Keplr Wallet Extension: Detecting Fake Token Listings Before Your First Swap

A Cosmos ecosystem user downloads the Keplr wallet extension, navigates to swap on Osmosis, and searches for a token by name. Several results appear, each with a similar icon and name. Without verification, it is easy to select the wrong contract address and approve a transaction that sends funds to a scam token that has no liquidity, no legitimate backing, and no way to recover the value. Spoofed tokens are a common attack vector on decentralized exchanges, and Keplr’s token import feature—while powerful for accessing legitimate assets—does not prevent users from importing tokens that exist only to steal funds.

The core problem is that a token name and symbol are not unique identifiers on a blockchain. Thousands of token contracts can claim to be “Cosmos Hub” or “USDC” or “Atom,” and a decentralized exchange cannot enforce exclusivity the way a centralized platform can by listing only verified tokens. The Keplr wallet extension allows users to add custom tokens by pasting a contract address, but that flexibility is only safe when the address has been verified against an authoritative source and cross-checked for common spoofing techniques. Learning to perform that verification before importing or swapping is essential for anyone managing assets across multiple Cosmos chains.

A screenshot of the Keplr wallet extension's custom token import interface, showing the contract address field and verification requirements for token addition

Why decentralized wallets cannot filter tokens the way exchanges do

Centralized exchanges maintain curated lists of trading pairs, and they reject tokens that do not meet their standards or that they suspect are scams. That gatekeeping is a form of security by restriction: if you cannot trade a token on Coinbase, you are protected from buying a counterfeit version on Coinbase. The tradeoff is that users also cannot access tokens that the exchange has simply not heard of yet, or tokens from smaller ecosystems that do not prioritize exchange relationships.

A decentralized wallet like Keplr takes the opposite approach. It does not curate an approved list; instead, it displays tokens that are already deployed on the chain and lets users import any token by contract address. This model is more permissive and gives developers access without an approval process. However, it also means that spoofed, low-liquidity, or malicious tokens can coexist with legitimate ones under nearly identical names. The burden of verification shifts entirely to the user.

The Keplr wallet extension applies some heuristics to reduce obvious confusion—it may show verified tokens first or display which tokens have liquidity on major decentralized exchanges. But these signals are not guarantees. A token with no liquidity cannot be swapped, which prevents accidental loss, but it does not prevent importing it into your portfolio as a display artifact. More importantly, a sophisticated scam token may have liquidity provided by the attacker themselves, making it temporarily tradeable at an unfavorable rate designed to trap liquidity providers or swappers who do not verify the address first.

The contract address is the only definitive identifier

A token’s true identity on a blockchain is its contract address—a long hexadecimal string that uniquely identifies the code deployed at that location. Everything else—the name, symbol, logo, and even the number of decimals—can be spoofed. This distinction is critical when using the Keplr wallet extension to import custom tokens or verify token authenticity before a swap.

To verify a token’s contract address, start with an authoritative source. The official website or GitHub repository of the token project should clearly display the contract address for each chain it is deployed on. If you are looking for Atom on Cosmos Hub, visit the official Cosmos documentation or the Cosmos Hub blockchain explorer. For Osmosis tokens, check Osmosis’s official token registry or the project’s verified social media accounts.

Once you have a contract address from an authoritative source, compare it character-by-character to the address displayed in the Keplr wallet extension or on the decentralized exchange you are about to use. Do not rely on the first few or last few characters matching, because attackers often create addresses that are nearly identical. Tools like a side-by-side text comparison or copying both strings into a note can reduce transcription errors. If even one character differs, you have identified a spoofed token.

The additional layer is to check the contract code itself using the appropriate blockchain explorer. On Cosmos Hub, that is Mintscan or similar explorers; on Osmosis, you can verify on Mintscan as well. Paste the contract address into the explorer’s search bar and review the contract’s transaction history, creator address, and deployment date. A token created moments ago by an unknown address, with no verification badge, and with unusual or empty metadata is a strong red flag. Legitimate tokens typically have a creation date that matches the project launch, a creator address that links to the official project wallet, and at least some transaction history or holder information.

Comparing addresses safely within the Keplr extension interface

When you add a custom token to the Keplr wallet extension, the interface displays the contract address in a field. Before confirming the import, copy that address and paste it into a text file or the blockchain explorer to verify it independently. Do not trust that the address shown in Keplr is correct simply because you copied and pasted it; phishing sites and compromised browsers can alter text between copy and display.

