Address poisoning is a scam that puts a fake address into your own wallet history, so that the next time you send, you copy the attacker’s address instead of your own. The fake is built to share the first and last characters of an address you really use, which is exactly the part your wallet shows you, and the transfer that follows cannot be reversed.
This guide is education, not financial, legal, or tax advice. Nothing here recommends buying, selling, or moving any asset. Check every character on your own screen before you sign anything.
How does an address poisoning attack work?
The attack has four steps, and none of them involve breaking into your wallet.
- The attacker watches the chain. Public ledgers show every transfer. A bot sees that your address regularly sends USDT to an exchange deposit address, or to your own second wallet.
- The attacker generates a lookalike. Software grinds through keys until it finds an address whose first few and last few characters match the address you keep using. Researchers presented at USENIX Security ‘25 documented attackers doing this at scale with GPUs.
- The attacker sends you something tiny. It might be a dust transfer worth a fraction of a cent. It is often a zero-value token transfer, or a transfer of a fake token that borrows the name and symbol of a real one. MetaMask’s own write-up describes these as usually transfers of zero tokens. The point is not the money. The point is to appear in your list.
- You do the rest. Days later you go to send again, open your activity list, tap the most recent familiar-looking entry, and paste. The funds go to the attacker.
That last step is why this works. Nobody stole your seed phrase. Nobody installed anything on your phone. You approved the transaction yourself, and on most chains there is no undo.
The scale is not small. The USENIX study measured roughly 270 million attack attempts against 17 million victim addresses on Ethereum and BNB Smart Chain over two years, of which 6,633 succeeded, for at least $83.8 million in losses. Chainalysis has published its own anatomy of these scams.
Why does your eye miss the difference?
Because your wallet never shows you the whole address.
A hex address on Ethereum is 42 characters. A Tron address is 34 characters of base58, starting with T. No interface displays all of that in a list, so every wallet truncates to something like 0x1f9c…4b2e. The truncated form is a head and a tail with the middle removed, and the head and tail are precisely what the attacker copied.
Your wallet shows TQ5No…cJ7a for both rows. So does the exchange. So does the block explorer list view. Truncation is convenient and it is also the whole vulnerability.
Sorting makes it worse. Wallets list activity newest first, so a dust transfer that arrived yesterday sits above the legitimate transfer you made last month. The poisoned entry lands at the top of the list, where your thumb goes.
Is this the same as clipboard malware or phishing?
No. These are three different attacks, and telling them apart matters because the defenses differ.
| Attack | Where it lives | What it needs from you |
|---|---|---|
| Address poisoning | Your own transaction history, on-chain | That you copy an address from history |
| Clipboard malware | Malicious software on your phone or computer | That your device is already infected |
| Phishing | A fake app, site, ad, or “support” account | That you enter a seed phrase or sign a malicious approval |
Clipboard malware swaps what you pasted for something else after you copy it, so the string you verified and the string in the field are different. Address poisoning does the opposite: the clipboard is honest, and the source you copied from was the trap. Antivirus will not help, because there is no malicious software involved.
Phishing is its own category, covered in How to spot phishing and fake wallet apps before they drain your wallet. A related risk is the leftover token permission, which is covered in Token approval checker: how to check and revoke token permissions.
The two do overlap. A fake token that lands in your wallet and invites you to “claim” or “swap” it on some site is phishing arriving on the back of a poisoning transfer. Do not interact with tokens you did not expect.
How do you check an address before you send?
Work through these in order. Steps 1 to 4 take under a minute and stop the attack completely.
- Never copy an address out of your transaction history. Your activity list records what happened; it is not where you go to find an address. This single rule closes the attack.
- Get the address from its current source. Ask the recipient to send it fresh, or open the receiving wallet’s receive screen and copy from there. For an exchange deposit, use the deposit page for that exact asset and network.
- Prefer the QR code. Scanning skips the copy-paste step entirely. Do this when the recipient is in front of you or on a video call.
- Compare a middle chunk, not just the ends. Pick six or eight characters from the middle of the address and check them against the source. MetaMask’s guidance says the same thing: verify the middle, because the start and end are the part an attacker can match. Reading the address aloud in groups of four is a fast way to do it.
- Save it to the wallet address book with a label. Most wallets store named contacts. A contact you verified once takes the history list out of the loop for good.
- Confirm on the hardware wallet screen, character by character. If you use a hardware wallet, the address on its display is the one being signed. Your computer can lie to you. The signing device cannot be edited by a website, so compare its screen to the address you verified, then approve.
- Send a small test amount first when the destination is new or the amount is large. Wait for the recipient to confirm receipt before sending the rest. You pay one extra network fee, so weigh it against the amount at risk.
- Check the explorer afterwards. Paste the transaction hash and confirm the recipient address matches what you intended. How to read a block explorer and verify your own transactions walks through this.
Most modern wallets now warn when a destination resembles an address from your history. Treat that warning as a hard stop, not a speed bump. Treat its absence as nothing at all, because detection varies by wallet, by chain, and by version.
Which chains and assets see this most?
Anywhere addresses are long and fees are low. Ethereum and BNB Smart Chain were the two chains in the USENIX measurement. Tron carries enormous USDT volume across Latin America, has very cheap transfers, and uses base58 addresses that look alike at a glance, which makes it a natural target for the same technique.
What decides your exposure is your send routine rather than your chain. Someone paying a supplier in Caracas or topping up a family member in Lima, moving USDT between a local exchange, a P2P counterparty and a self-custody wallet, is doing exactly the repeated, predictable transfer a poisoning bot looks for. The defense is identical on every network.
For the wider send and receive routine this fits into, read How to send crypto safely from a self-custody wallet and How to receive crypto safely into a self-custody wallet.
What if you already sent to a poisoned address?
The transfer is final. No support desk can claw it back, and no wallet developer holds a reverse button.
What you can still do:
- Save the transaction hash. Every report you file will ask for it.
- Report it. If the asset is a centrally issued stablecoin such as USDT or USDC and the funds land on an exchange, report to that exchange and to the issuer. Freezes are rare and never guaranteed, and this is the only path that exists.
- File with local authorities if your jurisdiction takes cybercrime reports.
- Ignore anyone offering recovery. Accounts that appear under a public loss post promising to recover funds for a fee are a second scam aimed at the same victim.
- Fix the habit before the next send. Save the correct address as a labeled contact and stop using the history list.
Your pre-send checklist
- The address came from the recipient’s current receive screen, a QR scan, or my saved contacts
- It did not come from my transaction history
- I compared characters from the middle of the address, not only the head and tail
- The network matches on both sides
- The hardware wallet screen shows the same address I verified
- For a new destination or a large amount, a test transfer arrived and was confirmed
Address poisoning is one of the cheapest attacks in crypto to run and one of the cheapest to defeat. It costs an attacker a fraction of a cent to plant the bait, and it costs you about thirty seconds to check the middle of an address against a source you trust.



