ZAFU · Address Confidence FAQ · Updated May 2026

Crypto Address Confidence FAQ

Direct answers about trusted address memory, protected wallets, source evidence, Transfer Check, privacy, and crypto address attacks.

Who is ZAFU for?+

ZAFU is for everyday crypto users, self-custody users, active traders, freelancers, and professional operators who want more confidence in the recipient address before funds move. The same workflow helps with a small exchange withdrawal, a repeat stablecoin payment, or a higher-value operator transfer.

Is ZAFU useful for everyday crypto users?+

Yes. ZAFU is not only for teams. It helps individuals review recipients before transfers, withdrawals, swaps, and DeFi actions by showing trusted address history, warning signals, source evidence when available, and the full segmented address.

What is the ZAFU address book?+

The address book is ZAFU's local-first trusted address memory. It stores trusted contacts, protected wallets, labels, notes, and history-derived context on your device so the extension can compare new sends against addresses you already recognize.

What are protected wallets?+

Protected wallets are addresses you control. Marking them helps ZAFU distinguish your own wallets from external recipients during review. ZAFU still cannot read private keys, sign transactions, or move funds from those wallets.

What does trusted address history mean?+

Trusted address history means ZAFU can recognize addresses you have saved or previously interacted with through supported local history workflows. It is evidence for review, not a guarantee about the person or service currently controlling that address.

What is source evidence?+

Source evidence is recent address-only copy context, such as an address copied from Telegram Web. ZAFU uses it to show whether the pasted address still matches what you copied. It does not store chat text, sender identity, group names, or message IDs.

How is ZAFU different from a public address checker?+

A public checker can show format results and public warning signals. The ZAFU Extension adds private context the checker cannot see: your trusted address book, protected wallets, copied source, paste destination, and final Transfer Check inside wallet, exchange, and dapp flows.

Are ZAFU Teams or Pro products live?+

No. ZAFU is researching shared trusted address books, operator reviews, verification receipts, and audit trails with design partners. Paid Teams and Pro products are not live yet.

What is address poisoning in crypto?+

Address poisoning is an attack where a scammer sends a zero-value transaction from an address that visually resembles one of your trusted contacts — same first and last characters, different middle. The fake address appears in your transaction history. When you copy an address from history to reuse it, you may copy the fake one and send funds to the attacker.

What is clipboard hijacking in crypto?+

Clipboard hijacking is a malware technique where software on your computer monitors your clipboard and silently replaces any crypto address you copy with an attacker's address before you paste. The replacement is invisible. The hijacked address is the same length and format as a real address.

What is the difference between address poisoning and clipboard hijacking?+

Address poisoning manipulates your transaction history: the attacker plants a lookalike address so you copy the wrong one yourself. Clipboard hijacking uses malware to replace the correct address you copied with a malicious one. Both attacks result in you pasting the wrong address. Both exploit the exact same window: the moment between copy and paste.

How do attackers generate addresses that look like mine?+

Attackers use vanity address generators: tools that brute-force millions of addresses per second until they find one matching a target prefix and suffix. For EVM addresses, matching the first 6 and last 4 characters typically takes minutes on a GPU. This is why checking only the start and end of an address is not enough protection.

How large is this problem?+

In January 2026 alone, there were 3.4 million address poisoning attempts on Ethereum and more than $300 million lost to phishing. Browser-based clipboard attacks drained an estimated $713 million in 2025. These attacks scale with no marginal cost to attackers: generating 10,000 poisoning transactions costs pennies in gas on cheap L2s.

How should I verify an address before sending?+

To verify a crypto address before sending: (1) Compare every character, not just the first and last few. (2) Check it against known warning lists. (3) Verify it against your own history — if it appeared as an unsolicited incoming transaction with no value, it may be a poisoning attempt. (4) Use a tool like Zafu that automates these checks at paste time, before the address reaches your wallet.