Open a new browser tab and go directly to the official blockchain explorer—not a search result that might link to a phishing version. Search for the contract address. Verify that the token name and symbol shown on the explorer match the expected values. Check that the deployer address is known or belongs to the project. Review the token supply and any holder concentration; if one address holds 90% of the tokens, that is a sign of potential manipulation.

If you are importing a token from an ecosystem you are unfamiliar with, look for verification badges or green checkmarks that some explorers add to recognized tokens. Mintscan, for example, may display a verified label for major tokens. That verification is not perfect—it depends on the explorer’s own review process—but it provides one additional signal. Never assume that a verified badge on one explorer means the token is safe everywhere; some explorers have lower verification standards than others.

The Keplr wallet extension also shows token holdings and portfolio value. If you have accidentally imported a scam token, it will appear in your wallet with a zero or near-zero value. Do not attempt to sell it immediately. Instead, leave it alone and remove it from your portfolio view if possible. Some wallets allow you to hide or remove custom tokens without deleting them from the blockchain. If you have transferred actual funds to a scam token address by mistake, those funds are likely unrecoverable, and you should focus on securing your remaining assets rather than attempting to retrieve them through unreliable recovery services.

Cross-chain token mapping and IBC verification

The Cosmos ecosystem is built on Inter-Blockchain Communication (IBC), which allows tokens to be transferred between chains while maintaining a canonical representation on their home chain. A token deployed on Juno can be bridged to Osmosis, and users can trade it there. However, the bridged version on Osmosis is not the same contract as the original on Juno; it is a separate token created to represent the bridged asset.

This creates an opportunity for confusion and scamming. A malicious actor could deploy a fake “Juno” token directly on Osmosis, even though legitimate Juno has been bridged through IBC. The real bridged Juno will have a different contract address, and the fake one will have no connection to the canonical Juno token on Juno itself. To verify which version is legitimate, check the official token’s documentation for the list of approved IBC routes and contract addresses on each chain.

When you use the Keplr wallet extension to manage assets across multiple chains, pay attention to how tokens are sourced. If you are swapping Juno, verify that the contract address corresponds to either the original Juno on Juno Hub or an officially approved bridged version on the chain you are using. Look for any official bridge address or governance decisions that specify the canonical representation. Many projects now list this information on their websites to prevent exactly this confusion.

The security risk is heightened when bridges are involved because a successful swap of a fake token may appear to complete, transferring your funds to a malicious address. The transaction will be confirmed on the blockchain, but the token you receive will have no value or liquidity. Always verify the receiving token address as carefully as the sending token address. After a swap, check that your holdings in the Keplr wallet extension match your expectations and that the new token balance corresponds to the executed transaction.

Avoiding social engineering and phishing disguises

Scammers often create fake social media accounts, websites, and support channels that appear to represent popular tokens. A fake Twitter account or Telegram group can direct users to a counterfeit token import link or a phishing website that mimics Keplr’s interface. If you follow a link from an unknown source to import a token, you may be directed to malicious code instead.

Always access the Keplr wallet extension directly from your browser’s extension list, never from a link. Verify that you are using the official Keplr extension by checking that it was installed from the Chrome Web Store (or equivalent official app store). Check the extension ID and publisher name to confirm it is the legitimate Keplr Wallet, maintained by the official development team. Fake extensions with nearly identical names have been distributed on unofficial app stores.

When searching for token information, use the official blockchain explorers and the project’s verified websites directly. Do not click links from chat messages, emails, or forum posts unless they are from clearly authenticated accounts. The official Keplr wallet extension will never ask you to enter your seed phrase or private keys into an external website. If any prompt requests sensitive information, you are interacting with a phishing site or malicious code.

If you receive a message directing you to claim rewards, participate in an airdrop, or import a special token, treat it as suspicious until you have independently verified the offer. Real airdrops do not require you to import a custom token or connect your wallet to a third-party interface. Instead, they credit tokens to your address automatically or through a process managed by the official project. The requirement to manually import a token or approve a transaction is a common scam pattern.

Using blockchain explorers to validate transaction history and contracts

Before importing any token into the Keplr wallet extension, spend two minutes examining the contract on the blockchain explorer. Look for the following information: deployment date, total supply, number of holders, and top holder concentration. A token deployed yesterday with a 99% supply held by one address is almost certainly a scam or a rug pull waiting to happen.

Check the transaction history of the contract address itself. Legitimate tokens show regular transfers and trading activity. A contract with a few transactions, all of which moved tokens to a single address, may be a test contract or a failed token. A contract with many transactions involving small amounts transferred from many addresses suggests actual utility and adoption.

