Start with the payment, not the suspicion
A customer says they paid an invoice in USDT on TRON. The amount appears in your wallet, but the sender address is unfamiliar and the transfer does not fit the expected payment pattern. The safest first move is not to label the customer or return the funds. It is to establish exactly what happened onchain, preserve the evidence, and separate verified facts from risk signals.
This guide presents a practical review for a business receiving USDT as a TRC20 token. The example is fictional. An address mentioned in a real investigation should never be described as criminal without reliable evidence and appropriate legal grounds.
First, preserve the transaction record
Before releasing goods, crediting an account, converting the funds, or sending a refund, save the information needed to reconstruct the event:
- the complete transaction hash;
- the full sending and receiving addresses;
- the network and token selected by your payment system;
- the amount and the time received;
- the invoice, order, customer reference, and stated purpose;
- relevant messages and any request to change payment or refund instructions.
Copy values as text where possible. Screenshots are useful context, but they are harder to search and can omit the middle of an address. If the concern arose after settlement, follow the more time sensitive steps in the first hour after a suspicious crypto payment.
Verify that it is the payment you think it is
1. Confirm the network and transaction status
Open the transaction hash in a trusted TRON explorer and confirm that the transaction succeeded. A submitted hash, a pending notification, or a wallet screenshot does not prove that the token transfer completed. TRON documentation advises checking the transaction information and successful receipt result when processing TRC20 deposits.
2. Verify the token contract, not only the ticker
A token can display the symbol USDT without being the official Tether token. Tether’s supported protocols page lists the USD₮ contract on TRON as TR7NHqjeKQxGTCi8q8ZY4pL8otSzgjLj6t. Compare the contract shown for the transfer with the current official source. Do not rely only on the token name, icon, or a link supplied by the payer.
3. Match the transfer event to your records
TRC20 tokens are smart contract assets. The TRC20 standard uses a Transfer event to record the token sender, recipient, and value. Confirm that your receiving address appears in the relevant transfer event and that the amount matches the invoice after applying the token decimals.
One outer transaction can contain several contract events. Focus on the USDT transfer that actually credits your address. Record the token sender shown in that event, the receiving address, the amount, the block time, and confirmation status. This prevents an unrelated event in the same transaction from becoming the basis of the review.
Then investigate the source and risk context
4. Run the correct Farona check
In Farona, open New check, choose Transaction Check, select TRON and USDT, and paste the complete transaction hash. Add the invoice or case reference in the note so another reviewer can understand why the check was created.
The report confirms the available transaction details and assesses the sender wallet. This sender result is not a complete legal or factual judgment about the transfer itself. It does not prove who controls the wallet or why the payment was made.
5. Read the report in the right order
- Confirm the transaction fields: Compare hash, network, token, amount, sender, receiver, onchain status, and block information with your saved record.
- Read the Farona level and verdict: Use them to set review priority, not as an automatic acceptance or rejection rule.
- Examine the strongest evidence: Identify the risk type, direction of funds, confidence of attribution, and whether the connection is direct or indirect.
- Assess materiality: Consider the relevant value, activity share, transaction distance, timing, and whether several independent signals support the same concern.
- Open more detail only when needed: Wallet overview, address labels, address actions, address profile, counterparties, and transaction flows should answer a defined question.
The Farona report reading guide explains how to interpret level, evidence, proximity, and materiality without turning a signal into a conclusion it cannot support.
6. Compare blockchain evidence with the customer story
Ask whether the payment fits the invoice, expected amount, customer profile, and previously agreed wallet or payment channel. If something does not fit, request focused evidence. Useful material may include an exchange withdrawal record, an earlier transaction hash, proof that the customer controls the sending wallet, or authorization for a related company to pay.
A document is useful only if it connects to the transaction. Check names, addresses, asset, network, amount, and time. A generic account screenshot does not resolve a mismatch involving a different wallet.
A fictional case shows how the evidence fits together
A software company expects 8,400 USDT on TRON from a corporate customer. The payment arrives from a new address. The transaction is successful, the official USDT contract is present, and the correct receiving address is credited.
The Farona report gives the sender wallet a result that requires closer review under the company’s policy. The customer then says a business partner paid on its behalf and asks that any refund be sent to a third address. None of these facts alone proves wrongdoing, but together they create unresolved questions about control, source, and refund destination.
The team pauses service activation, preserves the hash and messages, requests evidence of the relationship and payment authority, and screens the proposed refund destination before any outgoing transfer. This final step follows the principle in screening the destination before sending crypto. The reviewer records the evidence and escalates the case according to policy. The file describes the observed facts and avoids calling any address criminal.
Choose the next action proportionately
- Continue: Transaction facts match, risk signals are within policy, and the customer explanation is supported.
- Request clarification: The payment is technically valid, but ownership, source, amount, or purpose remains unclear.
- Pause and escalate: Material risk evidence, contradictory documents, a third party payment, pressure to bypass review, or several aligned red flags remain unresolved.
- Reject or restrict: Take this step only under the rules and authority that apply to your business. Obtain specialist advice where required.
Do not automatically refund suspicious funds to a new address supplied in a message. A refund is another outgoing transaction and needs verified instructions, destination screening, internal approval, and any legally required escalation.
Common mistakes to avoid
- checking the sender address but not confirming the transaction hash;
- trusting the USDT symbol without verifying the token contract;
- confusing a successful transfer with a low risk source;
- treating distant indirect exposure as if it were a direct payment;
- relying on a screenshot instead of complete onchain identifiers;
- sending a refund before verifying the destination and authority;
- recording a score without recording the evidence and decision.
Where Farona helps
Farona brings the transaction facts and sender wallet risk evidence into a structured investigation. It provides a Farona score, Farona level, plain language verdict, and supporting detail for a documented human review. It does not establish legal ownership, certify that funds are lawful, or replace customer due diligence, sanctions controls, an AML program, or qualified advice.
The practical goal is to make the decision reproducible. Another reviewer should be able to see what was received, what was checked, which questions remained, and why the business continued, paused, or escalated.
Sources and further reading
- Tether: Supported protocols and official contract addresses
- TRON Developer Hub: TRC20 protocol interface
- TRON Developer Hub: Exchange and wallet integration guidance
- FATF: Targeted report on stablecoins and unhosted wallet transactions
- United States Department of Justice: 2026 Tether seizure following blockchain tracing
Sources were checked on 8 September 2026. This article provides general information and is not legal advice. Procedures and obligations vary by jurisdiction, regulatory status, and business model.





