Shared wallets: catch multi-accounts that cash out crypto to the same address
A farm can fake devices, IPs and emails, but the money has to land somewhere it controls. On crypto rewards sites that is a short list of wallets. This guide shows how to use the payout address to find the farm behind many small accounts.
Short answer
Compare the payout address of every cashout with the addresses of your other accounts, after normalizing it: several accounts cashing out to one address, or one FaucetPay email, are almost always one person. Treat exchange addresses with a memo or destination tag as address plus memo, hold the shared cashouts for review and act on the whole cluster.
- Strongest single sign
- Two or more accounts paying out to the same wallet or FaucetPay email.
- Normalize first
- Trim spaces, compare case-insensitively where the chain allows it, and normalize payout emails.
- Exchange deposits
- Same address with a different memo or tag belongs to different people: compare address plus memo.
- Fair action
- Hold the cashout, review the cluster, pay one account if they are really a family.
Why the wallet gives the farm away
Faucets, PTC sites and crypto rewards apps pay many small amounts to many accounts. That is exactly what a farm wants: dozens or hundreds of accounts, each claiming a little, each looking like a normal user. Devices can be emulated, IPs rented and emails generated by the thousand.
The payout is different. Every account has to send its balance to an address the farmer controls, and managing hundreds of wallets is work. So most farms cash out to a handful of addresses, often one per payment method, and reuse them for months. When you compare payout addresses across accounts, the farm collapses into a few clusters.
What counts as the same address
Compare addresses after normalizing them, or trivial changes will hide the match. Trim spaces and invisible characters, and compare in a way that suits the payment method.
| Payout method | Compare | Watch out for |
|---|---|---|
| Bitcoin, Litecoin, Dogecoin | The address as entered, without spaces | The same wallet can generate new addresses: shared ones still catch the lazy farms |
| Ethereum, BNB Chain, USDT on EVM chains | Lower-case hex address | Checksum capitals change the look, not the address |
| USDT on Tron (TRC20) | The address as entered | Farms often cash out every account to one exchange deposit address |
| TON, XRP, XLM, BNB with memo | Address plus memo or destination tag | An exchange uses one address for thousands of customers; the memo tells them apart |
| FaucetPay and other microwallets | The email, normalized | Gmail dots and plus aliases (john.doe+2@gmail.com is john.doe@gmail.com) |
| PayPal | The email, normalized | Same aliases as above |
If your site accepts a memo or tag, store and compare the address together with it. Otherwise every customer of the same exchange looks like one person, which is the most common false positive in wallet matching.
The signals that go with a shared wallet
- Shared payout address. Two or more accounts on your site cash out to the same normalized address. The more accounts, the stronger the sign.
- New account, fast cashout. Farm accounts reach the minimum and cash out within their first day, then stop.
- Cashout velocity. Many cashouts to the same address within hours, from accounts that each claim only a little.
- Same device or network. Shared wallets usually come with shared devices or the same small set of IPs, which confirms the cluster.
- Round-trip patterns. The same addresses keep appearing in new accounts week after week, after you ban the old ones.
None of the device or network signals is needed to act on a shared wallet, but together they tell you how big the cluster is and which accounts to look at first.
Check your own history in five minutes
You can see how big the problem is on your site today with one query on your withdrawals table. Group the paid withdrawals of the last 90 days by the normalized address and count the distinct accounts behind each one.
SELECT LOWER(TRIM(payout_address)) AS address,
COUNT(DISTINCT user_id) AS accounts,
COUNT(*) AS cashouts,
SUM(amount) AS paid
FROM withdrawals
WHERE status = 'paid' AND created_at > NOW() - INTERVAL 90 DAY
GROUP BY address
HAVING accounts > 1
ORDER BY paid DESC
LIMIT 50;Adapt the table and column names to your script. Every row is one address shared by several accounts; the paid column is what those accounts took out. On most faucet and PTC sites the top rows are a handful of addresses shared by dozens of accounts, and they add up to a large share of all payouts.
Run the same query with your payout email column for FaucetPay and PayPal, after removing Gmail dots and plus aliases in your code, and again with only the last 7 days to see whether the farm is still active today.
Acting on it without hurting real users
- Hold, do not reject. Put the cashout on hold and keep the balance. You can always pay later; you cannot recover crypto once it is sent.
- Look at the whole cluster. Open every account that shares the address, with their devices, IPs and signup dates. A farm shows up as many accounts created close together that cashed out once each.
- Allow real families. Two members of a household sometimes share one wallet. If the accounts behave normally and were created far apart, pay one and ask the other to use their own address.
- Block the address, not just the accounts. Add the address to your block list so the next account the farmer creates with it is held at the first cashout.
- Say why. A short message that the address is already used by another account gets honest users to fix it and tells farmers the door is closed.
How CashoutGuard automates it
Send payout_address and payout_method with every cashout event to /v1/evaluate. CashoutGuard normalizes the address (spaces removed, lower-cased, Gmail dots and plus aliases folded for emails) and stores only a hash of it, scoped to your site. When a second account uses the same address, the cashout gets payout_address_shared with the number of accounts, and the linked accounts appear in the fraud rings view.
Send address and memo together as the payout_address when your users withdraw to an exchange, so different customers of the same exchange never collide. New sites start in shadow mode, and in Enforce mode you can choose to hold only cashouts without ever banning the user. See integrations for the code and the cashout checklist for the rest of the checks.