Written for people who do not do computers. If you can use WhatsApp, you can use this.
The whole manual in three lines:
1 · Someone sends you codes, screenshots or links about a USDT payment.
2 · You copy each thing they sent and paste it into the matching box in FlashGuard.
3 · You press one button — Run all checks — and read the colour of the answer.
Red means walk away.
PART 1
What is FlashGuard, and what is “One search”?
USDT (also called Tether) is digital money. One USDT is worth about one US dollar.
Because it moves fast and far, cheats love it. The most common trick is
“flash USDT” — fake money that appears in your wallet or in a screenshot,
looks completely real, and then vanishes or turns out to be worthless.
The cheat shows you this fake payment and asks you to send something real —
goods, cash, or a “small fee”.
FlashGuard is your verification counter. Think of it like the bank clerk who
holds a note up to the light. It does not touch your money. It cannot spend anything.
It only reads public records and tells you whether what you were shown is genuine.
“One search” is the first tab and the only one you need. The other tabs
(Transaction, Real balance, and so on) are single instruments. One search is the
full check-up: you put everything the other person gave you on the counter at once,
press one button, and every relevant test runs together. At the top you get
one verdict in one colour.
Comforting facts: FlashGuard never asks for your password, your secret words,
or any money. You cannot break anything by pressing the wrong button.
Boxes you leave empty are simply skipped.
PART 2
Opening the program and finding the tab
Open FlashGuard the way it was set up for you — usually a bookmark
or icon in Chrome (also fine: Brave, Edge or Firefox). If someone saved the file
index.html on your computer, double-clicking it opens it in the browser.
Across the top you will see a row of tabs, like the tabs of a file folder:
★ One search01 Transaction02 Real balance03 Token contract…
“One search” with the star ★ is the first one, top-left — and it is already
selected when the program opens. If you ever get lost in the other tabs,
click the star to come home.
Near the top of the page a small light tells you the network state.
Green (“Live nodes reachable”) means all is well. If you see a yellow warning that says
“Live checks are blocked in this preview”, it means FlashGuard was opened inside another
program's window — open it directly in Chrome instead.
PART 3
The only skill you need: copy and paste
Every code in this business is long and strange, like
TR7NHqjeKQxGTCi8q8ZY4pL8otSzgjLj6t.
Never type these by hand. One wrong letter ruins the check. Always copy and paste.
On a phone (WhatsApp, Telegram, any app)
Press your finger on the code and hold it there (one full second). The text turns
coloured / gets highlighted.
A small menu appears. Tap Copy. (For a link, the menu may say Copy link.)
Go to FlashGuard. Press and hold inside the box where the code should go.
Tap Paste. The code appears. Done.
On a computer
Click just before the code, hold the mouse button, and drag across it so it is highlighted
(or triple-click on it).
Press Ctrl and C together — that copies.
Click inside the FlashGuard box.
Press Ctrl and V together — that pastes.
Do not worry about tidiness. If extra spaces or line breaks come along
with the code, FlashGuard cleans them up by itself.
One caution about links: when a stranger sends a link, copy it without
opening it. On the phone: press and hold on the link, choose Copy. On the computer:
right-click the link and choose Copy link address. FlashGuard will inspect the link
for you — you never need to visit it yourself.
PART 4
A map of the One-search screen
This is what the tab looks like. The numbers in the green circles are mine —
we will go through them one by one in Part 5.
One search — run every check at once
Paste everything the other party gave you once… Fill only what you have; empty fields are skipped.
1
Network — leave on Auto if unsure
Auto — detect / hunt across all networks ▾
2
Expected amount in USDT — optional
e.g. 1500
3
Their address — the counterparty / wallet you’re checking
Link they sent — explorer, “proof”, or wallet download
https://… — checked against phishing lists & spoof tricks
Run all checksClear
Remember: you almost never fill all seven. Fill whatever the other
person gave you, leave the rest empty, and press Run all checks. The Clear button
wipes every box so you can start a fresh check.
PART 5
The seven boxes, one by one — and where to find what goes in them
① Network — which “rail” the money runs on
USDT travels on several different rails (called networks): Tron, Ethereum,
BNB Smart Chain, and others. Think of them as different railway lines carrying
the same currency.
If you are not sure, leave it on “Auto”. Auto makes FlashGuard hunt across
all the networks by itself. You lose nothing by leaving it on Auto.
