Address poisoning is a scam that turns your own transaction history into a trap. The attacker doesn't need to hack your wallet or steal your keys — they simply get a lookalike address to appear in your history, betting that next time you'll copy it from there instead of from the real source. Because crypto payments are irreversible, one careless copy-paste can send an entire balance to a stranger. This guide explains exactly how the attack works, why it's so effective, and the simple habits that make you immune to it.
This is a safety guide for anyone who moves crypto. Address poisoning is one of the most common and costly scams in the space precisely because it exploits a habit almost everyone has — reusing an address from a past transaction.
What address poisoning actually is
Every wallet address is a long string of characters, and almost nobody reads the whole thing. We glance at the first few and last few characters, decide "yep, that's the one," and move on. Address poisoning is built entirely around that shortcut.
The attacker generates an address that starts and ends with the same characters as one you use — a "vanity" lookalike — and then makes it show up in your transaction history next to your real activity. Later, when you want to send to that familiar counterparty, you scroll your history, copy the address that looks right, and pay the attacker instead. Nothing was hacked. You were nudged into copying the wrong string.
How the attack works, step by step
- They watch the chain. Public blockchains show every transaction. An attacker sees that you regularly send to, say, an exchange deposit address or a friend's wallet.
- They mint a lookalike address. Using automated tools, they grind out an address whose first 4–6 and last 4–6 characters match the one you use. The middle is completely different, but the middle is the part nobody checks.
- They "poison" your history. They push a transaction involving that lookalike address into your ledger so it appears among your real transactions (see the variants below).
- They wait. Days or weeks later you go to send funds, copy the address straight from your history because it "looks right," and broadcast the payment.
- The coins are gone. The transaction confirms to the attacker's address. There's no reversal, no support desk, no chargeback.
The common variants
- Zero-value transfer poisoning. On chains and tokens that allow it, the attacker triggers a
transferFromof zero tokens that moves value "from" the lookalike address to you. Your wallet logs it, so the poison address now sits in your history looking like a real counterparty — even though you never received anything. - Dust poisoning. The attacker sends a tiny, near-worthless amount ("dust") from the lookalike address to your wallet. It's a real inbound transaction, so it appears in your history and address suggestions as if it were legitimate.
- Fake-token poisoning. They send a bogus token (often named to mimic USDT, USDC, or a coin you hold) from the lookalike address, again just to seed that address into your ledger and wallet UI.
- Copy-suggestion poisoning. Some wallets and explorers auto-suggest addresses you've "interacted with." Once a poison address is in your history, it can surface in autocomplete — making the wrong address one careless tap away.
Why it works so well
- We trust our own history. An address that's already in your ledger feels vetted — but "it's in my history" only means someone put it there, not that you chose it.
- We only check the ends. Matching the first and last characters is exactly the shortcut the attack defeats. The lookalike is engineered to pass that glance.
- It's cheap and scalable. Generating vanity lookalikes and blasting dust is automated and costs the attacker almost nothing, so they poison thousands of wallets and wait for a few to slip. Individual victims have lost six and seven figures to a single mistaken paste.
- It survives good opsec. You can use a hardware wallet, a strong password, and a private connection and still fall for this — because the failure is a copy-paste habit, not a compromised device.
How to make yourself immune
The fix is a fixed routine, not vigilance-when-you-remember:
- Never copy an address from your transaction history. This single rule defeats address poisoning outright. Always pull a fresh address from the real source — the recipient's wallet, or the exchange's official deposit page for that specific swap.
- Use a saved address book / whitelist. Save trusted addresses once, from the source, and send only to saved entries — don't re-derive them from past transactions.
- Verify the whole string, or at least both ends and the middle. Poisoning matches the first and last characters, so checking only the ends is not enough. For anything meaningful, compare the entire address, or several characters from the middle too.
- Confirm on your hardware wallet's own screen. If you use a hardware device, read the destination address on the device display — not just the computer — before approving.
- Ignore and hide dust. Don't interact with unexpected tiny deposits or unknown tokens. Many wallets let you hide them; never use them as a source to copy an address from.
- Send a small test first for large transfers, and watch it land using a block explorer before sending the rest.
Address poisoning vs. the other address tricks
Poisoning is one of a family of "send it to the wrong place" attacks. It pairs with clipboard hijacking (malware swaps the address you copied), malicious pages that display a different deposit address, and QR swaps where the scanned code encodes something other than the text beside it. The defenses overlap, and they're all covered in our companion guide on how to double-check the address every time. The throughline is the same: get the address from the real source and verify it before you send — never trust an address just because it's already sitting in front of you.
Swap with confidence on SwapRaven
Address poisoning wins on autopilot — a familiar-looking string, a quick copy, an irreversible send. Breaking the habit costs you a few seconds and saves you everything: pull addresses from the source, keep a whitelist, verify the full string, and test-send large amounts. SwapRaven grades no-KYC instant swaps on trust and transparency so you start each swap from a legitimate exchange with a genuine deposit address — then it's on you to confirm that address, every single time, before you hit send.

Comments (0)
Leave a comment