DEV Community

Huzaifa Zahoor
Huzaifa Zahoor

Posted on

Before You Paste That Wallet Address: Sanity-Checking Crypto Addresses in Python

Every crypto transfer ends with the same scary moment: you paste a long string into a "recipient" box and press send. There's no chargeback and no support line that can reverse it. If the string is wrong, or right but on the wrong network, the money is usually gone.

As developers we can make that moment a lot less scary. This post walks through what a wallet address actually is and a few cheap checks you can run in code before trusting one.

What an address really is

A wallet address is a public identifier that can receive coins. It sits at the end of a one-way chain:

  • Private key: a secret number that signs transactions. Whoever holds it controls the funds.
  • Public key: derived from the private key, used by the network to verify signatures.
  • Address: a shorter encoding, usually a hash of the public key, built for sharing.

Because every step only works in one direction, sharing an address is safe. Sharing the private key or the seed phrase behind it is not. If you want the beginner-friendly version of all this, NutshellCrypto has a clear explainer on what a crypto wallet address is and how to use one safely.

Formats give you free validation

Different chains use different encodings, and most of them carry a checksum. That means a single typo is usually detectable before anything touches the network.

Chain Looks like Built-in check
Bitcoin SegWit / Taproot bc1q... / bc1p... Bech32 / Bech32m checksum
Bitcoin legacy 1... / 3... Base58Check
Ethereum and EVM chains 0x + 40 hex chars EIP-55 mixed-case checksum
Solana 32-44 base58 chars Must decode to 32 bytes

A quick EIP-55 check

Ethereum addresses encode a checksum in the capitalization of their letters. Here's a minimal validator using pycryptodome for Keccak-256:

from Crypto.Hash import keccak

def is_valid_eip55(addr: str) -> bool:
    if not (addr.startswith("0x") and len(addr) == 42):
        return False
    body = addr[2:]
    try:
        int(body, 16)
    except ValueError:
        return False
    if body.islower() or body.isupper():
        return True  # no checksum present, format only
    h = keccak.new(digest_bits=256, data=body.lower().encode()).hexdigest()
    for ch, nibble in zip(body, h):
        if ch.isalpha() and (int(nibble, 16) >= 8) != ch.isupper():
            return False
    return True
Enter fullscreen mode Exit fullscreen mode

An all-lowercase address passes the format check but carries no checksum, so treat it as "weaker" and confirm it another way. For Bitcoin, use a maintained library (for example the reference segwit_addr.py from BIP 173/350) rather than rolling your own bech32 decoder.

The check code can't do: the network

Here's the trap that a checksum won't catch. The same 0x... address is valid on Ethereum, Arbitrum, Base, Polygon, and BNB Chain. The string is identical, but the networks are separate ledgers. Send USDT on one chain to an exchange deposit that only credits another, and you may end up with a lost or stuck deposit.

So if you build anything that moves funds, make the network an explicit, required field next to the address, never something inferred from the address alone. Also watch for assets like XRP that need a destination tag or memo for exchange deposits.

Habits worth automating

A few things from the security side:

  • Clipboard hijackers swap a copied address for the attacker's. Compare the first and last several characters after pasting, every time.
  • Address poisoning scams send you tiny transfers from look-alike addresses, hoping you'll copy one from your history later. Keep an allowlist or address book instead of copying from past transactions.
  • Hardware wallets let you confirm the receiving address on the device screen, which beats trusting a possibly compromised computer.
  • Test transfers: send a small amount first on a new route, then the rest.
  • Privacy: addresses and balances are public on most chains. Anyone with your address can look at its history.

Takeaways

  • An address is public and safe to share; private keys and seed phrases are not.
  • Most address formats include a checksum, so validate it in code before sending.
  • A valid address on the wrong network is still a costly mistake; make the network explicit.
  • Defend against clipboard malware and address poisoning with visual checks and allowlists.
  • Do a small test transfer when in doubt.

For the full walkthrough, including how to find your address on exchanges and self-custody wallets, plus common mistakes and an FAQ: Read the full guide on NutshellCrypto.

This is educational content, not financial advice.

This post was written with AI assistance.

Top comments (0)