Stablecoins and Payments

Stablecoin Payment Security for Merchants

Security practices for merchants accepting stablecoin payments, covering receiving wallets, website integrity, fake payment proofs and incident response.

Shop counter behind a transparent shield with a coin resting safely

Accepting stablecoins removes some traditional payment risks, such as chargebacks, but introduces others. Merchants become responsible for protecting receiving wallets, verifying payments and defending their websites against tampering. A few security practices cover most of the risk.

Protect the receiving wallet

The receiving wallet accumulates revenue, so it deserves strong protection:

  • Use a hardware wallet or multisig for the receiving address
  • Never connect the receiving wallet to dApps or sign unknown messages with it
  • Move funds to treasury storage on a schedule
  • Keep seed phrase backups offline in secure locations
  • Limit who has access to signing devices

A receiving wallet should do one job: receive payments.

Protect the payment address display

Attackers who alter the address shown at checkout can redirect every payment. Protect the integrity of payment pages:

  1. Secure hosting, DNS and deployment accounts with strong authentication
  2. Serve payment pages over HTTPS with strict security headers
  3. Avoid loading third-party scripts on checkout pages
  4. Monitor pages for unexpected changes
  5. Publish the official receiving address in more than one place so customers can compare

If you use a payment address stored in configuration, protect that configuration like a password.

Verify payments on-chain

Never deliver based on screenshots or messages. Fraud attempts include:

Fraud type Defence
Edited screenshots of transactions Verify on the block explorer
Transaction hashes from other people's payments Check recipient, amount and timing
Fake tokens with real token names Check token contract addresses
Payments that later fail or disappear Wait for confirmations
Reused old transactions Record each payment reference and reject duplicates

Automated detection that checks token contracts, recipient, amount, confirmations and uniqueness handles most cases.

Beware of social engineering

Attackers target merchants directly:

  • Fake customers claiming overpayment and asking for refunds to a different address
  • Messages pretending to be from payment providers or exchanges
  • Requests to "verify" the business wallet on a website
  • Fake partnership offers containing malicious files

Handle refunds only after verifying the original payment and confirming the refund destination through trusted channels. Never sign messages or connect wallets in response to unsolicited requests.

Watch for address poisoning

Merchants who pay suppliers or refund customers from wallets with long transaction histories are targets for address poisoning. Use address books for regular recipients and never copy addresses from transaction history.

Protect staff and access

Limit who can access admin panels, wallets and payment configuration. Use strong authentication, remove access when staff leave and log administrative actions. Train staff to recognise phishing attempts.

Plan incident response

Prepare for problems before they happen:

  1. Suspected website tampering: take checkout offline, warn customers, investigate
  2. Compromised receiving wallet: move remaining funds, update payment address everywhere, notify customers
  3. Fraudulent refund request: document, refuse and review processes
  4. Payment detection failure: switch to manual verification and communicate delays

Write down steps and contacts, and review the plan periodically.

Review security every quarter

Set a recurring review of payment security. Check who has access to wallets and admin tools, confirm hardware wallets and backups are where they should be, review recent refunds and disputes for patterns and test the incident plan with a short tabletop exercise. Small, regular reviews catch drift, such as a former contractor who still has access, before it turns into a loss.

Give customers ways to verify

Customers are part of your security. Encourage them to check the receiving address on the checkout page against another official source and to contact you through official channels if anything looks wrong. Proud Globe shows its full receiving address on every order page, and the same site lists its terms and contact options, so buyers can confirm details before paying.

Educational content only. Nothing here is financial, legal or tax advice. Crypto assets carry risk, so check the details for your own situation.