Address Poisoning Scams Explained: Don't Copy the Wrong Address
Learn how address poisoning scams trick users into copying a lookalike address from their transaction history, and how to protect yourself.
Address poisoning is a scam where an attacker sends a tiny, often worthless transaction from a wallet address deliberately crafted to closely resemble one you've genuinely transacted with before, hoping that later, when you go to send funds again, you'll copy the fraudulent lookalike address directly from your transaction history instead of the correct one, sending your funds to the attacker instead.
This scam doesn't require tricking you into clicking a malicious link or entering a seed phrase anywhere — it exploits an entirely different, more mundane habit: copying a previously used address from your own wallet's transaction history rather than re-verifying it in full each time.
How the attack works step by step
- The attacker monitors blockchain activity, watching for wallets that regularly send funds to a specific, recurring address — for example, your own frequently used savings wallet, or an exchange deposit address you send to often.
- The attacker generates a new address that shares the same first and last several characters as your real, frequently used address, exploiting the fact that most people only glance at the beginning and end of an address rather than reading the entire string.
- The attacker sends a tiny amount of a token, or in some cases zero-value transactions, from this lookalike address to your wallet, ensuring it appears in your transaction history.
- Later, when you intend to send funds to your usual address, you open your transaction history to copy it, as many people do out of convenience, and if you're not careful, you copy the poisoned lookalike address instead, since it appears visually similar at a glance.
- Funds sent to that address go directly to the attacker, and the transaction is irreversible once confirmed.
Why this scam works
The attack succeeds because it targets a genuinely common, seemingly harmless habit — reusing a previous transaction as a shortcut to avoid retyping or re-copying an address from an external source. Most wallet interfaces display transaction history with addresses often truncated to just the first and last few characters, which is precisely enough to fool a quick visual check while differing entirely in the middle.
It also requires no interaction from the victim to set up — the attacker simply sends the poisoning transaction and waits, meaning a user can be targeted without ever clicking a suspicious link or falling for an obvious phishing message.
How to protect yourself
- Never copy an address directly from transaction history without verifying it in full first. Instead, maintain your own trusted, independently saved copy of frequently used addresses — such as in a wallet's dedicated address book feature, if it verifies entries at the time they're added rather than pulling from history.
- Always check the complete address, not just the beginning and end, especially before sending any significant amount — see how to verify a wallet address for a full verification checklist.
- Use a hardware wallet's own screen to confirm the destination address before signing, since it displays the address independently of a potentially manipulated or truncated view in browser software.
- Be suspicious of small, unexpected transactions appearing in your history from unfamiliar or unexplained sources, particularly ones with no clear reason for being sent to you — this can be a strong signal that poisoning is being attempted against your wallet specifically.
- Consider using a fresh, newly generated address for a new significant recipient rather than assuming a historical entry is trustworthy simply because it appears in your own records.
Comparing address poisoning to other address-related risks
| Risk | Mechanism | Key defense |
|---|---|---|
| Address poisoning | Lookalike address planted in transaction history | Verify full address, don't blindly reuse from history |
| Clipboard hijacking | Malware swaps a copied address before pasting | Verify pasted address against original source |
| Vanity address scams | Third-party generates a custom address, keeping the key | Never accept a pre-generated address/key from a third party |
| Manual typo | Human error when typing an address by hand | Rely on checksum validation, double-check carefully |
Why this scam is particularly hard to notice
Unlike phishing emails or fake websites, which sometimes have telltale signs once you know to look for them, address poisoning leaves no obvious red flag within the transaction itself — the poisoning transaction is a real, valid blockchain transaction, and the lookalike address is a real, functioning address; it simply isn't yours or your intended recipient's. This makes it one of the more purely mechanical scams in crypto, relying entirely on a predictable human shortcut rather than any form of social engineering or malware.
What to do if you've been targeted or affected
If you notice suspicious small transactions in your history that resemble your own frequently used addresses, avoid interacting with them and don't copy them under any circumstances. If you've already sent funds to a poisoned address by mistake, recovery is generally not possible given the irreversible nature of confirmed blockchain transactions — prevention through careful verification remains the only reliable defense, consistent with the broader scam awareness covered in common DeFi scams.
Bottom line
Address poisoning exploits the habit of copying a previously used address from transaction history, planting a lookalike address that shares the same visible start and end characters as your genuine, frequently used destination. Defending against it requires verifying the complete address every time, rather than trusting a truncated view or an entry pulled from history, and treating small unexplained transactions in your wallet's history as a potential warning sign rather than an inconsequential curiosity.
Related articles
This article is for educational purposes only and is not financial advice. DeFi involves significant risk, including total loss of funds. Always do your own research.