Swap security

Verify the recipient on the device before approving a swap

Use the hardware device’s trusted display to check destination details while distinguishing router and final token recipient.

Compare destination information on the hardware device with the address you independently intended to use. A browser field alone can be altered or misleading, and checking only the first and last characters is weaker than checking the full address.

Know which destination is displayed

For a simple transfer, the destination is usually the receiving account. In a swap, the top-level destination may be a router while the final output recipient is encoded inside the transaction. Uniswap’s router documentation shows recipient information within swap commands.

Seeing the correct router address therefore does not, by itself, prove the output recipient is correct. Use a supported signing view that exposes the relevant operation details.

Compare against an independent source

For a recipient you control, use its genuine wallet receive view and verify its address on that device where supported. For a service, use its authenticated deposit instructions and check the required asset and network.

Ledger’s clear-signing documentation explains the role of readable device review. If the device cannot expose enough information, do not infer the hidden fields from the website’s reassuring label.

After a mismatch

Reject the request, investigate the source address and check for clipboard replacement or an incorrect account selection. A small earlier test does not prove the next pasted address is unchanged.

Keep approval spenders separate from recipients. Correctly verifying where output goes does not validate who receives permission to pull the input token.

Sources & verification (3)

Source-check date is recorded in the article details. URLs are provided for manual verification. Use Copy to keep this page open.

  1. Universal Router Commands

    Optional command failure and payment/cleanup behavior in Universal Router.

    https://developers.uniswap.org/docs/protocols/universal-router/concepts/commands
  2. Overview - Ledger Developer Portal

    Human-readable transaction review and clear-signing scope.

    https://developers.ledger.com/docs/clear-signing/overview
  3. Ethereum security and scam prevention

    Secret protection, phishing, address checks and public-key custody hygiene.

    https://ethereum.org/security/

Continue reading

Pasted recipient changed: how to stop a misdirected swap How to verify the spender before approving an aggregator