← Back to Blog

Address Poisoning: What It Is and How to Protect Yourself

Address poisoning crypto scam how it works

Address poisoning doesn't require malware, social engineering, or a fake investment platform. It exploits one single habit: copying wallet addresses from your own transaction history. And it has cost victims millions.

This article explains exactly how it works, why it's so effective, and the specific habits that make you immune to it.

What Address Poisoning Actually Is

Definition

Address poisoning is an attack where a scammer "poisons" your transaction history by sending a small or zero-value transaction from a wallet address that looks nearly identical to one you've legitimately used. When you later go to copy an address from your history to make a real transaction, you copy the attacker's address instead.

The attack requires no interaction from you. You don't click a link, install software, or respond to a message. The scammer simply sends a dust transaction — sometimes as little as $0.00 — and waits. Their poisoned address sits in your history, looking like a trusted one.

All they need is for you to be in a hurry once.

How the Attack Works Step-by-Step

  1. 1

    Scammer identifies a target address

    They monitor the blockchain for wallets with regular transaction activity — particularly wallets that frequently send to or receive from the same addresses.

  2. 2

    Generate a look-alike address

    Using a vanity address generator, they create a wallet address that matches the first 4-6 and last 4-6 characters of a legitimate address in your history. The middle characters are completely different — but you'll never see them.

  3. 3

    Send a tiny "dust" transaction

    The attacker sends a micro-transaction (sometimes $0.00 using token transfer mechanics) from their look-alike address to your wallet. This transaction now appears in your history.

  4. 4

    Wait for you to copy from history

    When you next need to send funds to that address, you open your transaction history, see the familiar-looking address near the top, and copy it. You've just copied the attacker's address.

  5. 5

    Funds sent to wrong address

    You confirm the transaction. The funds go to the attacker. The blockchain is irreversible — there is no undo.

How Scammers Create Look-Alike Addresses

A standard Ethereum address is 42 characters long. Most wallets, exchanges, and block explorers display only the first 6 and last 4 characters — the rest is hidden by default with "..."

Here's what a poisoned address looks like compared to a real one:

Real Address 0x7F4aB3c8...d2E19F4a7b
Poisoned Address 0x7F4a99f1...c7A2034a7b

The highlighted characters — the ones you'd actually see in a wallet UI — are identical. The 30+ characters in the middle are completely different. This is not a coincidence; the attacker specifically generated this address to match.

Vanity address generators can try millions of combinations per second. Matching 8-10 visible characters is achievable in minutes with consumer hardware. Matching 12+ takes longer but is still feasible for a motivated attacker targeting a high-value wallet.

A Real-World Example

In 2023, a trader lost $68 million in a single address poisoning transaction. They had been regularly sending USDT to a specific address. The attacker generated a look-alike, poisoned their history, and waited. The trader copied from history without checking the full address. The $68 million transfer confirmed before they realized the error.

Important Context

This wasn't a naive user. It was an experienced trader making a routine transaction. Address poisoning exploits familiarity and habit — not ignorance. The more routine a transaction feels, the more dangerous it is.

Smaller cases happen constantly and go unreported. The victim sends $5,000 to an address that "looked right," realizes hours later, and finds nothing they can do about it.

Why This Scam Is So Effective

Three reasons address poisoning works on experienced users:

  • Transaction history feels trustworthy. You've used that address before. Seeing it again in your history triggers confirmation bias — your brain says "I recognize this."
  • Full address verification is inconvenient. A full Ethereum address is 42 characters. Nobody wants to read 42 characters. Interfaces truncate them. Attackers exploit that truncation.
  • Speed and habit create windows. You're moving funds during a busy moment. You've copied addresses from history hundreds of times without issue. This time is no different — until it is.

It's also a scalable attack. A single attacker can poison thousands of wallets simultaneously. They don't need all of them to fall for it — even a small success rate against high-value wallets is enormously profitable.

How to Protect Yourself

📖

Use an address book

Save verified addresses in your wallet's address book under recognizable names. Copy from the address book — never from transaction history.

🔍

Verify the full address

Before sending any significant amount, expand and verify the complete address — all 42 characters, not just the first and last few.

🚫

Never copy from history

Get addresses directly from the source: the exchange withdrawal page, the recipient's verified message, or your own saved address book.

🧪

Send a test transaction first

For large transfers to a new or recently used address, send a small test amount first. Confirm it arrived before sending the full amount.

⚠️

Ignore dust transactions

If you receive tiny, unsolicited transactions from unknown addresses, ignore them. Do not interact with those tokens or addresses. They exist to pollute your history.

🔒

Use hardware wallet confirmations

Hardware wallets display the full destination address on the device screen before signing. This forces manual verification before every transaction.

The One Rule That Prevents All Address Poisoning

Never copy a destination address from your transaction history. Always copy from the original source. This single habit makes address poisoning impossible to execute against you.

If You Already Sent Funds to a Poisoned Address

The transaction cannot be reversed. But that doesn't mean nothing can be done.

Here's what to do immediately:

  • Document everything. Screenshot your transaction history, the poisoned address, and the legitimate address side by side. Record the transaction hash, amount, and timestamp.
  • Run the poisoned address through a block explorer. See where the funds moved next — whether they went directly to an exchange, through mixers, or into other wallets. This tells you how fast you need to move.
  • Report to the destination exchange immediately. If the funds landed at a centralized exchange, contact their fraud team and provide the transaction hash. Some exchanges will freeze accounts pending investigation if contacted quickly.
  • File reports with IC3, FTC, and CISA. Federal agencies track address poisoning campaigns. Your report contributes to pattern recognition even if no immediate action is taken. See our guide on reporting malicious wallet addresses.
  • Engage a forensic investigator. A blockchain forensic report traces the full fund flow, identifies exchange deposit addresses, and produces a document law enforcement can act on. Start by gathering your transaction evidence.
Do Not

Do not interact with the poisoned address in any way. Do not send a "reclaim" transaction or try to contact the attacker. There are secondary scams that target victims immediately after — particularly "recovery services" that will take additional funds. Any service promising to reverse a blockchain transaction is a scam.

The window for exchange cooperation closes quickly — often within 24-72 hours before funds are moved to non-custodial wallets or exchanged. Follow the first 72 hours checklist to act in the right sequence. If significant funds were lost, act on the exchange contact and forensic investigation simultaneously, not sequentially.


Lost Funds to Address Poisoning?

We trace poisoned address transactions across chains, identify exchange deposits, and produce forensic reports that law enforcement and exchange fraud teams can act on. Time matters — the sooner we start, the more options remain open.

Zack Coffing — Wallet Witness

Blockchain forensic investigator specializing in crypto fraud, on-chain tracing, and litigation support. Wallet Witness produces forensic reports for victims, attorneys, and law enforcement worldwide.