Crypto Donation Scams and How to Spot Them

Sep 23, 2026 · 7 min read · The TraceGood Team

Crypto donations are irreversible. That's a feature when you want a permanent, public record of where money went — and a liability when someone has tricked you into sending to the wrong place. There's no chargeback, no fraud department, no reversal.

The good news is that crypto donation scams are not clever. They recycle the same handful of tricks, and every one of them can be defeated by checks that take about two minutes. This article covers what the tricks look like and exactly what to do about them.

The scams you'll actually encounter

Lookalike domains

The most common attack is also the dullest: register a domain one character away from a real charity's, clone the site, swap the wallet address. tracegoods.org, trace-good.org, tracegood.co, tracegood.org.donate-now.net — all are trivially registrable, and at a glance in a browser tab they read identically to the real thing.

These domains are usually seeded through search ads, comment replies, QR codes on printed material, or a link in a message that arrives at exactly the moment you were already thinking about donating.

"Send 1 ETH, get 2 back" and matching scams

If a post promises that a donation will be doubled, matched by an anonymous whale, or returned multiplied — it is a scam, without exception. There is no version of this that is real. The format survives because it works on urgency and greed at the same time, and because scammers seed fake "it worked, thank you!" replies underneath.

A related variant targets generosity rather than greed: "an anonymous donor will match every gift in the next hour." Real matching campaigns exist, but they are run by the charity on its own site, announced in advance, and never require you to send funds to a third-party address.

Address-swap malware and clipboard hijacking

This one is quieter and far nastier. Clipboard-hijacking malware sits on your machine, watches for anything that looks like a crypto address being copied, and silently replaces it with the attacker's address at the moment you paste. You copy the right address. You paste a different one. Everything on screen looks normal.

Some variants are network-level rather than device-level, altering an address displayed on a page you're viewing. Either way, the defence is the same and it's below.

Disaster-exploiting appeals

Within hours of an earthquake, flood or conflict escalation, fake relief appeals appear. They use real photographs, real place names, and real urgency. They work because the emotional pressure is genuine even when the organisation isn't.

Legitimate emergency response does exist in crypto — settlement in minutes genuinely matters when aid is time-critical — but that's a reason to donate carefully to a known organisation, not a reason to trust a new address that appeared yesterday.

Unsolicited messages

No real charity will DM you on Telegram, Discord, X or WhatsApp with a wallet address. None. If someone reaches out to you unprompted with an address, the interaction is fraudulent regardless of how professional it looks or whose logo is in the profile picture.

Be especially wary of replies to your own public posts about donating — announcing that you're about to give crypto puts a target on you.

Fake QR codes

A QR code is unreadable to a human, which makes it a perfect place to hide an address swap. Stickers placed over legitimate printed codes, altered images in forwarded flyers, and codes in social posts are all common. Scanning a code should always lead to a page you can then verify by reading the URL — if scanning immediately opens your wallet with an address pre-filled and no verifiable page in between, stop.

"Verify your wallet" phishing

A message or page asks you to connect your wallet, sign a transaction, or enter your seed phrase to "verify eligibility", "confirm your donation" or "claim a receipt".

No donation ever requires your seed phrase, your private key, or a wallet signature. A donation is an outgoing transfer, nothing more. Anyone asking you to sign or verify something is trying to drain your wallet, not accept your gift.

Six checks that defeat all of it

These are in rough order of how much protection they buy you per second spent.

  1. Type the domain yourself. Don't click links from messages, ads, comments or emails. Type the charity's address into the address bar, or use a bookmark you made from a session you trust. This single habit neutralises lookalike domains, most QR code attacks and nearly all phishing.
  2. Confirm the payment page belongs to the charity's real checkout. Look at who is processing the payment and whether that's consistent with what the organisation publishes about itself. Our donations run through a NOWPayments hosted checkout — if you ever reach a TraceGood donation flow that doesn't hand off to NOWPayments, close the tab.
  3. Verify the first and last characters of the address. After you paste, compare the first four and last four characters against what's on screen, in the wallet, before confirming. This is the specific defence against clipboard hijacking, and it takes three seconds.
  4. Send a small test amount. On a low-fee network this costs cents. Send it, confirm it arrives and appears where it should, then send the rest. For any gift large enough that losing it would hurt, this is simply worth doing.
  5. Look for a public ledger. An organisation that publishes its incoming donations on-chain has handed you a verification tool it can't switch off. You can check the transactions yourself rather than taking anyone's word — here's how to verify a donation on the blockchain, and our own ledger is at /transparency.
  6. Check for a real legal entity. Somewhere on the site there should be a stated legal name, a registration status, a physical location and a way to contact a human. Vagueness here is the single most reliable warning sign in charitable giving, crypto or otherwise.

Apply these to us, too

It would be easy to end this article implying TraceGood is the safe exception. We'd rather be straight with you.

TraceGood is newly founded and our formal registration is still being finalised. That means we don't yet have the years of filings and third-party evaluations that an established charity can point to. You should weigh that, and you should run every check in this article on us exactly as you would on anyone else.

What we can offer in the meantime is verifiability rather than reputation. Every confirmed donation appears on our public transparency ledger with a link to the blockchain transaction, so you can audit the inbound side yourself without trusting a word we say about it. Our programs — food, shelter, medical care, children's education and emergency relief — are described on the site, and our FAQ answers the specifics.

Anyone claiming a charity is beyond scrutiny is telling you something useful about themselves. Scrutiny is the point.

If you've already sent to a scammer

Be honest with yourself quickly: the funds are almost certainly gone, and anyone who contacts you offering to recover them is running the second half of the same scam. Recovery services in crypto are, with vanishingly few exceptions, fraudulent. What's worth doing is reporting the address and domain to the platform where you found it and to your national fraud reporting body, and scanning your machine for malware if an address was altered.

The bottom line

Type the domain. Check the address ends. Test with a small amount. Look for a ledger and a legal entity. Ignore anyone who messages you first, promises to multiply your gift, or asks you to verify a wallet.

Those habits make crypto one of the safer ways to give — and they're worth keeping whether or not you ever donate to us. If you'd like the broader version of this argument, see is it safe to donate cryptocurrency?, and when you're ready, our donate page is one you should reach by typing the address yourself.

Turn crypto into care

Every gift is an on-chain transaction you can trace from your wallet to the field.

Donate in crypto

All articles