How to know the network, if you want to set it: look for these short codes —
people write them everywhere:
If you see written…
Choose in the Network box
TRC20 or TRC-20 — the most common in scams
Tron · TRC-20
ERC20 or ERC-20
Ethereum · ERC-20
BEP20 or BSC
BNB Smart Chain · BEP-20
Polygon or MATIC
Polygon PoS
TON (Telegram wallets)
TON · Jetton
Where this word appears on common apps and websites
On the payment screenshot they sent — a line usually says Network: TRC20.
Binance app — on any Deposit or Withdraw screen there is a “Network” choice showing TRC20 / ERC20 / BEP20.
Trust Wallet — under the coin name it says e.g. “USDT TRC20” or “USDT BEP20”.
In the chat itself — senders often write “send me the TRC20 address”.
② Expected amount in USDT — how much they claim they paid
Just the number. If they say they paid 1,500 USDT, type 1500.
Plain digits — no commas, no ₹, no $ sign. For decimals use a dot: 1500.50.
Why it matters: a favourite trick is a real payment of a tiny amount
(say 1.5 USDT) shown quickly on a phone hoping you read it as 1,500. With the amount
filled in, FlashGuard compares the claim with the truth.
Optional — leave empty if no amount was claimed.
③ Their address — the stranger's wallet code
Every wallet has an address: one long code of letters and digits, like an account number.
This box takes the other person's address — the buyer, the “investment manager”,
the person asking you for a fee. What it looks like:
TR7NHqjeKQxGTCi8q8ZY4pL8otSzgjLj6t ← starts with T = Tron0xdAC17F958D2ee523a2206206994597C13D831ec7 ← starts with 0x = Ethereum / BNB / Polygon…
With their address, FlashGuard checks their real balance, whether Tether has
blacklisted them, whether security services have flagged them, and (on Tron)
whether their account keys look hijacked.
Where to find their address
WhatsApp / Telegram chat — it is the long code they pasted to you, usually with the words
“send here” or “this is my wallet”. Press-and-hold on it → Copy.
On their payment screenshot — the line marked From is their address.
On an explorer link they sent (tronscan.org, etherscan.io, bscscan.com) — open our Part 5 ⑦ warning first!
Better: paste the link in box ⑦ and paste the From code in this box only if you can already see it in the chat.
Binance P2P order page — the counterparty's wallet/account details shown on the order.
A QR code they sent — under or beside every wallet QR code the same address is printed as text. Copy the text, not the picture.
④ Your receiving address — your own wallet code
This is your address — where the money was supposed to arrive. It is optional,
but filling it unlocks the best checks: FlashGuard confirms the payment really came
to you (not to a look-alike of your address), and checks nobody has been given
permission to pull money out of your wallet.
Where to find your own address — pick the app you use
Trust Wallet: open the app → tap USDT in your coin list → tap Receive →
a QR code appears with your address under it → tap Copy.
Binance app: tap Wallet (bottom) → Deposit → choose USDT →
choose the network (e.g. TRC20) → your deposit address appears → tap the copy symbol ⧉.
TronLink: your address (starting with T) is at the top of the home screen — tap it once and it copies.
MetaMask: your address (starting with 0x) is under the account name at the top — tap it once and it copies.
Telegram Wallet: open the Wallet inside Telegram → USDT → Deposit / Receive → copy.
SafePal / other wallets: always the same idea — find the coin, press Receive, press Copy.
⑤ Transaction hash — the receipt number of the payment
Every payment on a blockchain gets a unique receipt number, called the
transaction hash (also written TxID, Txn Hash or Transaction ID).
When someone says “I have paid you, look!” — this number is the proof that can be
checked. A screenshot can be photoshopped; the hash cannot. What it looks like:
0x4f8a99… (66 characters starting 0x — Ethereum, BNB, Polygon…)d0e2b7c14a99… (64 characters, only 0–9 and a–f — Tron)
FlashGuard pulls the raw receipt from the public ledger and inspects the one thing
fakes cannot forge: which contract actually moved the money — the real Tether, or an imitation.
Where to find the hash
On the screenshot they sent — look for the line named TxID, Txn Hash,
Transaction ID or Hash. Ask them to send it as text so you can copy it:
“Please send me the TxID as text.” A genuine payer never refuses this.
