the payment screenshot — since that record is what gets a held deposit released weeks later. Split a large first deal with a new counterparty into two. And re-check before you release rather than relying on a result from last week: labels appear after arrests, seizures and new designations, so an old check answers an old question.
The transfer is final. TRC-20 has no reversal and no chargeback, and any service promising to pull the funds back for a fee is the second scam arriving to collect what the first one left. What is still worth doing, in this order:
Check the TRON address for scam exposure before you release funds, not after the transfer confirms. Open @sanctuaryapp_bot, paste the address, read the verdict: what the wallet is tied to, the labels on it, and its sanctions exposure — about 60 seconds, free, 3 checks a day, no registration. If a name comes back, you kept your money. If nothing comes back, you kept your minute.
An explorer shows you what moved and when. It does not tell you what the address is attributed to, and it does not carry the scam and phishing reports collected elsewhere. Use the explorer for the transfers and a screening check for the attribution: the free check in the Telegram bot returns both sides in about 60 seconds, drawn from 20+ intelligence sources.
It means nothing is known against that address at the moment you checked, which is a real fact and not a guarantee about the person. Every scam address is clean once, because the label arrives after somebody loses money and reports it. Stay inside the platform escrow, keep the order record, and re-check right before you release funds rather than relying on a result from last week.
Because a label is a record of something already reported, and fresh TRON addresses cost nothing to create — a scammer can use a new one for every victim. That is why the behaviour signs matter alongside the check: a late change of wallet, an address pasted into a chat, a lookalike copied out of your own transaction history. If you do get hit, report the address so the next trader sees it.
No. TRC-20 transfers are final and there is no chargeback, so any service offering to recover the funds for a fee is a second scam working the same victim. What is still worth doing: save the transaction hash and the chat, report the address to the platform and the police, and check the address that paid you if coins also came in — that is the one that shows up at your next exchange deposit.