CashoutGuard: fraud prevention for rewards, GPT, faucet, PTC and offerwall sites.

Shared wallets: catch multi-accounts that cash out crypto to the same address

A farm can fake devices, IPs and emails, but the money has to land somewhere it controls. On crypto rewards sites that is a short list of wallets. This guide shows how to use the payout address to find the farm behind many small accounts.

Short answer

Compare the payout address of every cashout with the addresses of your other accounts, after normalizing it: several accounts cashing out to one address, or one FaucetPay email, are almost always one person. Treat exchange addresses with a memo or destination tag as address plus memo, hold the shared cashouts for review and act on the whole cluster.

Strongest single sign
Two or more accounts paying out to the same wallet or FaucetPay email.
Normalize first
Trim spaces, compare case-insensitively where the chain allows it, and normalize payout emails.
Exchange deposits
Same address with a different memo or tag belongs to different people: compare address plus memo.
Fair action
Hold the cashout, review the cluster, pay one account if they are really a family.

Why the wallet gives the farm away

Faucets, PTC sites and crypto rewards apps pay many small amounts to many accounts. That is exactly what a farm wants: dozens or hundreds of accounts, each claiming a little, each looking like a normal user. Devices can be emulated, IPs rented and emails generated by the thousand.

The payout is different. Every account has to send its balance to an address the farmer controls, and managing hundreds of wallets is work. So most farms cash out to a handful of addresses, often one per payment method, and reuse them for months. When you compare payout addresses across accounts, the farm collapses into a few clusters.

What counts as the same address

Compare addresses after normalizing them, or trivial changes will hide the match. Trim spaces and invisible characters, and compare in a way that suits the payment method.

Payout methodCompareWatch out for
Bitcoin, Litecoin, DogecoinThe address as entered, without spacesThe same wallet can generate new addresses: shared ones still catch the lazy farms
Ethereum, BNB Chain, USDT on EVM chainsLower-case hex addressChecksum capitals change the look, not the address
USDT on Tron (TRC20)The address as enteredFarms often cash out every account to one exchange deposit address
TON, XRP, XLM, BNB with memoAddress plus memo or destination tagAn exchange uses one address for thousands of customers; the memo tells them apart
FaucetPay and other microwalletsThe email, normalizedGmail dots and plus aliases (john.doe+2@gmail.com is john.doe@gmail.com)
PayPalThe email, normalizedSame aliases as above

If your site accepts a memo or tag, store and compare the address together with it. Otherwise every customer of the same exchange looks like one person, which is the most common false positive in wallet matching.

The signals that go with a shared wallet

  • Shared payout address. Two or more accounts on your site cash out to the same normalized address. The more accounts, the stronger the sign.
  • New account, fast cashout. Farm accounts reach the minimum and cash out within their first day, then stop.
  • Cashout velocity. Many cashouts to the same address within hours, from accounts that each claim only a little.
  • Same device or network. Shared wallets usually come with shared devices or the same small set of IPs, which confirms the cluster.
  • Round-trip patterns. The same addresses keep appearing in new accounts week after week, after you ban the old ones.

None of the device or network signals is needed to act on a shared wallet, but together they tell you how big the cluster is and which accounts to look at first.

Check your own history in five minutes

You can see how big the problem is on your site today with one query on your withdrawals table. Group the paid withdrawals of the last 90 days by the normalized address and count the distinct accounts behind each one.

SELECT LOWER(TRIM(payout_address)) AS address,
       COUNT(DISTINCT user_id)      AS accounts,
       COUNT(*)                     AS cashouts,
       SUM(amount)                  AS paid
FROM withdrawals
WHERE status = 'paid' AND created_at > NOW() - INTERVAL 90 DAY
GROUP BY address
HAVING accounts > 1
ORDER BY paid DESC
LIMIT 50;

Adapt the table and column names to your script. Every row is one address shared by several accounts; the paid column is what those accounts took out. On most faucet and PTC sites the top rows are a handful of addresses shared by dozens of accounts, and they add up to a large share of all payouts.

Run the same query with your payout email column for FaucetPay and PayPal, after removing Gmail dots and plus aliases in your code, and again with only the last 7 days to see whether the farm is still active today.

Acting on it without hurting real users

  1. Hold, do not reject. Put the cashout on hold and keep the balance. You can always pay later; you cannot recover crypto once it is sent.
  2. Look at the whole cluster. Open every account that shares the address, with their devices, IPs and signup dates. A farm shows up as many accounts created close together that cashed out once each.
  3. Allow real families. Two members of a household sometimes share one wallet. If the accounts behave normally and were created far apart, pay one and ask the other to use their own address.
  4. Block the address, not just the accounts. Add the address to your block list so the next account the farmer creates with it is held at the first cashout.
  5. Say why. A short message that the address is already used by another account gets honest users to fix it and tells farmers the door is closed.

How CashoutGuard automates it

Send payout_address and payout_method with every cashout event to /v1/evaluate. CashoutGuard normalizes the address (spaces removed, lower-cased, Gmail dots and plus aliases folded for emails) and stores only a hash of it, scoped to your site. When a second account uses the same address, the cashout gets payout_address_shared with the number of accounts, and the linked accounts appear in the fraud rings view.

Send address and memo together as the payout_address when your users withdraw to an exchange, so different customers of the same exchange never collide. New sites start in shadow mode, and in Enforce mode you can choose to hold only cashouts without ever banning the user. See integrations for the code and the cashout checklist for the rest of the checks.

Frequently asked questions

Is the wallet address stored?

Only a hash of the normalized address, scoped to your site, so it can be matched against your other accounts without keeping the address itself.

What if a farm uses a new address for every account?

Then the wallet signal is quiet, and device, network and behaviour signals carry the check. Most farms still reuse addresses, because moving funds out of hundreds of wallets costs time and fees.

Should I block every shared address?

Hold and review instead. Families and exchange deposit addresses without a memo cause most false matches, and a quick look at the cluster tells them apart.

Keep reading