Skip to content
Pages/Legal & Compliance
Page

Wallet Verification

Crypto payments can’t be reversed. If you send funds to the wrong address, they’re gone. Wallet Verification lets you confirm, before you pay someone for the first time, that the wallet really belongs to them and can receive what you’re about to send.

You’ll find it in the sidebar under Legal & Compliance → Wallet Verification.

Most lost payments aren’t hacks. They’re ordinary mistakes and ordinary scams:

  • A wrong address. A character is missed in a copy-paste, or the address comes from an old invoice or the wrong spreadsheet row.
  • A swapped address. Someone impersonating a vendor emails our wallet has changed, please pay this one instead.
  • The right wallet on the wrong network. The address is correct, but the owner can’t access funds sent on the network or in the asset you chose.

Verification catches all three. The owner proves they control the wallet by reporting a small amount only they could see. They also tell you which networks and assets the wallet can receive. You get a record of who confirmed it and when, which helps when an auditor or your board asks how you check counterparties.

  1. You add the wallet and choose the network you plan to pay on.
  2. Mezzanine sends it a small, random amount of USDC, between $0.10 and $0.99. The deposit comes from Mezzanine, not from your accounts.
  3. You send the owner a secure link. Mezzanine gives you a ready-to-send message; you pass it on however you normally talk to them.
  4. The owner signs in and enters the exact amount they received, then says which networks and assets the wallet accepts.
  5. The wallet is marked Tested. You can pay it knowing it reaches the right person.

The whole thing takes you about two minutes, and the owner about one. For the full walkthrough, see Verify someone’s wallet with a test transaction.

  • Before the first payment to a new vendor, contributor or grantee.
  • Whenever someone gives you a new address, even if the request looks like it came from someone you know. This is when verification matters most.
  • Before an unusually large payment to a wallet you haven’t paid in a while.
  • When you’ll pay on a different network or asset from the one you tested. A wallet is only confirmed for the networks and assets its owner listed.

The page has two tabs: Wallets and Bypass log.

Every counterparty wallet across your contacts, and where each one stands. Use the search box to find a wallet by address, name or owner. Filter by Network, Status or Type. Click an owner’s name to open their contact.

The Tested column tells you whether a wallet is safe to pay:

You see What it means What to do
Tested · date The owner confirmed the amount. Hover to see what was confirmed and by whom Pay it, on the networks and assets listed for it
Test pending The test was sent; the owner hasn’t finished yet Wait, or click Review to re-send them the link
Untested This wallet hasn’t been verified Click Test
Failed The test deposit didn’t arrive Click Reverify to try again
Locked The owner entered the wrong amount too many times Click Reverify to send a new amount and link
Expired The owner didn’t finish within 7 days Click Reverify to send a new link

The Network(s) and Asset(s) columns show what the owner said the wallet can receive. All Networks or All assets means they accept everything.

To verify a wallet that isn’t listed yet, click Add Wallet.

The page updates itself while a test is pending, so you’ll see the owner’s confirmation arrive without reloading.

A record of every payment that went ahead to a wallet that hadn’t passed verification. It shows who moved the payment forward, when, which payment and wallet it was, and why the wallet didn’t pass:

  • Untested: the wallet was never verified.
  • Network not in list: the payment used a network the owner didn’t confirm.
  • Asset not in list: the payment used an asset the owner didn’t confirm.

Only entries made while Wallet Verification Mode is on (see below) appear here. It’s the place to look when you need to show that exceptions were tracked.

Wallet Verification Mode is on for every organization unless an admin turns it off, in System Controls → Organization Settings.

While it’s on, anyone who approves, signs or executes a payment to a wallet that hasn’t passed verification sees a warning, such as Destination wallet not verified. To go ahead, they tick I understand this wallet isn’t verified for this payment and want to proceed. The payment isn’t blocked, but each exception is recorded in the Bypass log, with the step it was taken at: proposed, approved, signed or executed.

With it off, nobody sees the warnings and nothing new appears in the Bypass log. See Turn on Wallet Verification Mode.

  • The owner needs no Mezzanine account. They confirm with their email address and a one-time code.
  • Links expire after 7 days and work once. If you send a new test to the same wallet, the old link stops working, so always send the owner the latest one.
  • The owner gets 5 tries to enter the right amount. After that the link locks, and you’ll need to send a new test.
  • Every address is screened against sanctions lists first. If an address is flagged, no test is sent, and you’ll see This address was flagged by OFAC screening; no test was sent. Don’t pay that wallet; raise it with whoever handles compliance.
  • Supported networks: Ethereum, Base, Arbitrum, Optimism, Avalanche and Hyperliquid. Safes and onchain exchange accounts are tested on their own network automatically.
  • Tested means tested for what the owner listed. If you later pay on a different network or in a different asset, verify again or check the wallet’s Network(s) and Asset(s) first.
  • There’s a limit of 100 tests per organization per day. If a send fails with Something went wrong, you may have hit it. Try again later.
To… You need the permission
See this page View contacts and View wallet verification
Add wallets and send tests Start wallet verification, plus Add and edit contacts to add a new wallet
Turn Wallet Verification Mode on or off Edit general organization settings

If you can’t open the page, it tells you which permission is missing and lets you request it. If you can see the page but not start tests, the buttons explain why when you click them.