Skip to content
Get started

Privacy & safety · Beginner

How to spot a fake block explorer

A convincing fake explorer takes an afternoon to build and can show you any transaction you like, for any amount, with a green confirmed badge. Here is how to tell.

Updated 17 September 2026 · 11 min read · How we test

The short answer

A fake explorer is a website that displays whatever its operator wants rather than what the chain says. Verify any transaction on a second explorer you navigated to yourself, never one reached by a link someone sent you. No legitimate explorer ever asks for a seed phrase, a private key or a wallet connection.

Abstract illustration of digital currency and deception

Why fake explorers work at all

An explorer is just a website that displays data. Nothing about the page proves where that data came from.

A real explorer reads a blockchain. A fake one reads a database its operator controls, and can therefore show a transaction that never happened, an amount that was never sent, a confirmation count that is invented, and an address balance chosen to be persuasive.

Building one is not difficult. Clone the visual design of a well-known explorer, register a domain that looks approximately right, and serve pages from your own data. An afternoon's work produces something that will convince most people, because most people have no reason to be suspicious of a page that looks exactly like the one they have used before.

The reason this is worth a guide rather than a footnote is that the technique is a standard component of several common frauds, and the victims are frequently careful people who simply did not know the category existed.

The three patterns you will actually encounter

Proof of a payment that was never made. Somebody buying something from you claims to have paid and sends a link "to the transaction". The page shows a confirmed transfer to your address. You ship the goods. The transaction does not exist on any real explorer. This is the most common version and it works on marketplaces, peer-to-peer trades and private sales.

Fake balance to support a story. An investment scheme shows you a dashboard, and a link to "verify on the blockchain" that displays your balance growing. The explorer is theirs. The balance is a number in their database. This pattern keeps people invested long past the point where a real check would have ended it.

Seed phrase harvesting. A page presenting itself as an explorer offers to "validate", "synchronise", "unlock" or "recover" your wallet, and asks for your seed phrase or a wallet connection. This is straightforward theft. A real explorer reads public data and needs nothing from you — there is no function it could offer that would require a private key.

Related, and worth knowing: the same technique is used against regulated financial firms, not just explorers. Financial regulators publish "clone firm" warnings precisely because impersonators copy a genuine firm’s name, branding and registration number onto a lookalike domain. If a site asks you to act on money, the check is the same one we describe here — confirm the domain independently rather than through any link you were sent.

The specific tells

You arrived by a link somebody sent you. This is the single strongest signal, and it is worth more than every technical check combined. If the link came from the person who benefits from you believing the page, treat the page as fiction until proven otherwise.

The domain is nearly right. Look carefully at the spelling and the suffix. Real explorers include blockchain.com, blockchair.com, mempool.space, blockstream.info, etherscan.io, tronscan.org. A fake will be something like blockchain-explorer.info or etherscan.io.com — plausible at a glance and wrong.

Nothing else on the site works. Real explorers have blocks, statistics, charts, API documentation and years of history. A fake is usually one page deep. Click something unrelated to the transaction you were sent and see whether anything real happens.

The transaction is not on any other explorer. This is the decisive check and it is covered below.

Something asks for a key. Instant, unconditional disqualification. Close the tab.

The check that settles it

Take the transaction hash — just the hash, not the link — and look it up on an explorer you navigated to yourself by typing the address, from a bookmark, or from our directory.

Do not click any link you were given. Do not search for the explorer's name and click the first result, because paid search results for explorer names have been used to serve clones. Type the address or use a bookmark.

If the transaction exists on a real explorer with the amounts and addresses claimed, it is real. If it does not exist, or exists with different details, you have your answer.

For anything of consequence, check two independent explorers. If mempool.space and Blockchair both show the same transaction, it happened — they are separately operated with separately maintained indexes, and fabricating agreement across both is not something a fraudster can do.

Our lookup tool queries public node APIs directly, which means it is reading the chain rather than a database anyone controls. It is a reasonable second source for exactly this purpose.

Screenshots prove nothing whatsoever

This deserves its own section because people keep accepting them.

