Impersonator Tokens: Fake USDT, PEPE, and Look-Alikes
Scam tokens copy famous names but deploy at a different contract address. Real flagged examples of fake USDT and PEPE, and how to verify the address before you trust the name.
One of the simplest and most effective crypto traps needs no exotic code: just a famous name. Impersonator tokens copy the name and symbol of a well-known project — Tether, PEPE, a trending meme, a public figure's "new coin" — and deploy them at a different contract address than the real thing. The name does the marketing; the address is where the truth lives.
Why the name means nothing
On every chain, a token's real identity is its contract (or mint) address, not its name or symbol. Those are just labels, and anyone can set them to anything. Two completely unrelated contracts can both call themselves "USDT." So the single most important habit in crypto is also the most boring: verify the exact address from an official source before you interact, and never trust a name, logo, or ticker on its own.
This is not a hypothetical. It is one of the most common shapes of scam token in circulation.
Real examples from Orixa's flagged report
The following are entries from Orixa's public Tokens Flagged as Very High Risk report — a live list generated only from stored scan decisions. (As recorded in that report from scans dated 7–12 August 2026, captured 2026-08-21. A high-risk classification reflects on-chain and simulation evidence at scan time; it is not, by itself, proof of anyone's intent, and it does not implicate the genuine projects whose names were copied.)
- A token labeled "Tether USD (USDT)" at
0x1395…9008on Ethereum. This is not Tether's canonical USDT contract (0xdAC1…1ec7). Orixa flagged it at 100/100 with a sell-simulation honeypot flag and a single wallet holding effectively the entire supply — behavior the real, widely-held USDT does not exhibit. - A token labeled "Pepe (PEPE)" at
0x25d8…bb00on BNB Chain. The well-known PEPE is an Ethereum token at a different address; a BSC token reusing the name is a separate contract. Orixa flagged it high-risk with a sell-simulation honeypot flag and removable owner-controlled liquidity. - Persona and meme look-alikes — entries like "Coinbase Man," "Vitalik's New Dog," and "Ethereum's New Mascot" ride recognizable names and narratives. Each was flagged 100/100 with a honeypot flag and near-total holder concentration.
These are flags, not verdicts — a high-risk or honeypot flag is evidence at scan time, not proof of fraud, and scanners can misfire, so verify independently. But the underlying pattern is consistent and easy to check for yourself: a borrowed famous name deployed at a fresh, unrelated contract address.
How to spot an impersonator
- Get the address from an official source — the project's verified site or docs, a reputable data aggregator — not from a chat, reply, ad, or search result you can't vouch for.
- Confirm the chain. A "USDT" or "PEPE" on a chain where the real token doesn't primarily live is an immediate flag.
- Compare the address character-by-character. Attackers use visually similar or vanity addresses; a quick glance is not enough.
- Check supply and holders. A "stablecoin" with one wallet holding all supply, or a token with almost no real liquidity, contradicts the identity it's claiming.
- Run a scan. A sell simulation and contract review will usually surface the risk regardless of the name on the label.
Why address verification is the whole game
Every other check you do — sell simulation, liquidity, owner powers, holder concentration — is only meaningful if you're analyzing the right contract. Verifying the address first is what makes the rest trustworthy. For the full pre-purchase routine, see How to Identify a High-Risk Crypto Token Before Buying; for the exit-blocking mechanic these tokens often use, see What Is a Honeypot Crypto Token.
A note on caution the other way: a scanner flagging a token that shares a famous name does not mean the genuine project is implicated — it means that specific address was flagged. Always read the address, not just the label.
Paste a contract address into Orixa to check whether it's a honeypot and how its supply and liquidity are structured — then confirm the address itself against an official source before you trust the name. Orixa is decision support, not financial advice.
Enter a contract address and review the available risk evidence.
Orixa provides risk-analysis tools, not financial advice or a safety guarantee. Always verify evidence independently before interacting with a token.