← News & Guides
SECURITY/SEP 25, 2026·15 MIN READ

Crypto address poisoning: how lookalike wallets hijack transfers

Address poisoning puts lookalike wallets into your transaction history. Learn how the scam works and how to verify addresses before sending any crypto.

Crypto address poisoning: how lookalike wallets hijack transfers

Address poisoning doesn’t require stolen private keys, malware, or a compromised wallet. The attacker wants you to make the transfer yourself.

The scam works by placing a lookalike address in your transaction history. Later, you copy it instead of the intended recipient’s address and send funds directly to the attacker.

It’s a simple attack. It can also be brutally effective.

Key takeaways

  • Attackers create addresses resembling wallets you’ve previously interacted with.

  • A zero-value or dust transaction places the fake address in your history.

  • Checking only the first and last few characters isn’t enough.

  • Saved addresses, independent verification, and properly handled test transfers reduce the risk.

What is address poisoning?

Address poisoning is a scam built around transaction history.

Suppose you regularly send USDT to an exchange deposit address, OTC counterparty, or another wallet you control. That activity is visible on a public blockchain. An attacker identifies the recipient and generates a new address with a similar-looking beginning and ending.

The attacker then creates a transaction involving your wallet. Depending on the network and token, this may be a dust transfer, a zero-value token transfer, or another activity designed to place the lookalike address in your wallet interface or block explorer history.

Nothing has been stolen yet. The attacker is waiting.

When you make the next transfer, you may open an old transaction and copy what appears to be the familiar address. If you select the poisoned entry, the new payment goes to the attacker.

How the attack works

A typical address-poisoning campaign follows four steps.

1. The attacker studies an active wallet

Public blockchains expose transaction addresses and amounts. The attacker looks for wallets that make regular or high-value transfers, then identifies frequently used recipients.

They don’t need to know who owns either wallet. The on-chain pattern is enough.

2. A lookalike address is generated

Software generates addresses until it finds one that shares some of the same characters as the legitimate recipient.

For example:

Legitimate: 0x7A91...42B8
Attacker:   0x7A91...42B8

The abbreviated versions look identical, but the full addresses differ.

How difficult this is depends on how many characters the attacker wants to match. Matching more characters requires more computation, but wallet interfaces often display only a short prefix and suffix.

3. The transaction history is poisoned

The attacker sends a tiny amount to the target or creates a zero-value token transfer. This adds the lookalike address to the activity feed.

The transaction may be easy to dismiss as spam. Its value isn’t the point. The attacker only wants the address to appear somewhere you might copy it later.

4. The victim sends to the wrong wallet

Days or weeks later, the victim searches their history for the previous recipient. They recognize the shortened address, copy it, and make the transfer.

Once confirmed, the transaction generally can’t be reversed. Recovery depends on the attacker voluntarily returning the funds or, in limited cases, a service provider being able and willing to intervene.

Why checking the ends isn’t enough

Many wallets shorten long addresses for readability. A full Ethereum address might appear as 0x7A91...42B8, leaving most characters hidden.

Users are often taught to check the first and last four characters before sending. Address poisoning is designed specifically to defeat that habit.

Compare more than the visible ends. For a large transfer, open the full address and verify it against a trusted source. Don’t rely on memory, recent transactions, or a familiar-looking abbreviation.

A $68 million mistake

In May 2024, a trader transferred roughly $68 million in wrapped bitcoin to a poisoned Ethereum address.

The fake address resembled the intended recipient closely enough to pass a quick visual check. The attacker later returned the funds after negotiations, an unusual outcome documented by Chainalysis.

Most victims shouldn’t expect the same result. Whoever controls the receiving address controls whether the funds come back.

Who gets targeted?

Active wallets are attractive targets because their transaction patterns give attackers more material to copy. Wallets holding large balances also offer a higher potential payout.

Still, address poisoning isn’t limited to whales. Any user who copies recipient addresses from transaction history can be targeted.

The economics favor scale. Attackers can generate many lookalike addresses and send large numbers of cheap poisoning transactions. Most attempts fail, but a single successful transfer may cover the entire campaign.

How to prevent address poisoning

Don’t copy addresses from transaction history

Retrieve the destination from a trusted source each time. For an exchange deposit, open the exchange directly and generate or confirm the address there. For another person or organization, verify it through an established communication channel.

A previous transaction is not a trusted address book.

Check the full address

Expand the address before approving a transfer. Compare it with the intended destination rather than checking only the first and last few characters.

Hardware wallets can help by displaying the final destination on a separate device, but only if you read and verify what the screen shows.

Use saved contacts and withdrawal allowlists

Store recurring destinations under clear labels. Where available, use an exchange withdrawal allowlist so transfers can only go to addresses you approved earlier.

Take the same care when adding an address to the allowlist. Saving a poisoned address simply makes the mistake persistent.

Handle test transfers correctly

For a large payment, send a small test first and ask the recipient to confirm receipt.

Then send the remaining amount to the exact same saved and verified address. Don’t return to the transaction history and copy the address again, since that recreates the original risk.

A test transfer only helps if the destination is independently confirmed.

Treat dust and zero-value transfers as untrusted

Unexpected dust doesn’t necessarily mean your wallet has been compromised. It may be spam, an address-poisoning attempt, or another form of on-chain noise.

Don’t interact with the token or copy addresses from the entry. Hide or report the transaction if your wallet supports that option.

Use human-readable names carefully

Systems such as Ethereum Name Service can replace hexadecimal addresses with names like example.eth. This reduces the need to copy long strings.

It doesn’t remove verification from the process. Similar-looking names, compromised accounts, or incorrect records can still direct funds to the wrong destination. Confirm both the name and its resolved address before a large transfer.

Add independent checks for high-value wallets

For treasury and operational wallets, require a second person to verify the full destination through a separate source.

A multisig helps only when signers perform independent checks. If everyone approves the same poisoned address without verifying it, multiple signatures won’t prevent the loss.

What to do after spotting a poisoned address

Receiving a dust or zero-value transaction doesn’t give the sender control over your wallet. Your private keys remain safe unless something else has been compromised.

Mark the entry as spam if possible. Remove any saved version of the suspicious address, and review pending transfers before signing them.

If you already sent funds to the poisoned address, record the transaction hash and contact any involved exchange or custody provider immediately. You can also report the address to relevant blockchain analytics and law-enforcement channels. Recovery isn’t guaranteed, and speed matters if the attacker moves funds through centralized services.

The practical rule is narrow but effective: never treat transaction history as proof of a destination address.

#Security#Wallets#Scams#Phishing