A screenshot of a transaction is an image. Producing a convincing one requires opening a real explorer, editing the page in the browser's developer tools — which takes about thirty seconds and no technical skill — and taking a screenshot. The result is indistinguishable from genuine.

The same applies to a screen recording, which is only marginally harder. And to a PDF, and to a forwarded email.

The only thing that constitutes evidence is a transaction hash you looked up yourself on an explorer you chose. Anything else is somebody telling you a story with pictures.

If you are transacting with a stranger, ask for the hash rather than a screenshot, and say why. Anyone genuine will provide it immediately, because it costs them nothing. Reluctance to hand over a transaction ID is itself informative.

A related trick uses a real explorer and relies on you misreading it, which is in some ways harder to defend against.

Token names and symbols are arbitrary strings chosen by whoever deploys the contract. They are not unique and nobody polices them. Anyone can deploy a token called USDT, or USDC, or the name of any project, and it will display with that name on every explorer — because the explorer is faithfully showing what the contract says.

So a transaction showing a large USDT payment may involve a contract that has nothing to do with Tether. The explorer is not lying; you are reading the wrong field.

The defence is a habit rather than a check: verify tokens by contract address, against the project's own published address, every time. This applies on Ethereum, BNB Chain, Tron and every other chain with a token standard.

Chains that require explicit opt-in to hold an asset — XRP Ledger trust lines, Stellar trustlines, Hedera token association — are structurally immune to the unsolicited-token half of this, which is a genuine design advantage that rarely gets mentioned.

The second scam that targets victims of the first

There is a follow-on fraud worth naming explicitly, because it targets people who are already distressed and it is extremely common.

After someone loses funds, they search for help. What they find are services offering to recover stolen cryptocurrency — often with professional-looking sites, testimonials, and claimed relationships with law enforcement or blockchain analytics firms. Some of them approach victims directly, in the comments of posts where they described what happened.

These do not work, and the reason is structural rather than a matter of competence. A confirmed blockchain transaction cannot be reversed by anyone. Not by the explorer, not by the network, not by a recovery service, not by a court order against a party that does not hold the funds. The only entities that can move the funds are whoever holds the keys.

What recovery services actually do is take a fee, sometimes several, escalating as they report progress that does not exist. In some cases they are operated by the same people who ran the original fraud, working from a list of known victims.

The narrow exception is when funds reached a regulated exchange that holds identity documents for the recipient. In that case law enforcement, working through the exchange, can sometimes act. That route runs through the police and the exchange, not through a private company charging an upfront fee — and a genuine analytics firm works for institutions, not for individuals responding to a direct message.

Report fraud to the police or national fraud reporting service where you live, and to your bank if fiat money left an account you control. Preserve the transaction hashes and any correspondence. Then be extremely sceptical of anyone who contacts you afterwards offering to help, because a great many of them are the second half of the same operation.

Questions people ask

How do I know if a block explorer is real?

Navigate to it yourself rather than following a link, check the domain carefully, and verify the transaction on a second independently-operated explorer. Two real explorers agreeing is conclusive.

Someone sent me a link to prove they paid. Is that safe?

Do not trust it. Take the transaction hash and look it up yourself on an explorer you chose. A link from the person who benefits from you believing it is the weakest possible evidence.

Can a screenshot of a transaction be faked?

Trivially, in about thirty seconds, using nothing but a browser’s developer tools. Screenshots are not evidence. Only a hash you looked up yourself is.

Why does a block explorer ask for my seed phrase?

Because it is not a block explorer. Real explorers read public data and have no function that could require a private key. Any page asking for one is stealing from you.

The token name looks right but is it the real token?

Check the contract address against the project’s own published address. Token names are arbitrary and freely reusable, and the explorer is faithfully displaying whatever the contract declares.

What should I do if I have been scammed?

Report it to your national fraud reporting service, and to your bank if fiat was involved. Blockchain transactions cannot be reversed, and any service offering to recover funds for an upfront fee is a second scam targeting victims of the first.