Look at the contract code if the explorer provides a readable view. Many blockchain explorers display contract bytecode; some also show the source code if it was verified during deployment. Verified code is more trustworthy because you can read the actual logic. Unverified code is still functional, but you cannot inspect what it does. For tokens critical to your portfolio, use the Keplr wallet extension with an unverified contract only if you have very strong reasons to trust it and can accept the risk of hidden malicious behavior.

The project’s GitHub repository is another source of truth. If a token is legitimate and open-source, the contract code should be published on GitHub with documentation. Compare the source code in the GitHub repository to the verified code on the blockchain explorer, if available. A match between these sources is strong evidence that you are looking at the real contract.

Setting up alerts and monitoring for portfolio changes

After importing tokens into the Keplr wallet extension, monitor your portfolio for unexpected changes. If a token you believe you own suddenly appears in your holdings without a transaction, or if the balance changes unexpectedly, investigate immediately. Check your transaction history to see whether any unapproved transactions occurred. If you find unauthorized activity, your private keys may be compromised, and you should move funds to a new wallet using a different secure device.

The Keplr wallet extension provides transaction history on each connected chain. Review this history regularly, especially after visiting decentralized exchanges or granting approvals to dApps. Understand that an “approval” transaction does not transfer funds directly; instead, it grants permission to a smart contract to move up to a specified amount on your behalf. If you have approved a malicious contract or a typosquatted version of a legitimate dApp, an attacker could later submit a transaction to drain your funds.

Consider using the Ledger hardware wallet integration with the Keplr wallet extension for large balances. Hardware wallets require physical confirmation for each transaction, which prevents an attacker with access to your browser from moving funds without your knowledge. The trade-off is that signing transactions becomes slower and more cumbersome, but for assets worth thousands of dollars, that friction is worth the security improvement.

Document the official contract addresses for all tokens in your portfolio. Keep them in a secure location, such as an encrypted note or an offline file, separate from your wallet recovery phrase. If you ever need to verify a token quickly, you will have the authoritative address readily available without having to search the internet and risking a phishing site.

Building a verification checklist before every swap

Develop a repeatable process before importing any token or executing a swap. First, identify the token by its official name and the chain it is deployed on. Second, locate the official source—the project’s website, GitHub, or a trusted blockchain explorer—and copy the exact contract address. Third, paste the address into a blockchain explorer and verify the token name, symbol, total supply, and holder distribution. Fourth, check the contract deployment date and creator address for signs of legitimacy or suspicious behavior. Fifth, if adding the token to the Keplr wallet extension for the first time, import only a small amount and execute a test swap or transfer before moving larger amounts.

This process takes fewer than five minutes but has prevented countless users from losing funds to fake tokens. The time investment is small relative to the value protected. When you have completed verification and are confident the token is legitimate, you can proceed with larger transactions knowing you have reduced the risk of a spoofed token scam significantly.

The Keplr wallet extension is a powerful tool for managing assets across the Cosmos ecosystem, but its power depends on careful usage. Unlike centralized exchanges that filter tokens for you, a decentralized wallet puts the responsibility of verification on the user. By learning to read blockchain explorers, cross-check contract addresses, and identify red flags, you can safely use the Keplr wallet extension, explore new tokens, and participate in decentralized finance without falling victim to common scams. You can also visit the keplr wallet / keplr wallet extension / keplr wallet download page to ensure you are installing the genuine version from an official source before beginning this verification process.

Frequently asked questions

How do I verify a token address in the Keplr wallet extension before swapping?

Copy the contract address from an official source (project website or GitHub), then search for it in a blockchain explorer such as Mintscan. Verify that the token name, symbol, and supply match the expected values. Compare the contract address character-by-character to the one displayed in the Keplr wallet extension. If any character differs, the token is spoofed.

Can the Keplr wallet extension automatically prevent me from importing fake tokens?

The Keplr wallet extension applies heuristics such as displaying verified tokens first and checking for liquidity, but it cannot prevent all spoofed tokens because names and symbols are not unique on blockchains. You must verify the contract address independently using a blockchain explorer before importing or swapping. No wallet interface can substitute for your own verification.

What should I do if I accidentally imported a scam token into the Keplr wallet extension?

Do not attempt to sell or transfer the scam token. Instead, leave it in your wallet or remove it from your portfolio view if the extension allows. If you have transferred funds to a scam token address, those funds are almost certainly unrecoverable. Focus on securing your remaining assets and use the Keplr wallet extension to monitor for unauthorized transactions in the future.