← FLASHGUARD ⤓ Download the PDF
FlashGuard · USDT Safety Checker

The “One Search” Tab
— a manual in plain words —

Written for people who do not do computers.
If you can use WhatsApp, you can use this.
The whole manual in three lines:
1 · Someone sends you codes, screenshots or links about a USDT payment.
2 · You copy each thing they sent and paste it into the matching box in FlashGuard.
3 · You press one button — Run all checks — and read the colour of the answer. Red means walk away.
PART 1

What is FlashGuard, and what is “One search”?

USDT (also called Tether) is digital money. One USDT is worth about one US dollar. Because it moves fast and far, cheats love it. The most common trick is “flash USDT” — fake money that appears in your wallet or in a screenshot, looks completely real, and then vanishes or turns out to be worthless. The cheat shows you this fake payment and asks you to send something real — goods, cash, or a “small fee”.

FlashGuard is your verification counter. Think of it like the bank clerk who holds a note up to the light. It does not touch your money. It cannot spend anything. It only reads public records and tells you whether what you were shown is genuine.

“One search” is the first tab and the only one you need. The other tabs (Transaction, Real balance, and so on) are single instruments. One search is the full check-up: you put everything the other person gave you on the counter at once, press one button, and every relevant test runs together. At the top you get one verdict in one colour.

Comforting facts: FlashGuard never asks for your password, your secret words, or any money. You cannot break anything by pressing the wrong button. Boxes you leave empty are simply skipped.
PART 2

Opening the program and finding the tab

  1. Open FlashGuard the way it was set up for you — usually a bookmark or icon in Chrome (also fine: Brave, Edge or Firefox). If someone saved the file index.html on your computer, double-clicking it opens it in the browser.
  2. Across the top you will see a row of tabs, like the tabs of a file folder:
    ★ One search 01 Transaction 02 Real balance 03 Token contract
    “One search” with the star ★ is the first one, top-left — and it is already selected when the program opens. If you ever get lost in the other tabs, click the star to come home.
  3. Near the top of the page a small light tells you the network state. Green (“Live nodes reachable”) means all is well. If you see a yellow warning that says “Live checks are blocked in this preview”, it means FlashGuard was opened inside another program's window — open it directly in Chrome instead.
PART 3

The only skill you need: copy and paste

Every code in this business is long and strange, like TR7NHqjeKQxGTCi8q8ZY4pL8otSzgjLj6t. Never type these by hand. One wrong letter ruins the check. Always copy and paste.

On a phone (WhatsApp, Telegram, any app)

  1. Press your finger on the code and hold it there (one full second). The text turns coloured / gets highlighted.
  2. A small menu appears. Tap Copy. (For a link, the menu may say Copy link.)
  3. Go to FlashGuard. Press and hold inside the box where the code should go.
  4. Tap Paste. The code appears. Done.

On a computer

  1. Click just before the code, hold the mouse button, and drag across it so it is highlighted (or triple-click on it).
  2. Press Ctrl and C together — that copies.
  3. Click inside the FlashGuard box.
  4. Press Ctrl and V together — that pastes.
Do not worry about tidiness. If extra spaces or line breaks come along with the code, FlashGuard cleans them up by itself.
One caution about links: when a stranger sends a link, copy it without opening it. On the phone: press and hold on the link, choose Copy. On the computer: right-click the link and choose Copy link address. FlashGuard will inspect the link for you — you never need to visit it yourself.
PART 4

A map of the One-search screen

This is what the tab looks like. The numbers in the green circles are mine — we will go through them one by one in Part 5.

One search — run every check at once
Paste everything the other party gave you once… Fill only what you have; empty fields are skipped.
1
Network — leave on Auto if unsure
Auto — detect / hunt across all networks  ▾
2
Expected amount in USDT — optional
e.g. 1500
3
Their address — the counterparty / wallet you’re checking
0x… · T… · Solana — runs balance, blacklist, permission audit
4
Your receiving address — optional
Yours — enables recipient, twin & approval checks
5
Transaction hash — their “payment proof”
0x… (EVM/Aptos) · 64-hex (Tron/TON/Liquid) · base58 (NEAR) · o… (Tezos)
6
Token contract — a mystery “USDT” that appeared
0x… or T… — checks it against the real USDT
7
Link they sent — explorer, “proof”, or wallet download
https://… — checked against phishing lists & spoof tricks
Run all checks Clear
Remember: you almost never fill all seven. Fill whatever the other person gave you, leave the rest empty, and press Run all checks. The Clear button wipes every box so you can start a fresh check.
PART 5

The seven boxes, one by one — and where to find what goes in them

① Network — which “rail” the money runs on

USDT travels on several different rails (called networks): Tron, Ethereum, BNB Smart Chain, and others. Think of them as different railway lines carrying the same currency.

