Term
Address poisoning
Address poisoning is a scam where an attacker sends a zero-value or dust transaction from an address that looks visually similar to one the victim recently used — hoping the victim copies the poisoned address from their transaction history on a future send.
Address poisoning is a class of attack that exploits how people copy crypto addresses. The attacker generates an address whose first few and last few characters match an address the victim has previously interacted with, then sends the victim a zero-value or dust transaction from that lookalike address. The poisoned address now appears in the victim's transaction history.
The trap springs when the victim later wants to send to the original address and copies from their transaction history — a wallet or explorer view that shows only truncated addresses. They copy the poisoned address by mistake, paste it into the send screen, and lose the funds. The visible characters look right; the middle differs completely.
Defenses are simple but require discipline. Always verify the full address before sending, not just the first and last few characters. Prefer copying from an address book or the original source (an invoice, a message), not from transaction history. Hardware wallets that display the full address on-device add another layer, but only if you actually read the full string.
Want to put this to work?