Back to Glossary

Address Poisoning

Address Poisoning Definition: Address poisoning is a crypto scam in which an attacker sends a tiny or zero-value transfer from a wallet address that looks almost identical to one the victim uses, so the fake address appears in the victim’s transaction history. If the victim later copies an address from that history, the funds go to the attacker, and because blockchain transfers are final, they cannot be recovered without the attacker’s cooperation.

What Is Address Poisoning?

Nobody reads 42 characters of hexadecimal text before every transfer. Most people glance at the first few and last few characters and move on. Address poisoning exploits that shortcut.

A crypto wallet address on Ethereum looks like 0x followed by 40 letters and digits. Wallet apps often shorten it to something like 0x7a3f…9c2e, showing only the ends. An attacker who creates an address with the same beginning and ending can make it look identical in that shortened view.

No hacking is involved. The victim’s keys stay safe, and the wallet software works as designed. The scam succeeds only if the victim sends the money personally, which is why it targets habits rather than code.

How Does Address Poisoning Work?

The attack has three steps. First, the attacker watches the blockchain for wallets that regularly send large amounts to the same address, such as a trader moving funds between a personal wallet and an exchange deposit address. Every transaction on a public chain is visible, so finding these patterns takes only a script.

Second, the attacker generates a vanity address whose first and last four to six characters match the real destination. Specialised software tries millions of key pairs until one fits, which takes minutes to hours on a graphics card.

Third, the attacker plants the fake address in the victim’s history. This can be a dust transfer of a few cents, a counterfeit token with a real-looking name, or a zero-value transfer. On ERC-20 tokens, a quirk in how many token contracts implement the standard lets anyone call a transfer of zero tokens “from” the victim’s wallet, so the fake entry shows up as if the victim had sent it.

Now picture the trap closing. A trader who sends 50,000 USDT to an exchange every week opens the wallet, sees what looks like the usual address at the top of the history and copies it. The 50,000 USDT lands in the attacker’s wallet in seconds, and the attacker usually swaps it or bridges it to another chain before anyone notices.

Address Poisoning Example

On 3 May 2024, a holder transferred 1,155 wrapped bitcoin (WBTC), worth about $68 million, to a poisoned address that matched the first and last characters of the intended one. The attacker swapped much of the WBTC for ETH within hours.

That case ended unusually. On-chain investigators traced the funds, the victim sent public messages to the attacker’s address offering a bounty, and about a week later the attacker returned nearly all of the money after negotiations. Most victims get nothing back, because thousands of smaller thefts never attract that level of attention.

Address Poisoning vs. Phishing

Address Poisoning Phishing
What the attacker steals A single transfer the victim sends Passwords, seed phrases or token approvals
Victim contact None, only an entry in the wallet history Fake emails, websites or messages
Victim action required Copying the wrong address Entering secrets or signing a malicious transaction
Damage Limited to the amount sent Can drain the whole wallet

Poisoning is quieter than phishing. There is no fake website to spot and no suspicious message to delete, only an extra line in a list of transactions.

Why Is Address Poisoning Important for Traders?

Traders are prime targets because they move large sums to the same addresses on a schedule, and that routine is visible on-chain. Poisoning campaigns concentrate on stablecoins such as USDT and USDC, since those transfers are large, frequent and easy to launder.

Defence comes down to breaking the copy-from-history habit. Saving verified addresses in the wallet’s address book, checking the full address or a middle section rather than only the ends, and sending a small test transfer before a large one all defeat the trick. A hardware wallet helps too, since its screen displays the full destination before you approve.

Some wallets and block explorers now hide zero-value transfers or flag suspected poisoning entries. These filters catch many attacks but not all, and a dust transfer of real value can slip past them, so the final check still falls to the person pressing “send”.

Key Takeaways

  • Address poisoning plants a look-alike wallet address in a victim’s transaction history and waits for the victim to copy it by mistake.
  • Attackers generate vanity addresses that match the first and last characters of a real destination, which is all that shortened wallet displays show.
  • The scam needs no access to keys, and a poisoning entry alone cannot move funds; the loss happens only when the victim sends a transfer.
  • Blockchain transfers are final, so prevention matters far more than recovery.
  • Saved address books, full-address checks and small test transfers defeat nearly all poisoning attempts.
FAQ section

I received a zero-value transaction from an unknown address. Am I hacked?

No. A zero-value or dust transfer cannot take funds from your wallet, and your keys are safe. It is a warning sign that someone is trying to plant a look-alike address in your history, so avoid copying addresses from that list.

Can a poisoned transfer be reversed?

Blockchain transfers are final, so neither the network nor the wallet provider can undo one. Recovery depends on the attacker returning the funds or an exchange freezing them before they are moved.

Does address poisoning only affect Ethereum?

It is most common on Ethereum and other EVM chains such as BNB Chain and Polygon, where transferring tokens costs little, and on Tron, where much USDT moves. Any blockchain with public histories and cheap transfers is exposed.

Compliance
Compliance Definition: Compliance is the system of policies,...
Crypto Regulation
Crypto Regulation Definition: Crypto regulation is the body ...
Custodial vs Non-Custodial
Custodial vs Non-Custodial Definition: Custodial vs non-cust...
DDoS Attack
DDoS Attack Definition: A DDoS (distributed denial-of-servic...

Live Chat

Contact our support team via live chat.

Help Center

Questions about our services?
Check out our Help Center.

Risk Warning:
Trading in leveraged products carries a high level of risk and may not be suitable for all investors.