A token arriving is not something you authorised. It is somebody writing your address into their contract, which costs them very little and happens to almost every address that has been used.
The point is rarely the token itself. It is the website printed in its name, the "claim" it invites, and the approval or signature that site will ask for.
How Smartable shows it
- A blue tick means registries agree on what the contract is — at least two independent ones — or Smartable added it to its own list.
- A token no registry knows is marked as unverified, and its details say No source knows it. Known to a single registry, it says One source only.
- An imitation is never merged into the real asset's row, even if it uses the same name or ticker. And a token that no price source knows adds nothing to your total.
Unverified does not mean malicious — a brand-new token can be genuine. It means nobody the wallet trusts has vouched for it yet.
The rules that keep it harmless
- Do not visit a website named in the token.
- Do not connect your wallet to claim anything you did not expect.
- Do not try to sell or swap it. Some of these contracts are written so that interacting with them is what costs you.
- Hide it and move on: swipe the row off your assets. Hidden rows can be brought back under Settings → Display → Hidden assets. Transfers from a spam token can be hidden from Activity the same way.
A fake token sitting in your list can do nothing by itself. Every loss from one begins with a signature you give.
What the app shows
- “No source knows it”
- “One source only”
Security note
Never share your recovery phrase, private key, password or device PIN. Smartable will never ask for them or ask you to sign a transaction to “verify” or “recover” your wallet.
Related