Sanctuary Research

What to check before a P2P crypto deal, in this order: the counterparty's wallet address, the token you are actually being sent, the venue's escrow rules, the payment leg, the counterparty's profile, and the record you keep afterwards. The order is not decorative: the address check costs a minute and can end the deal before you commit anything; the payment leg can undo itself weeks later. Start at the top: run the address through the Sanctuary bot — 3 free checks a day, about 60 seconds, no signup.
Do this first: it is the only step that ends a deal for free.
Copy the address from the platform's order page, never from the chat or your own transaction history — that is where substituted and lookalike addresses come from. Paste it into the Sanctuary Telegram bot. About 60 seconds later you have a risk level, a named entity if the address has one, and the risk categories behind it. Three decisions follow.
Watch for the contradiction: "my personal wallet" that comes back as an exchanger's settlement wallet is not the deal you agreed to. The verdict arrives as a level — clean, low, medium, high, critical — see what a crypto risk score means. If the other leg is Bitcoin, how to check a Bitcoin address for AML risk is the same step with BTC specifics.
Your wallet shows a name and a logo. Neither is the asset. Anybody can deploy a token contract, call it USDT, copy the icon and send you five figures of it: the balance renders correctly, the screenshot looks right, the thing is worthless.
Our label set carries token_contract 19,356 labels as of August 2026 — a lookalike token is a different contract, and the check names which one you were sent. The defence is mechanical: compare the contract address of what arrived against the official contract for that asset on that chain. The symbol beside the balance is decoration; the contract is the asset.
Three confirmations before you count a token payment as received:
How to check a USDT TRC-20 address walks that layer field by field.
Escrow is the only thing between you and a stranger with a good story: the platform holds the seller's crypto from the moment the order opens until the seller releases it — and only for orders opened on the platform, so a chat deal has no escrow at all. Everything a fraudster does aims to get you outside it.
Steps 1 and 2 — the on-chain half of what to check before a P2P crypto deal — are the same 60 seconds in the Sanctuary Telegram bot. Paste the counterparty's address and read back the risk level, the named entity when attribution exists, and the risk categories behind the verdict. 3 free checks a day, no registration, buttons instead of commands.
Behind that verdict sit sanctions designations, darknet and ransomware clusters, reported scam and phishing wallets, exchange and deposit-address attribution and token contract labels, across 10 chains at full AML depth — the same screening the exchange will run on your deposit next week. Running it first is the difference between making a decision and receiving one.
Traders who screen every incoming order move to a paid plan: the same data in a web workspace, PDF reports, monitoring, bulk checks and an API. Check an address free in the Telegram bot.
The checks before releasing crypto p2p come down to one question on the fiat side: can this payment be taken back?
Reversibility. A crypto transfer is final the second it confirms. A card payment is not, and neither are some bank transfers. The trap runs in slow motion. The buyer pays by card. You watch the money land in your account. You release the USDT. Three weeks later the buyer tells their bank the card was used without permission, the bank takes the money back out of your account — that is a chargeback — and the coin is long gone. You are down both legs, arguing with a bank that never heard of your P2P order. That asymmetry is the business model: the leg they control can be undone, the leg you control cannot. What a bank can claw back, and for how long, differs by country.
Name mismatch. The name on the incoming payment has to match the name on the P2P account you are trading with. Not close enough, not "that's my wife's card", not a company account for a personal profile.
Third-party payments. Money from someone who is not your counterparty is the mule pattern in its plainest form: they hand a victim your bank details, the victim pays you, and your account is the one named in the fraud report. Refuse it, do not release, appeal with the mismatch as evidence.
Account age, completed trades, completion rate, the verified badge, the wall of feedback. Read all of it, then be clear about what it is: social proof about an account, not evidence about money.
The address history is evidence about the money in front of you, and when the two disagree the evidence wins. Accounts are bought, rented and shared: a long trade record says the account has behaved, not where this settlement wallet took funds from last week.
What the profile is good for is the part no screen shows — whether the chat terms match the order, whether the story changes mid-deal, whether you are being hurried. Hurry is the tell that survives every platform redesign.
The deal ends; the exposure does not. Before you close the tab, save five things: the order ID, the in-app chat, the transaction hash, the receipt with the sender's name on it, and the result of the check from step 1 with its timestamp. Two minutes, once.
Money gets questioned months later: an exchange holds your deposit for review, a bank asks about an incoming transfer, a counterparty's wallet gets labelled after an arrest. What works then is a dated record made before anything went wrong. "It looked fine at the time" is not an answer. "Here is the check I ran that morning, here is the order, here is the hash" is one.
Re-check the same counterparty next time: a regular partner is not a cleared partner. Labels arrive after the fact, and a wallet quiet in March reads differently in September. Most p2p trade safety steps take about a minute; this one pays out months later.
What to check before a P2P crypto deal, with the signal that ends each step:
| Step | What you check | Deal-breaker signal |
|---|---|---|
| 1. Wallet address | Risk level, named entity, risk categories | Sanctions, darknet, ransomware or reported scam on it or one hop away |
| 2. Token | The contract address of what arrived, not the ticker | The contract is not the official one for that asset |
| 3. Venue | Escrow terms, who releases, appeal window, evidence rules | Any push to leave the platform or release early |
| 4. Payment | Reversibility, payer name, is the sender your counterparty | Third-party payer, name mismatch, reversible method |
| 5. Profile | Account age, trade history, does the story stay consistent | Changed terms, changed wallet, pressure to hurry |
| 6. Record | Order ID, chat, hash, receipt, timestamped check | Nothing to show if the money is questioned later |
Run it in sequence. The p2p counterparty verification order matters because each step costs more to undo than the one before: the check costs a minute, an escrow mistake costs an appeal, a chargeback costs both legs.
Open @sanctuaryapp_bot, press the check button, paste the counterparty's address. In about 60 seconds you have the risk level, the named entity if there is one, and the categories behind it — before the order opens, while the decision is still yours. Three free checks a day, no registration. Run the rest of the list while it answers. That is what to check before a P2P crypto deal, and step one costs you nothing.
No. Release only when the money has settled in your account under your counterparty's own name, and never on a screenshot, a pending notification or a promise. A crypto transfer cannot be undone; a card payment or a bank transfer can be pulled back weeks later. Releasing early hands the one irreversible leg of the trade to the person who still controls the reversible one.
Copy the address from the platform's order page, never from the chat or your own transaction history, and paste it into the Sanctuary Telegram bot. In about 60 seconds you get a risk level, a named entity if the address is attributed to one, and the risk categories behind the verdict. Three free checks a day, no registration. Sanctions, darknet or reported scam links end the deal.
Yes, and that is the most common P2P loss. The buyer pays by card, you release the coin, then weeks later they tell their bank the payment was unauthorised and the bank takes it back out of your account. The crypto side has no equivalent. Prefer settled payments in the counterparty's own name, refuse third-party senders, and keep the order record for the dispute.
Yes. Trade counts and badges are social proof about an account; the address history is evidence about the money you are being handed today. Accounts get bought, rented and shared, and a long record says nothing about where this settlement wallet took funds from last week. The check costs a minute, so run it on regulars too, since labels arrive after the fact.