Seed Phishing Drain vs Issuer Freeze: How to Tell Them Apart
If the official flag is true and the balance is still there, it is an issuer freeze. If the flag is false and the tokens left with a signature or allowance, it is a drain.

Support queues mix three failures into one word: “frozen.” Sometimes Tether or Circle actually set a restriction flag. Sometimes an exchange held a ledger. Sometimes the user signed a phishing drain and the tokens left. Treating a drained seed as an issuer freeze burns days on the wrong desk. This post is how to tell them apart. Glossary owner for the drain typology is phishing address. Issuer freeze still lives on can Tether freeze USDT and exchange hold vs issuer blacklist.
Educational only. Not legal advice. Not a recovery service. Not instructions to phish, drain, or evade issuer or venue controls. If you are a victim, use official issuer/exchange/law-enforcement channels; FBI IC3 publishes victim guidance for crypto scams.

Check a wallet before you act
Run a FreezeRadar scan for issuer-freeze signals, sanctions exposure, counterparty risk, and freezeable asset sensitivity before moving funds.
Direct answer
An issuer freeze leaves a visible token balance that will not transfer; the official contract says the address is restricted (isBlackListed / isBlacklisted / Paxos frozen / Solana token-account frozen). A venue hold leaves on-chain balances transferable (or sitting on an omnibus you do not control) while the exchange app refuses credit or withdrawal. A seed/phishing drain moves tokens out with the victim’s signature or a malicious allowance; the issuer flag is often still false and the balance is gone. Read the contract flag, then the last outbound hash, then the venue. Do not open a Tether unfreeze ticket for a drain. Do not tell a frozen address to “revoke approvals” as if that clears addBlackList.
Who owns which query
| Question | Owner page |
|---|---|
| What a phishing/drainer address is | Glossary: phishing address |
| Issuer USDT freeze functions | Can Tether freeze USDT? |
| Venue vs issuer | Exchange hold vs issuer blacklist |
| First-hour IR if they received frozen USDT | Received frozen USDT desk IR |
| Tell-apart playbook | This post |
Do not publish a competing /guides landing for this distinction.
Three planes, three observables
| Plane | Balance on official token | Official restriction flag | Typical user story |
|---|---|---|---|
| Issuer freeze | Still there (unless later destroyed/wiped) | True | “Send failed / transfer reverted” |
| Venue hold | On-chain may be fine; app is not | False on issuer contract | “Withdrawal pending / deposit credited then reversed” |
| Phishing / seed drain | Dropped; tokens at another address | Usually false | “My USDT disappeared” / “I connected to a site” |
USDT destroy (destroyBlackFunds) is a fourth state: flag was true, then balance burned. That is still issuer, not phishing. See blacklist vs destroy.
Solana: a frozen token account can look like “I can’t send USDC” with balance still showing. That is mint freeze authority, not a drain. If the ATA is empty and initialized (not frozen), look at outbound signatures. Token-2022 permanent delegate can move funds without a holder signature — that is issuer/mint clawback, not a seed phish (Token-2022). Do not call a permanent-delegate move “I got hacked” until you read the mint.
Five-minute triage
- Which asset and chain? Official contract from contracts. Fake USDT with the same ticker is a token-authenticity problem (verify payment logic), not Tether.
- Restriction flag now. Read USDT yourself or the matching USDC/PAXG/XAUt getter. True → issuer path. Stop drain theatre.
- Balance vs last week. Explorer token balance. If it went to zero and flag is false, you need the outbound transfer(s).
- Who signed? Drain:
transfer/transferFromfrom the victim, or a spender that wasapproved. Freeze: transfer reverts; no successful outbound of that token. - Is the leftover problem an exchange UI? Flag false, on-chain send works (or would work), app blocked → venue.
Save a FreezeRadar scan. A drain can still leave counterparty findings (phishing/scam labels) without DIRECT_ISSUER_BLACKLIST_MATCH. A freeze can be 100 overall with no phishing label. Scoring talk: explainable scoring.
What a drain looks like (so you do not romanticize it)
Glossary: phishing addresses receive funds obtained by tricking a victim into signing or approving. Drainers industrialize that. Typical desk facts:
- User clicked a “support”, mint, or airdrop link
- Wallet connected to a site;
approve/increaseAllowance/ a malicious Permit - Tokens left to a collector; sometimes native gas left so it “doesn’t look empty”
- Seed phrase was typed into a fake wallet app (then every asset on that key is gone, including non-freezeable)
IC3 / FBI scam-victim PSAs exist so you send people to official reporting, not to Telegram “recoverers.” Those recoverers are often the second drain.
FreezeRadar does not currently score token-approval risk as its own finding type. Absence of an allowance finding is not “safe approvals.” If the user still holds the seed that was typed into a fake UI, the key is burned. New wallet. Do not reuse it for OTC receive.

