Published on

Fake USDC or USDT in your wallet: why it arrived and what to do

The short answer

It is not USDC. It is a token someone created shortly before sending it, with USDC in its name. It has no value and no market. Your wallet is not compromised, and the token can do nothing on its own.

The risk is the link written in its name. That is where the attacker wants you to go.

32 fake USDC on one wallet

The sample wallet on this site, 0x4cb9…a743, received 32 of them on Base between 27 July 2025 and 6 June 2026. Their face value adds up to 37,158 "USDC". Their value is zero.

DateAmountName as the wallet shows it
27 July 20251,080UЅDС | t.me/s/US_CIRCLE | *claim until 30.07.25
11 October 20253,850UЅDС | t.me/s/US_CIRCLE | *claim until 15.10.25
13 February 20261,250(t.me/s/US_POOL) *claim until 14.02.26
3 May 2026980U S D C ✅Visit to claim: t.me/s/us_pool
6 June 20261,850U S D C (swap: t.me/s/us_pool)
The WalletHistory feed for the sample wallet on Base, received only and spam shown: fake USDC airdrops with Telegram links in their names, each flagged as spam

Every amount is different, from 385 to 3,850, and most names carry a deadline a few days away. Fifteen point to a channel called US_CIRCLE, which borrows the name of Circle, the company that issues USDC. The other seventeen point to US_POOL.

It seems to come from the USDC contract itself

In the history, all 32 arrive from 0x833589fc…2913. That is the real USDC contract on Base. It never sent any of them.

Take the last drop, on 6 June 2026. The transaction was sent by 0x013daa…2637, who paid the gas. It called 0x65755e…f31f, a contract that is the fake token itself. That contract wrote 46 Transfer events, one for each of 46 wallets, and in every one it put the real USDC address in the sender field. The real USDC contract does not take part in the transaction at all.

A token contract writes its own Transfer events, and nothing checks what it puts in the sender field. Explorers and wallet apps display that field as the sender, so the fake token looks like it came from USDC.

WalletHistory reads the same event, so in the picture above the sender column says USDC token contract too. What gives each row away is the token itself: a contract that is not USDC, with a link in its name. That is why every one of them is flagged.

Across the 32 drops there were 29 different fake contracts and 24 different addresses paying the gas. The 32 transactions wrote 12,930 of these transfers, between 46 and 500 each. A blocklist of token addresses is always one contract behind.

The name is the attack

UЅDС in the older names is not USDC either:

U+0055   Latin U
U+0405   Cyrillic DZE, drawn like an S
U+0044   Latin D
U+0421   Cyrillic ES, drawn like a C

To the eye it reads USDC. To a filter looking for the letters U, S, D and C, it is a different word. Later drops gave up the disguise and wrote U5DC or U S D C, with emoji and the word claim.

The token cannot move your funds. Its name is an advertisement: a balance of free USDC, a deadline, and a channel where the claim supposedly happens. A page that asks you to connect your wallet and sign a message to receive tokens you never expected is how wallets get emptied. I did not open the channel.

How to tell a real stablecoin from a fake

The only test that works is the contract address. Not the name, not the icon, not the sender. These are the real ones, in full:

Ethereum   USDC   0xa0b86991c6218b36c1d19d4a2e9eb0ce3606eb48
Ethereum   USDT   0xdac17f958d2ee523a2206206994597c13d831ec7
Base       USDC   0x833589fcd6edb6e08f4c7c32d4f71b54bda02913
Arbitrum   USDC   0xaf88d065e77c8cc2239327c5edb3a432268e5831
Arbitrum   USDT   0xfd086bc7cd5c481dcc9c85ebe478a1c0b69fcbb9
Optimism   USDC   0x0b2c639c533813f4aa9d7837caf62653d097ff85
Polygon    USDC   0x3c499c542cef5e3811e1192ce70d8cc03d5c3359
Polygon    USDT   0xc2132d05d31c914a87c6611c10748aeb04b58e8f
BNB Chain  USDC   0x8ac76a51cc950d9822d68b83fe1ad97b32cd580d
BNB Chain  USDT   0x55d398326f99059ff775485246999027b3197955

Compare every character, not the first and last few. Shortened addresses are exactly what these attacks rely on.

Other signs, none of them enough on its own:

  • Your wallet app shows no dollar value next to it. Real USDC and USDT are priced at about one dollar.
  • The name contains a link, an emoji, spaced letters or the word claim.
  • It arrives from the address of the USDC or USDT contract. Real stablecoins come from the person or protocol that paid you.

What to do

  • Leave the token alone. There is no market for it, so there is nothing to sell. A site that offers to swap or claim it is the attack.
  • Do not open the channel or any address written in the name.
  • Never connect your wallet or sign anything to claim tokens you did not expect.
  • Hide the token in your wallet app if it lets you.
  • If you already signed something on such a page, revoke the approvals you gave and move what is left to a new wallet.

The same attack in other forms

Fake tokens also go out of your wallet instead of in. Both of these exist so that a lookalike address sits next to a real one in your history:

Check your own address

Paste an address on the front page. WalletHistory reads the last 500 transactions on ten EVM chains and flags fake tokens, spam airdrops and poisoning transfers where they sit. There is nothing to connect and nothing to sign.

These rows are hidden by default. Switch off Hide spam in the Transactions tab to see each one. The tool reads the last 500 transactions, so for the wallet in this article it shows the 12 most recent of the 32 drops.

The same tricks are common on Tron, where most USDT moves. This page covers Ethereum and the other EVM chains. The tool does not read Tron.