If you are not sure, leave it on “Auto”. Auto makes FlashGuard hunt across all the networks by itself. You lose nothing by leaving it on Auto.

How to know the network, if you want to set it: look for these short codes — people write them everywhere:

If you see written…Choose in the Network box
TRC20 or TRC-20the most common in scamsTron · TRC-20
ERC20 or ERC-20Ethereum · ERC-20
BEP20 or BSCBNB Smart Chain · BEP-20
Polygon or MATICPolygon PoS
TON (Telegram wallets)TON · Jetton
Where this word appears on common apps and websites
  1. On the payment screenshot they sent — a line usually says Network: TRC20.
  2. Binance app — on any Deposit or Withdraw screen there is a “Network” choice showing TRC20 / ERC20 / BEP20.
  3. Trust Wallet — under the coin name it says e.g. “USDT TRC20” or “USDT BEP20”.
  4. In the chat itself — senders often write “send me the TRC20 address”.

② Expected amount in USDT — how much they claim they paid

Just the number. If they say they paid 1,500 USDT, type 1500. Plain digits — no commas, no ₹, no $ sign. For decimals use a dot: 1500.50.

Why it matters: a favourite trick is a real payment of a tiny amount (say 1.5 USDT) shown quickly on a phone hoping you read it as 1,500. With the amount filled in, FlashGuard compares the claim with the truth.

Optional — leave empty if no amount was claimed.

③ Their address — the stranger's wallet code

Every wallet has an address: one long code of letters and digits, like an account number. This box takes the other person's address — the buyer, the “investment manager”, the person asking you for a fee. What it looks like:

TR7NHqjeKQxGTCi8q8ZY4pL8otSzgjLj6t   ← starts with T = Tron 0xdAC17F958D2ee523a2206206994597C13D831ec7   ← starts with 0x = Ethereum / BNB / Polygon…

With their address, FlashGuard checks their real balance, whether Tether has blacklisted them, whether security services have flagged them, and (on Tron) whether their account keys look hijacked.

Where to find their address
  1. WhatsApp / Telegram chat — it is the long code they pasted to you, usually with the words “send here” or “this is my wallet”. Press-and-hold on it → Copy.
  2. On their payment screenshot — the line marked From is their address.
  3. On an explorer link they sent (tronscan.org, etherscan.io, bscscan.com) — open our Part 5 ⑦ warning first! Better: paste the link in box ⑦ and paste the From code in this box only if you can already see it in the chat.
  4. Binance P2P order page — the counterparty's wallet/account details shown on the order.
  5. A QR code they sent — under or beside every wallet QR code the same address is printed as text. Copy the text, not the picture.

④ Your receiving address — your own wallet code

This is your address — where the money was supposed to arrive. It is optional, but filling it unlocks the best checks: FlashGuard confirms the payment really came to you (not to a look-alike of your address), and checks nobody has been given permission to pull money out of your wallet.

Where to find your own address — pick the app you use
  1. Trust Wallet: open the app → tap USDT in your coin list → tap Receive → a QR code appears with your address under it → tap Copy.
  2. Binance app: tap Wallet (bottom) → Deposit → choose USDT → choose the network (e.g. TRC20) → your deposit address appears → tap the copy symbol ⧉.
  3. TronLink: your address (starting with T) is at the top of the home screen — tap it once and it copies.
  4. MetaMask: your address (starting with 0x) is under the account name at the top — tap it once and it copies.
  5. Telegram Wallet: open the Wallet inside Telegram → USDT → Deposit / Receive → copy.
  6. SafePal / other wallets: always the same idea — find the coin, press Receive, press Copy.

⑤ Transaction hash — the receipt number of the payment

Every payment on a blockchain gets a unique receipt number, called the transaction hash (also written TxID, Txn Hash or Transaction ID). When someone says “I have paid you, look!” — this number is the proof that can be checked. A screenshot can be photoshopped; the hash cannot. What it looks like:

0x4f8a99… (66 characters starting 0x — Ethereum, BNB, Polygon…) d0e2b7c14a99… (64 characters, only 0–9 and a–f — Tron)

FlashGuard pulls the raw receipt from the public ledger and inspects the one thing fakes cannot forge: which contract actually moved the money — the real Tether, or an imitation.

Where to find the hash
  1. On the screenshot they sent — look for the line named TxID, Txn Hash, Transaction ID or Hash. Ask them to send it as text so you can copy it: “Please send me the TxID as text.” A genuine payer never refuses this.
  2. Tronscan (tronscan.org) — on a transaction page the hash is the very long code at the top, with a copy symbol ⧉ next to it.
  3. Etherscan (etherscan.io) / BscScan (bscscan.com) — the line “Transaction Hash:” at the top of the page, copy symbol beside it.
  4. Binance app (if you made the payment) — Wallet → Transaction History → tap the withdrawal → TxID → copy.
  5. Trust Wallet — tap the coin → tap the payment in the list → the detail screen shows the hash (or a “view on explorer” button whose page shows it at the top).
  6. If they only sent a link — you may simply paste the whole link into box ⑦ instead; if the link is genuine, the hash is the long code at its end.