What an issuer freeze looks like (so you do not call it theft)
- Successful inbound in the past; current outbound of that token reverts
- Flag true at a block you recorded
- Balance still displayed
- Sometimes later destroy/wipe
Unfreeze is owner-gated (how USDT unfreeze works). Revoking approvals does nothing to isBlackListed.
What a venue hold looks like
- Issuer flag false
- User might still send on-chain from self-custody
- CEX/P2P platform froze account or memo/tag deposit
Do not file a Tether packet. Do not tell them to mix funds to “clear the exchange.” That is evasion coaching and it makes the venue story worse.
Ticket macros
Drain: “Official USDT restriction false at [time]. Balance decreased via outbound tx [hash] to [address]. Labels: [phishing/scam if sourced]. Action: user rotates keys if seed exposed; report to venue/issuer/law enforcement as theft; FreezeRadar scan [url]. Not an issuer freeze ticket.”
Issuer freeze: “Restriction true. Balance still present. Scan shows DIRECT_ISSUER_BLACKLIST_MATCH. Action: IR pack, official issuer process, no unfreeze vendors.”
Venue: “Restriction false. On-chain transfer would succeed / already succeeded. Exchange UI blocked. Action: venue support with tx history; exchange hold article.”
Bad: “Everything is frozen, contact our partner to unlock.” Bad: “Approve this helper contract to recover.” That is a second drainer. Bad: “If you hop through a mixer Tether will unfreeze.” Stop.
Seed exposure vs allowance drain
Keep them distinct in the SOP:
- Seed/typed phrase/exported key: attacker has the key. All chains, all tokens. Issuer freeze is irrelevant until you abandon the key.
- Approval drainer: they have spender rights on specific tokens. Revoke on a new session from a clean machine only after you understand what is left; still not an issuer freeze.
- Malicious signing of a transfer: one-shot outbound. Same as drain.
If FreezeRadar later adds approval findings, this post should link that pattern. Today, analysts read explorer approval tabs themselves.
Support-scam callbacks (the second crime)
After a freeze or a drain, the user will be offered “Tether investigators,” “wallet recovery,” and “unfreeze partners.” Those are usually phishing. Official paths only: issuer published support, the exchange they actually used, and law enforcement (IC3 for U.S. victims). FreezeRadar support tickets do not unfreeze and do not recover drains. Guide-feedback intents on public pages are for evidence correction, not magic restores.
If the user already signed a second “recovery” allowance, treat it as drain #2 in the same ticket. Do not merge it into the original issuer-freeze narrative.
Address poisoning (dust from a lookalike address) can panic users into copying the wrong from next time. That is not a drain of the real balance. Teach them to copy from their own wallet history, not from a dust inbound. Glossary: address poisoning.
After-action
- Do not receive OTC/P2P on a drained or seed-exposed address (pre-P2P, OTC pre-settle).
- Watchlist the collector address if policy allows; that is not a freeze watch.
- If a freeze and a drain both exist (rare but possible: flagged address later phished for other assets), write both sentences. Do not collapse them.
Honest limits
Explorers lag. Users lie (or are confused). Labels for drainers are incomplete. A lookalike address poisoning inbound is not a drain of their funds (address poisoning). This page does not recover funds and does not teach bypasses.
Related FreezeRadar surfaces
- Phishing address · Scam address
- Exchange hold vs issuer blacklist
- Received frozen USDT desk IR
- FBI IC3 cryptocurrency scam victim PSA (official reporting)
- Scan · Methodology
Key takeaway
If the official flag is true and the balance is still there, it is an issuer freeze. If the flag is false and the tokens left with the user’s signature or allowance, it is a drain. If the chain would move and the app will not, it is a venue. Wrong classification delays the only useful actions: issuer petition, exchange ticket, or accepting theft and rotating keys. FreezeRadar can label sourced phishing counterparties; it cannot unfreeze, and it cannot undo a signed drain.
Sources (4)
Phishing Address (glossary)
FreezeRadar
Term owner for phishing/drainer addresses.
FBI Guidance for Cryptocurrency Scam Victims
FBI IC3
Official victim-reporting path; not a FreezeRadar recovery product.
Exchange hold vs issuer USDT blacklist
FreezeRadar
Venue plane versus issuer flag.
Tether Token Terms of Sale and Service
Tether
Issuer freeze/blacklist is a different plane from theft.
Related reading
Continue exploring FreezeRadar knowledge content.
On this page
Get posts like this by email
A daily or weekly digest of FreezeRadar freeze activity.
By FreezeRadar Team
Wallet risk intelligence and stablecoin compliance analysis from FreezeRadar.