Tronscan (tronscan.org) — on a transaction page the hash is the very long code at the
top, with a copy symbol ⧉ next to it.
Etherscan (etherscan.io) / BscScan (bscscan.com) — the line “Transaction Hash:” at the top of the page, copy symbol beside it.
Binance app (if you made the payment) — Wallet → Transaction History → tap the withdrawal → TxID → copy.
Trust Wallet — tap the coin → tap the payment in the list → the detail screen shows the hash (or a “view on explorer” button whose page shows it at the top).
If they only sent a link — you may simply paste the whole link into box ⑦ instead; if the link is genuine, the hash is the long code at its end.
⑥ Token contract — for mystery money that appeared out of nowhere
Sometimes thousands of “USDT” simply appear in your wallet, or a stranger
helps you “import” a token. Every token is issued by a contract — its passport.
Real USDT comes from exactly one contract per network (printed in Appendix B).
Fake USDT comes from an impostor contract that merely uses the same name and logo.
Paste the contract code of the suspicious token here and FlashGuard compares it with
the genuine one.
Where to find a token's contract code
Trust Wallet: tap the suspicious token in your list → tap its name / the ⓘ info symbol at the top →
the detail page shows Contract — a 0x… or T… code → copy.
MetaMask: tap the token → tap the three dots ⋮ → Token details → the contract address is shown → copy.
TronLink: tap the token → the details screen shows the contract (T…) → copy.
Tronscan / Etherscan: if you are viewing the token's page, the contract is shown under the token
name (and it is also the long code in the browser's address bar).
CoinMarketCap (coinmarketcap.com) — search “Tether”, and on the coin page the section
Contracts lists the real address for every network. Useful for comparing with your own eyes.
⑦ Link they sent — any website they want you to open
Cheats send links: a “payment proof” page, a look-alike of tronscan, a “wallet app to
download”, a “verification portal”. Some of these pages are perfect copies of real sites.
Do not open the link. Copy it and paste it here. (How to copy without opening:
Part 3, the red box.) FlashGuard checks it against phishing lists and spoofing tricks —
twin letters, hidden characters, fake subdomains, wrong endings like
tronscan-check.live instead of tronscan.org.
Where links hide
WhatsApp / Telegram / SMS message — press-and-hold on the link → Copy.
Email — on a computer, right-click the link → Copy link address. Never click it.
Inside a QR code they told you to scan — if scanning shows a website address, copy that address here instead of visiting it.
Two bonus checks run by themselves — you do nothing.
· If the two addresses (③ and ④) look suspiciously alike, FlashGuard runs the
address-poisoning test — a trick where a cheat manufactures an address almost identical to
yours, hoping you copy the wrong one from your own history.
· If you filled both addresses and chose a specific network in box ① (not Auto),
FlashGuard also audits spending approvals — whether their address holds a signed permission
to pull USDT out of your wallet.
PART 6
Pressing the button and reading the colours
When your boxes are filled, press Run all checks.
Wait a few seconds while FlashGuard questions the public ledgers. Then read the
top banner first — it is the summary verdict, and it comes in three colours:
⛔ DO NOT PROCEED
At least one check failed — a hard red flag straight from the public ledger.
Treat this as a scam until proven otherwise. No fee, no “one last step”,
no smooth explanation on the phone changes a failed check. Stop replying. Walk away.
⚠ CAUTION
No hard red flag, but something is unverified or unusual — perhaps the payment has
too few confirmations yet, or a check could not finish. Read each card below the
banner, and never hand over money or goods before a payment is fully confirmed on-chain.
✔ NO RED FLAGS
Everything you provided passed. This is not a guarantee of an honest person —
it means the data was genuine. Still follow the iron rules in Part 8, and never send
anything of value first.
Under the banner you will see a line — “Checks run (4): Transaction · Real balance ·
Token contract · Link” — listing what was tested, and a “Skipped” line listing what
could not run because its box was empty. Below that come the detailed cards, one per check,
each with its own small verdict. You do not have to understand every line in the cards —
the colours carry the message.
Small tip: pressing the Enter key inside any box does the same
as pressing “Run all checks”. And Clear empties every box for the next case.
PART 7
Three true-to-life stories, done step by step
Story 1 — “I have already paid you, brother”
You are selling something for the equivalent of 1,500 USDT. A buyer on WhatsApp
sends a payment screenshot: green tick, “1,500 USDT sent”, network TRC20, a TxID at
the bottom. He presses you to hand over the goods, or asks for a small “release fee”.
