TrueHold

BlogSelf-custody

Address poisoning: the copy-paste attack

Scammers plant lookalike addresses in your history, betting you copy the wrong one. How address poisoning works and the habits that beat it.

Azat Tulegenov2 min read

Address poisoning is a patience attack. The scammer generates an address whose first and last characters match one you actually use, sends you a zero-value or dust transaction from it, and waits. Weeks later you need to send funds, copy "your" address from transaction history, check the first four and last four characters, and send. The middle characters were never yours.

Why such a dumb trick works

Because everyone verifies addresses exactly the way wallets display them: truncated to the ends. Generating a vanity address that matches a target’s prefix and suffix takes commodity hardware and minutes. Sending dust from it costs cents. The attack scales to millions of wallets, and it only has to work once. Losses to poisoning run into hundreds of millions because the human habit it exploits is nearly universal.

What it looks like in your wallet

  • Tiny incoming transfers you never expected, sometimes of worthless tokens, from addresses that look eerily familiar.
  • History entries that seem to be your own past counterparties but with different middle characters.
  • Sometimes fake outgoing entries: spoofed token contracts can fabricate transfers "from" you to the lookalike.

The habits that beat it

  • Never copy addresses from transaction history. History is attacker-writable; that is the entire attack.
  • Keep an address book in your wallet and send only to saved entries. Your address book is not attacker-writable.
  • Verify more than the ends: check a chunk of the middle, or better, compare the full string once and save it.
  • For large transfers, send a test amount first and confirm receipt out-of-band before the real one.
  • Ignore dust. Do not interact with unexpected tokens; interacting is sometimes the second stage of the scam.

If you already sent to a poisoned address

Honesty first: on-chain transfers are final, and the receiving key belongs to the attacker, so recovery is unlikely. Report the address to your wallet provider and explorers so it gets flagged, document everything for law enforcement, and audit how the poisoned entry got into your flow so it cannot happen again. Then build the address-book habit; it costs nothing and closes the door.

Frequently asked questions

Can receiving dust or strange tokens harm my wallet?

Receiving alone cannot move your funds; your private key never left. The danger is downstream: copying the lookalike sender later, or interacting with a malicious token contract.

Should I do anything about the dust in my history?

Leave it. Do not swap it, approve it, or visit sites it advertises. Some trackers and wallets let you hide flagged tokens so they stop cluttering the view.

Does address poisoning affect exchanges too?

Exchange withdrawals use saved addresses more often, which helps. The attack targets any flow where a human copies an address from history, so the same address-book rule applies everywhere.

Terms in this article

See your whole portfolio in one view

Read-only by design. Paste a wallet, link an exchange, and watch every chain. Free to start.