⑥ Token contract — for mystery money that appeared out of nowhere

Sometimes thousands of “USDT” simply appear in your wallet, or a stranger helps you “import” a token. Every token is issued by a contract — its passport. Real USDT comes from exactly one contract per network (printed in Appendix B). Fake USDT comes from an impostor contract that merely uses the same name and logo. Paste the contract code of the suspicious token here and FlashGuard compares it with the genuine one.

Where to find a token's contract code
  1. Trust Wallet: tap the suspicious token in your list → tap its name / the ⓘ info symbol at the top → the detail page shows Contract — a 0x… or T… code → copy.
  2. MetaMask: tap the token → tap the three dots ⋮ → Token details → the contract address is shown → copy.
  3. TronLink: tap the token → the details screen shows the contract (T…) → copy.
  4. Tronscan / Etherscan: if you are viewing the token's page, the contract is shown under the token name (and it is also the long code in the browser's address bar).
  5. CoinMarketCap (coinmarketcap.com) — search “Tether”, and on the coin page the section Contracts lists the real address for every network. Useful for comparing with your own eyes.

⑦ Link they sent — any website they want you to open

Cheats send links: a “payment proof” page, a look-alike of tronscan, a “wallet app to download”, a “verification portal”. Some of these pages are perfect copies of real sites. Do not open the link. Copy it and paste it here. (How to copy without opening: Part 3, the red box.) FlashGuard checks it against phishing lists and spoofing tricks — twin letters, hidden characters, fake subdomains, wrong endings like tronscan-check.live instead of tronscan.org.

Where links hide
  1. WhatsApp / Telegram / SMS message — press-and-hold on the link → Copy.
  2. Email — on a computer, right-click the link → Copy link address. Never click it.
  3. Inside a QR code they told you to scan — if scanning shows a website address, copy that address here instead of visiting it.
Two bonus checks run by themselves — you do nothing.
· If the two addresses (③ and ④) look suspiciously alike, FlashGuard runs the address-poisoning test — a trick where a cheat manufactures an address almost identical to yours, hoping you copy the wrong one from your own history.
· If you filled both addresses and chose a specific network in box ① (not Auto), FlashGuard also audits spending approvals — whether their address holds a signed permission to pull USDT out of your wallet.
PART 6

Pressing the button and reading the colours

When your boxes are filled, press Run all checks. Wait a few seconds while FlashGuard questions the public ledgers. Then read the top banner first — it is the summary verdict, and it comes in three colours:

⛔ DO NOT PROCEED
At least one check failed — a hard red flag straight from the public ledger. Treat this as a scam until proven otherwise. No fee, no “one last step”, no smooth explanation on the phone changes a failed check. Stop replying. Walk away.
⚠ CAUTION
No hard red flag, but something is unverified or unusual — perhaps the payment has too few confirmations yet, or a check could not finish. Read each card below the banner, and never hand over money or goods before a payment is fully confirmed on-chain.
✔ NO RED FLAGS
Everything you provided passed. This is not a guarantee of an honest person — it means the data was genuine. Still follow the iron rules in Part 8, and never send anything of value first.

Under the banner you will see a line — “Checks run (4): Transaction · Real balance · Token contract · Link” — listing what was tested, and a “Skipped” line listing what could not run because its box was empty. Below that come the detailed cards, one per check, each with its own small verdict. You do not have to understand every line in the cards — the colours carry the message.

Small tip: pressing the Enter key inside any box does the same as pressing “Run all checks”. And Clear empties every box for the next case.
PART 7

Three true-to-life stories, done step by step

Story 1 — “I have already paid you, brother”

You are selling something for the equivalent of 1,500 USDT. A buyer on WhatsApp sends a payment screenshot: green tick, “1,500 USDT sent”, network TRC20, a TxID at the bottom. He presses you to hand over the goods, or asks for a small “release fee”.

What you do: reply “please send the TxID as text”. Then fill:

① NetworkTron · TRC-20 (the screenshot said TRC20 — or just leave Auto)
② Amount1500
③ Their addressthe From code on the screenshot, or the wallet he shared in chat
④ Your addressyour own — Trust Wallet → USDT → Receive → Copy
⑤ Hashthe TxID he sent as text

Press Run all checks. If the hash does not exist, or the “USDT” came from an impostor contract, or the money went to a different address, or the amount is 1.5 not 1500 — the banner turns red: DO NOT PROCEED. The screenshot was theatre.

Story 2 — money fell from the sky

You open your wallet and 50,000 “USDT” is sitting there from an unknown sender. Soon a message arrives: “sent by mistake / pay 2% network charge to activate it”.

