Counterfeit Token
Pronunciation: KOWN-tur-fit TOH-kun
Definition
A Counterfeit Token is a blockchain token created or presented to imitate another asset, project, brand, stablecoin, or official contract without authorization. A similar name or symbol does not establish identity because tokens on the same or different networks can share metadata. Users and systems should verify contract address, network, issuer source, decimals, code and proxy status, liquidity, holder distribution, and official announcements, while interfaces should avoid trusting logos or ticker symbols alone.
Overview
A Counterfeit Token is a blockchain token created or presented to imitate another asset, project, brand, stablecoin, or official contract without authorization. The control exists to reduce technical, fraud, and financial risk arising from blockchain transactions, signatures, smart contracts, clients, bridges, wallets, and public transaction data. A similar name or symbol does not establish identity because tokens on the same or different networks can share metadata. It should be interpreted alongside Contract Verification because the concepts can affect the same decision without representing the same control, event, or risk.
The workflow identifies the exact network, contract, implementation, message, signer, asset, dependency, and expected state transition. Systems should verify domain and chain context, authoritative addresses, signatures, nonces, code or client versions, confirmations, and the difference between observable data and inferred ownership. In this context, users and systems should verify contract address, network, issuer source, decimals, code and proxy status, liquidity, holder distribution, and official announcements, while interfaces should avoid trusting logos or ticker symbols alone.
It should connect the term to Address Validation where that relationship changes access, transaction treatment, investigation, communication, or recovery.
Records should retain transaction and block identifiers, contract addresses, network and chain ID, decoded input, signer, signature domain, client version, timestamps, confirmations, attribution source, alerts, decisions, and resulting state. Reorganizations, bridges, proxies, and off-chain dependencies require explicit treatment.
Useful measures include affected value, suspicious exposure, signature warnings, replay or duplicate attempts, client concentration, failed validation, contract mismatches, investigation time, unresolved attribution, and recovery outcomes.
The relationship with Approval Phishing should be documented where it affects residual risk or control ownership.
Key Takeaway
Users and systems should verify contract address, network, issuer source, decimals, code and proxy status, liquidity, holder distribution, and official announcements, while interfaces should avoid trusting logos or ticker symbols alone.
Sources
- Updated Guidance for a Risk-Based Approach to Virtual Assets and VASPs — FATF (2026-08-03)
- Ethereum Security and Scam Prevention — Ethereum Foundation (2026-08-03)
- Security and Privacy Controls for Information Systems and Organizations, SP 800-53 Rev. 5 — NIST (2026-08-03)