Skip to main content
Don't invest unless you're prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong. Take 2 min to learn more.

Address poisoning

A scam that plants look-alike addresses in your transaction history hoping you will copy the wrong one for your next transfer.

Address poisoning is a scam of patience. The attacker generates an address whose first and last few characters match one you genuinely use, sends a tiny or zero-value transaction so it appears in your history, and waits. Weeks later, you copy an address from a past transaction instead of from the destination itself, check the first four and last four characters, see what you expect to see, and send funds to the impostor.

It works because of two habits: copying addresses from transaction history, and verifying only the ends. Crypto addresses are long enough that people check a few characters and trust the middle, and vanity-address tools make matching those few characters cheap.

The defences are unglamorous. Copy addresses only from the destination source itself (the receiving wallet, the platform's deposit screen), never from history. Compare more than the ends, or better, use your wallet's address book so trusted destinations have names. For a large transfer, send a small test amount first and confirm it arrived where you meant, exactly as you would with a new bank payee.

The tiny planted transactions are cousins of dust: they cost the attacker almost nothing and sit harmlessly until a rushed moment turns them expensive. The fix is a habit, not a product.

Buy Ethereum

Last updated: 02 August 2026