Is checking only the first and last characters of a crypto address enough?+

No. Address poisoning attacks specifically exploit this habit. Attackers generate addresses that share the same first 6 and last 4 characters as your trusted contacts using vanity address tools. The cautious approach is to compare the full address character-by-character, or use a tool that does it automatically.

Does a hardware wallet protect against address poisoning?+

A hardware wallet prompts you to verify the destination address on the physical device screen. This can protect against clipboard hijacking if you carefully read the full address on-device. However, it does not protect against address poisoning. If you already copied the wrong address from your history, you would see the poisoned address on the device screen and likely confirm it.

Can you recover funds sent to a wrong address?+

No. Cryptocurrency transactions are irreversible. Once confirmed on-chain, funds cannot be recovered without the recipient's cooperation. This is why prevention — catching the wrong address before you send — is the only effective protection.

What is Zafu and how does it protect me?+

ZAFU is a free Chrome extension for address confidence before crypto sends. It combines trusted address memory, source evidence, full address review, clipboard hijacking detection, address history checks, curated warning lists, community-reported addresses, and GoPlus real-time threat data. It never touches your wallet, private keys, or signing process.

What is Transfer Check?+

Transfer Check is the extension's final review before a crypto address reaches a wallet, exchange, or dapp field. It summarizes copied-address match, source evidence when available, warning signals, field context, and the full segmented address so you can review before sending.

Is ZAFU only for teams or professional operators?+

No. The free extension and checker are built for everyday crypto users too. ZAFU is researching additional team workflows, but those future products are separate from the live free tools.

How do ZAFU community reports work?+

When Zafu users report a suspected attacker address, the report is added to a community signal pool. Once an address accumulates enough independent signal weight, Zafu can warn other users. Community-reported means high risk; team-reviewed or trusted external confirmation is required before stronger "confirmed malicious" language is used. The Security Model explains the current privacy and review boundaries.

Does Zafu send my addresses to a server?+

Zafu sends pasted EVM addresses to GoPlus for real-time threat checks, public wallet addresses to Etherscan or Solscan only when you fetch history, and suspected attacker addresses to Zafu community reports if you report them or opt in to automatic threat signals. Labels, notes, trusted contacts, private keys, seed phrases, and wallet credentials stay on your device.

Is the Zafu Extension source public?+

The Chrome extension source is public and auditable at github.com/jimozo/zafu-extension. Zafu's private operating repo also contains website, backend, launch, and automation work that is not part of the public extension release. No bundler, no CDN scripts, no npm dependencies in the extension: the release source is readable. Zafu also ships a verifiable install fingerprint you can compare in Settings to confirm your install matches the published release.

Why does Chrome say Zafu can read and change data on websites?+

Chrome shows that warning because Zafu must see crypto-address paste events before the destination field accepts them. That is how it can catch clipboard hijacking and address poisoning at the paste moment. Zafu does not request tabs or activeTab, does not read browser history, does not run advertising analytics, and only activates address-checking logic when a crypto address is pasted in a relevant wallet, exchange, or dapp context.

What wallets does Zafu work with?+

Zafu works with any web-based wallet or exchange: MetaMask, Rabby, Phantom, Coinbase Wallet, Binance, Kraken, Uniswap, Aave, and hundreds more. Zafu operates at the browser level, intercepting paste events regardless of which wallet or dApp you use. It does not require wallet integration or any special permissions from your wallet.

Does Zafu work with Solana and TRON addresses?+

Yes. Zafu detects clipboard hijacking, address poisoning, and scam addresses for both EVM addresses (Ethereum, Arbitrum, Base, Polygon, and all EVM-compatible chains) and Solana addresses (including system program impersonation detection). ENS name resolution is also supported for EVM, and v1.1.7 adds local TRON validation and comparison.

Build address confidence before every crypto send.

Free Chrome extension. Trusted address memory, source evidence, Transfer Check, and no wallet access.

Install - Free

Public extension source · Optional anonymous counts · Zero wallet access

Back to FAQ topics