What you do: reply “please send the TxID as text”. Then fill:
① Network
Tron · TRC-20 (the screenshot said TRC20 — or just leave Auto)
② Amount
1500
③ Their address
the From code on the screenshot, or the wallet he shared in chat
④ Your address
your own — Trust Wallet → USDT → Receive → Copy
⑤ Hash
the TxID he sent as text
Press Run all checks. If the hash does not exist, or the “USDT” came from an
impostor contract, or the money went to a different address, or the amount is 1.5 not 1500 —
the banner turns red: DO NOT PROCEED. The screenshot was theatre.
Story 2 — money fell from the sky
You open your wallet and 50,000 “USDT” is sitting there from an unknown sender.
Soon a message arrives: “sent by mistake / pay 2% network charge to activate it”.
What you do: in Trust Wallet, tap the mystery token → tap the ⓘ info symbol →
copy the Contract code. Paste it into box ⑥ Token contract. Press Run.
Almost always the verdict is red: the token came from an impostor contract — it is
stage money, printed for free in any quantity. The 2% “charge” they want is the only real
money in the story: yours. Do not touch the token, do not pay, do not reply.
Story 3 — “check the proof yourself, here is the link”
A Telegram “trader” sends https://tronscan-verify.live/tx/… —
“see, the payment is right there on the blockchain!” The page looks exactly like tronscan.
What you do: do not open it. Press-and-hold the link → Copy → paste into
box ⑦ Link they sent → Run. FlashGuard recognises the address is a costume —
the real explorer is tronscan.org, and anything else showing you a “payment”
is showing you a stage set. Red banner, case closed.
PART 8
The six iron rules
A screenshot is not money. Only a checked transaction hash is proof, and FlashGuard checks it in seconds.
Real USDT never needs a fee to be “released”, “activated” or “unlocked”. Anyone asking for such a fee is the scam itself.
Never send anything of value first — not goods, not gift cards, not a “refundable deposit” — before FlashGuard shows the payment confirmed on-chain.
Copy, never type. And take the codes from the chat as text — a genuine payer will happily send the TxID as text.
Never open their links; paste them into FlashGuard instead. And never, ever tell anyone your 12 secret words. No support person, no bank, no police officer will ever need them.
Red banner = walk away. Do not argue, do not give a second chance, do not let them “explain”. Silence is the correct reply to a cheat.
APPENDIX A
Recognise a code by its shape
You will meet three kinds of codes. When unsure what something is, match its shape here:
The code looks like…
It is probably…
Goes into box
T + 33 more letters/digits (34 total)
A Tron wallet address
③ or ④
0x + 40 characters (42 total)
An Ethereum-family wallet address (also BNB, Polygon…)
③ or ④
0x + 64 characters (66 total)
A transaction hash (receipt number)
⑤
64 characters, only 0-9 a-f, no 0x
A Tron / TON transaction hash
⑤
EQ… or UQ…
A TON (Telegram) address
③ or ④
Ends in .near
A NEAR address / contract
③, ④ or ⑥
KT1… / tz1…
A Tezos contract / address
⑥ / ③ ④
o + about 50 characters
A Tezos transaction hash
⑤
Starts with https:// or www.
A link
⑦
A plain number like 312769 next to the word Algorand
An Algorand asset ID (token passport)
⑥
And if you guess wrong — nothing bad happens. FlashGuard tells you the format was not
recognised, and you try the other box.
APPENDIX B
The REAL USDT addresses — printed for your eyes
You never need to memorise or type these. FlashGuard already knows every one and
does the comparison for you. They are printed here for one reason only: so that you can
hold a suspicious contract next to the genuine article and see the difference with your
own eyes. Compare the first six and the last six characters — if either
differs, it is not Tether, whatever its name and logo say.
FlashGuard also knows the newer “USDT0” rails (Arbitrum, HyperEVM, Ink, Mantle,
Berachain, Flare, Sei, Unichain, Conflux, Hedera, X Layer and more) and checks them
automatically — you do not need their addresses on paper.
The last word. You do not need to understand blockchains, and you never will need to.
You only need three habits: copy what they send you, paste it into One search,
and obey the colour. Everything else is FlashGuard's job.