you are on the clearnet. the addresses listed here only open inside the tor network - download the tor browser here »
AlphaBay.Market
last update: 1 min ago 255 onions tracked
home / news / security
28 October 2025 security 4 min read

Address poisoning explained: how lookalike addresses drain crypto wallets

It takes one wrong copy-paste to lose a fortune on-chain. In an address poisoning attack, criminals seed your transaction history with lookalike wallets and simply wait for you to grab the wrong one. Here is how the scheme works, what it has already cost, and how to close it out of your life.

A vanity address built for your wallet

Attackers watch public blockchains for wallets that move funds often, especially in stablecoins such as USDT and USDC. Software then grinds out candidate addresses until one appears whose first and last few characters match a contact you pay regularly. Once a wallet truncates the string for display, the forged middle becomes invisible. Delivery follows fast. The scammer sends dust, a zero-value token transfer or even a counterfeit coin from the lookalike wallet to your address. The amount is worthless, but the entry it writes into your transaction history is the payload. As researchers at Chainalysis put it in their anatomy of the scam, the approach is simple, yet highly effective.
The scam relies on victims blindly copying addresses from their recent transaction history instead of verifying the string character by character.

Why copying from history betrays you

Nobody types a 42-character hexadecimal string by hand, so wallets train us to copy recipients from recent activity. Explorers shorten addresses to a prefix and suffix for readability, which means two very different strings can look identical on screen. That gap between display and reality is the entire attack. Engineers at Etherscan documented spoofed transfer events landing in victim histories as little as one minute after the legitimate transaction they mimicked, positioned exactly where a hurried user will look next. And once funds leave, there is no support desk to call. Blockchain transactions are final, which turns a two-second paste into a permanent payment to whoever controls the lookalike wallet.

The documented cost of one misclick

A two-year measurement study presented at USENIX Security 2025 detected more than 270 million poisoning attempts across Ethereum and BNB Smart Chain, targeting over 17 million addresses. Confirmed losses across 6,633 successful deceptions exceeded 83.8 million dollars. The flagship incident came on May 3, 2024, when a holder sent 1,155 WBTC, worth roughly 68 million dollars at the time, to a lookalike address confirmed by Certik analysts and CoinDesk reporting. Fortune intervened and the attacker returned everything. Even so, Chainalysis calculated the same campaign still cleared about 1.49 million dollars from other victims. Success rates hover near 0.03 percent, which sounds reassuring until you price the economics. Each seeded address costs fractions of a cent, so a single whale-sized hit repays millions of failed attempts many times over. Targets also skew toward high-balance, high-volume wallets, meaning active users are chosen deliberately.

Why address books beat transaction history

A saved contact is a string you verified once and stored on purpose. A transaction history is an append-only public log that any stranger with gas money can write into. Confusing those two sources of truth is the exact mistake this scam monetizes. Security guidance from the MetaMask team tells users to store every recurring recipient in the contacts feature precisely so they never need to scroll back through activity. Hardware wallet suites and exchange dashboards offer equivalent address book functions. Use them.
  • Copy deposit addresses only from saved contacts or the recipient's official channel.
  • Check the middle characters, not just the familiar prefix and suffix.
  • Treat any small unsolicited deposit as noise, never as a reference entry.
  • Send a test transfer, then verify where it actually landed before moving real value.

Layered checks for larger sums

For high-value moves, compare the pasted string against the original source character by character before signing. Modern wallets now warn when a destination closely resembles a previously used address, a guardrail worth reading rather than clicking through. Poisoning is not the only history-based hazard, either. Our coverage of clipboard hijackers explains malware that swaps addresses after you paste. Before sending bitcoin anywhere, run the destination through our bitcoin validator. Thirty seconds of checking beats an irreversible loss.

more notes

all news ›