What you do: in Trust Wallet, tap the mystery token → tap the ⓘ info symbol → copy the Contract code. Paste it into box ⑥ Token contract. Press Run.

Almost always the verdict is red: the token came from an impostor contract — it is stage money, printed for free in any quantity. The 2% “charge” they want is the only real money in the story: yours. Do not touch the token, do not pay, do not reply.

Story 3 — “check the proof yourself, here is the link”

A Telegram “trader” sends https://tronscan-verify.live/tx/… — “see, the payment is right there on the blockchain!” The page looks exactly like tronscan.

What you do: do not open it. Press-and-hold the link → Copy → paste into box ⑦ Link they sent → Run. FlashGuard recognises the address is a costume — the real explorer is tronscan.org, and anything else showing you a “payment” is showing you a stage set. Red banner, case closed.

PART 8

The six iron rules

  1. A screenshot is not money. Only a checked transaction hash is proof, and FlashGuard checks it in seconds.
  2. Real USDT never needs a fee to be “released”, “activated” or “unlocked”. Anyone asking for such a fee is the scam itself.
  3. Never send anything of value first — not goods, not gift cards, not a “refundable deposit” — before FlashGuard shows the payment confirmed on-chain.
  4. Copy, never type. And take the codes from the chat as text — a genuine payer will happily send the TxID as text.
  5. Never open their links; paste them into FlashGuard instead. And never, ever tell anyone your 12 secret words. No support person, no bank, no police officer will ever need them.
  6. Red banner = walk away. Do not argue, do not give a second chance, do not let them “explain”. Silence is the correct reply to a cheat.
APPENDIX A

Recognise a code by its shape

You will meet three kinds of codes. When unsure what something is, match its shape here:

The code looks like…It is probably…Goes into box
T + 33 more letters/digits (34 total)A Tron wallet address③ or ④
0x + 40 characters (42 total)An Ethereum-family wallet address (also BNB, Polygon…)③ or ④
0x + 64 characters (66 total)A transaction hash (receipt number)
64 characters, only 0-9 a-f, no 0xA Tron / TON transaction hash
EQ… or UQ…A TON (Telegram) address③ or ④
Ends in .nearA NEAR address / contract③, ④ or ⑥
KT1… / tz1…A Tezos contract / address⑥ / ③ ④
o + about 50 charactersA Tezos transaction hash
Starts with https:// or www.A link
A plain number like 312769 next to the word AlgorandAn Algorand asset ID (token passport)

And if you guess wrong — nothing bad happens. FlashGuard tells you the format was not recognised, and you try the other box.

APPENDIX B

The REAL USDT addresses — printed for your eyes

You never need to memorise or type these. FlashGuard already knows every one and does the comparison for you. They are printed here for one reason only: so that you can hold a suspicious contract next to the genuine article and see the difference with your own eyes. Compare the first six and the last six characters — if either differs, it is not Tether, whatever its name and logo say.

NetworkThe one and only genuine USDT contract
Tron (TRC-20) — most scams live hereTR7NHqjeKQxGTCi8q8ZY4pL8otSzgjLj6t
Ethereum (ERC-20)0xdAC17F958D2ee523a2206206994597C13D831ec7
BNB Smart Chain (BEP-20)0x55d398326f99059fF775485246999027B3197955
Polygon PoS0xc2132D05D31c914a87C6611C10748AEb04B58e8F
SolanaEs9vMFrzaCERmJfrF4H2FYD4KCoNkY11McCe8BenwNYB
TON (Telegram wallets)EQCxE6mUtQJKFnGfaROTKOt1lZbDiiX1kCixRv7Nw2Id_sDs
Arbitrum One0xFd086bC7CD5C481DCC9C85ebE478A1C0b69FCbb9
OP Mainnet (Optimism)0x94b008aA00579c1307B0EF2c499aD98a8ce58e58
Avalanche C-Chain0x9702230A8Ea53601f5cD2dc00fDBc13d4dF4A8c7
NEARusdt.tether-token.near
Aptos0x357b0b74bc833e95a115ad22604854d6b0fca151cecd94111770e5d6ffc9dc2b
Tezos (FA2)KT1XnTn74bUtxHfDtBmm2bGZAQfhPbvKWR8o
AlgorandAsset ID 312769
Polkadot Asset HubAsset ID 1984

FlashGuard also knows the newer “USDT0” rails (Arbitrum, HyperEVM, Ink, Mantle, Berachain, Flare, Sei, Unichain, Conflux, Hedera, X Layer and more) and checks them automatically — you do not need their addresses on paper.

The last word. You do not need to understand blockchains, and you never will need to. You only need three habits: copy what they send you, paste it into One search, and obey the colour. Everything else is FlashGuard's job.