What Is Address Poisoning? The Wallet Copy-Paste Scam
Address poisoning explained: how scammers plant lookalike addresses in your transaction history to trick you into sending funds to the wrong place.
Address poisoning is a scam in which an attacker sends a tiny or zero-value transaction from a wallet address deliberately crafted to closely resemble one of your frequently used addresses, hoping you'll later copy the scammer's lookalike address from your transaction history by mistake instead of the correct one.
Most people don't retype full crypto addresses character by character — they copy an address from a previous transaction in their wallet's history or from a block explorer, trusting that it matches an address they've used before. Address poisoning exploits exactly that habit.
How the scam works step by step
Crypto addresses are long strings of characters, and most wallet interfaces only display a truncated version showing the first few and last few characters (for example, "0x4F3a...9c1B"). Scammers use software to generate vanity addresses that match the beginning and ending characters of an address you've genuinely transacted with before, even though the full address in the middle is completely different and belongs entirely to the attacker.
The scammer then sends a negligible or zero-value transaction from this lookalike address to your wallet, which causes it to appear in your transaction history. Later, when you go to send funds to your real, familiar contact or your own other wallet, you might glance at your history, see what looks like the right address (because the visible truncated portion matches), copy it, and send your funds — straight to the scammer instead.
Because the truncated display matches and the transaction appears to involve an address you've "seen before" in your own history, this attack can fool even relatively careful users who have learned to double-check but only compare the shortened version shown in their wallet interface.
Why this scam is effective
- It requires no interaction, approval, or signature from the victim to plant the poisoned entry — the attacker just needs to broadcast a cheap transaction to the victim's public address
- It exploits normal, otherwise-safe behavior (copying from transaction history) rather than tricking someone into an obviously risky action
- Truncated address displays, meant to improve readability, are precisely what makes the lookalike convincing
- It can target high-value wallets specifically, since attackers can monitor public blockchain activity to find and poison whales or frequent traders
How to protect yourself
- Always verify the full address, not just the truncated display, before confirming any significant transfer — most wallets let you expand or copy the complete string for comparison
- Save frequently used addresses to a trusted address book within your wallet rather than copying from transaction history each time
- Send a small test transaction first when transferring to an address for the first time or after a long gap, and confirm receipt before sending the full amount
- Use a hardware wallet that displays the full destination address on its own screen for verification before signing, adding a layer of protection against a compromised computer display
- Be wary of any transaction appearing in your history that you don't recognize sending or receiving, even if it involves no funds of consequence
A more advanced variant: poisoning with matching transaction amounts
Some more sophisticated address poisoning attempts go further than just matching the visible start and end characters of an address. Attackers have been observed sending a poisoned transaction for an amount that closely matches a real transaction you recently made, so that if you're scanning your history looking for "the transaction where I sent X amount to this contact," the poisoned entry appears to match on multiple details at once, not just the address format. This makes a quick, half-attentive review of transaction history even less reliable as a verification method, reinforcing why checking the complete address rather than any partial or contextual match is the only dependable defense.
Address poisoning vs. related wallet scams
| Scam type | Mechanism | Requires victim signature? |
|---|---|---|
| Address poisoning | Lookalike address planted in transaction history | No |
| Fake airdrop claim | Malicious approval disguised as a token claim | Yes |
| Clipboard hijacking malware | Malware swaps copied address before pasting | No (malware acts automatically) |
| Fake support scam | Social engineering to extract seed phrase or remote access | Yes (indirectly) |
Address poisoning is unusual among wallet scams in that it requires zero action or signature from the victim to set up — the trap is planted passively, and only the eventual copy-paste mistake completes the theft. Related tactics like clipboard hijacking malware achieve a similar end result through different means, by altering an address you've copied rather than planting a fake one in your history.
Bottom line
Address poisoning succeeds by exploiting the normal habit of copying addresses from transaction history rather than typing them out, using visually similar addresses that only match at a glance. The fix is straightforward but requires discipline: always verify a full address before a meaningful transfer, rely on a saved address book instead of history, and consider a small test send for new or infrequent destinations. For more on general wallet hygiene, see our guide to DeFi wallet security and browse the broader landscape of tactics in common DeFi scams.
Related articles
This article is for educational purposes only and is not financial advice. DeFi involves significant risk, including total loss of funds. Always do your own research.