Close Menu
Crypto Valley Journal
    Facebook X (Twitter) Instagram
    Crypto Valley Journal
    • Hot Topics
      • News
      • Minds
    • Focus
      • Background
      • Blockchain
      • Legal & Compliance
      • Non-Fungible Token (NFTs)
    • Investing
      • Markets
      • Financial Products
      • Decentralized Finance (DeFi)
      • Exchange overview
    • Education
      • Basics
      • Glossary
      • Politicians on crypto
    • Statistics
      • Bitcoin-ETF-Flows
      • Ethereum-ETF-Flows
      • Crypto market data
      • On-chain data
    • Academy
      • Overview
      • Part 1: Blockchain
      • Part 2: Money
      • Part 3: Bitcoin
      • Part 4: Cryptocurrencies
      • Part 5: Decentralized Finance
      • Part 6: Investing
    • English
      • Deutsch
    Crypto Valley Journal
    You are at:Home » Glossary » CA – Contract Address
    A contract address derives from the creator address plus a nonce or salt, and its mixed case spelling encodes an EIP-55 checksum.

    CA – Contract Address

    0
    By Editorial Office CVJ.CH on 21. August 2026 Glossary

    A contract address is the fixed address where a smart contract sits on a blockchain. It derives from the creator address plus a nonce or salt, and belongs to program code, not a private key. Anyone sending tokens there addresses the program directly.

    Ethereum distinguishes two account types: accounts under the control of a private key, and contract accounts. Those contract accounts run a smart contract on the EVM. Both share the same address format. As a result, users regularly mistake a contract address for a wallet address. The difference lies in the origin. A wallet address derives from a public key under secp256k1. A contract address, however, comes from the data of the deployment transaction. No key pair therefore belongs to a contract address.

    How CREATE and CREATE2 compute the address

    A contract address first arises from a transaction without a recipient in the to field. That transaction's data field carries the init code. From that input, the CREATE opcode builds the hash keccak256(rlp([sender, nonce])). Specifically, the hash's last 20 bytes form the address, 42 characters long in hex notation with the 0x prefix. The nonce counts the outgoing transactions of the creator and rises with each one. Consequently, anyone deploying the same code twice receives two different addresses.

    CREATE2, however, replaces the nonce with a freely chosen salt and folds the init code into the hash. EIP-1014 describes the formula, while the Constantinople hard fork activated the opcode on the main chain on 28 February 2019. Because the creator chooses the salt, they control the address and can publish it before the contract exists. Developers call this counterfactual deployment. In both cases, the address itself stays permanent. Should the contract receive new code through a proxy pattern, that leaves the address untouched.

    FeatureCREATECREATE2
    Formulakeccak256(rlp([sender, nonce]))[12:]keccak256(0xff ++ sender ++ salt ++ keccak256(init_code))[12:]
    Depends onnonce of the creatorfreely chosen salt
    Address computable before deploymentNoYes
    Introducedoriginal EVM opcodeEIP-1014, Constantinople hard fork 28 February 2019

    Other chains also derive addresses, yet they calculate differently. Solana addresses are usually Ed25519 public keys. Program Derived Addresses, however, emerge deterministically from seeds and a program ID via SHA-256. Such addresses are guaranteed to lie outside the Ed25519 curve. No private key exists for them as a result.

    How do you recognize a real contract address?

    A block explorer displays a contract address in mixed upper and lower case, just like any Ethereum address. That spelling encodes a checksum under EIP-55. Specifically, a hex letter appears in upper case under one condition. The matching nibble in the keccak256 hash of the lowercase address must reach at least 8. The pattern therefore comes not from the address as text, but from its hash. A single wrong character changes that hash completely. Consequently, the pattern of upper and lower case letters usually changes with it. When the spelling does not match the hash, the address is faulty.

    EIP-55 places an average of 15 check bits into an address. A randomly generated address that someone mistypes still passes the checksum with a probability of 0.0247%. Thus, in arithmetic terms, roughly one in 4,049 mistyped addresses slips through unnoticed. Those check bits occupy no extra character. Instead, they sit entirely in the upper and lower case of the letters.

    However, the checksum is not mandatory, and an address written entirely in lower case remains valid. A fully valid address that belongs to someone else passes just as easily. After all, the checksum tests the character string and not the intent behind it. Nor does the checksum reveal whether a program or a key pair sits behind an address.

    When a fake address matches the real one

    Under the name address poisoning, the block explorer Etherscan describes how attackers replicate addresses that belong to others. In address spoofing, an attacker first generates a vanity address. Its first and last characters match those of the genuine address. Subsequently, the attacker sends the victim a worthless transaction, which shows up in the victim's history. Anyone who compares only the start and the end there sees no difference. Fake ERC-20 contracts also circulate, and they imitate the names and symbols of well-known tokens. In event spoofing, a forged transfer event via transferFrom simulates a movement that never took place.

    One documented case hit a single wallet in May 2024. The attacker had replicated the first and last characters of the target address beforehand. The transfer ran to roughly USD 68 million. Later, the attacker returned the funds.

    Zero-value transfers are one channel through which a fake address enters a transaction history in the first place. Etherscan has therefore hidden token transfers without value by default since April 2023. Still, the reliable source for a contract address remains the project page, not the transaction history.

    Automated market makers manage liquidity pools like rule-based portfolios, with direct consequences for impermanent loss and hedging. Basics
    8. October 2026

    Automated market makers as decentralized portfolio managers

    Automated market makers manage liquidity pools like rule-based portfolios, with direct consequences for impermanent loss and hedging.

    Bitcoin in 2026 trades around USD 84,000, while US spot ETFs hold about USD 102 to 104 billion and listed companies 1.27 to 1.29 million BTC. Background
    29. September 2026

    Bitcoin in 2026: what the numbers actually say

    Bitcoin in 2026 trades around USD 84,000, while US spot ETFs hold about USD 102 to 104 billion and listed companies 1.27 to 1.29 million BTC.

    24. September 2026

    Unit bias in crypto: Why cheap coins mislead investors

    The Chainalysis Crypto Crime Report puts illicit activity below 1% of on-chain volume, countering the myth of Bitcoin as a criminal currency.
    23. September 2026

    Myth: Bitcoin and cryptocurrencies mainly serve criminal activity

    Zcash hides transaction data with zk-SNARK proofs and now sits between a US spot ETF listing and the EU privacy coin ban of 2027.
    22. September 2026

    What is the privacy coin Zcash (ZEC)?

    The Trezor data breach at fulfillment provider ShipMonk exposed names, addresses and phone numbers of 13,689 customers.
    21. September 2026

    Hardware wallet comparison 2026: Ledger vs. Trezor – new models, new risks

    The Ethereum Foundation's Protocol Cluster rated 62 EIPs and set December 2029 as the target for a quantum-safe Ethereum base layer.
    8. September 2026

    Ethereum targets a quantum-safe blockchain by 2029

    Bitcoin near USD 78,000 and stablecoin supply above USD 300 billion shape the crypto market outlook heading into Q4 2026.
    2. September 2026

    The signals to watch: a crypto market outlook for Q4 2026

    Popular Posts
    About Crypto Valley Journal
    About Crypto Valley Journal

    On the pulse of the movement

    • Academy
    • Contact
    • Advertising
    • About us
    • Partner
    • Imprint
    • Privacy
    • Disclaimer
    Search
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.