Emerging Scams · Crypto Security
Crypto Address Poisoning
The scam that turns your own transaction history against you — by slipping in a wallet address that looks almost exactly like one you trust.
Updated Aug 2026 · 6 min read
Wallet · transaction history
0xA1b2C3…f8AABB — looks familiar, but isn’t
In December 2025, someone sent a $50 test transaction, saw it arrive, and then moved the real amount — 49,999,950 USDT. Twenty-six minutes later it was gone. They hadn’t been hacked. They’d copied a wallet address from their own history that looked right but wasn’t.
That’s address poisoning: an attacker plants a lookalike address in your transaction history so that, next time you pay, you copy theirs by mistake. It exploits a simple human habit — we recognize a wallet address by its first and last few characters, never the middle.
Why It’s So Costly
It has scaled into an industry. One study counted over 270 million poisoning attempts on BNB Chain and Ethereum in two years; the successful ones drove tens of millions in losses. The pace hasn’t slowed — Ethereum users alone lost a reported $62 million to address poisoning across December 2025 and January 2026, including a single $12.4 million mistake after the victim’s wallet had been quietly “dusted” for two months. The losses are large because the attack targets the one moment you’re moving real money. Zoom out and the scale is staggering — worldwide scam losses reached roughly $1 trillion in 2024, and crypto is a fast-growing slice of it.
How the Attack Works
They watch your wallet
Automated bots scan the blockchain for wallets that just moved funds to a counterparty — an exchange deposit address, a friend, a business.
They craft a lookalike
They generate a “vanity” address whose first and last few characters match that counterparty’s. At a glance — which is all most people check — it looks identical.
They poison your history
They send you a tiny “dust” transfer, or even a zero-value token transfer, from the lookalike address. Now it sits in your transaction history, looking like an address you’ve used before.
You copy the wrong one
Next time you pay that counterparty, you copy the address from your history to save time — and grab the poisoned lookalike instead. The crypto goes to the attacker, and because blockchain transactions are irreversible, it’s gone.
Red Flags in Your Wallet
- A tiny or zero-value transfer from an address that “almost” matches one you’ve paid before.
- Unexpected token spam or dust landing in your wallet, especially just after you sent a payment.
- Clusters of small transactions appearing near the time you last paid a counterparty.
Check an Address Before You Send
Paste the address you’re about to send to and the one you meant to use. Our checker highlights the matching ends versus the different middle — and flags the poisoning pattern instantly.
Open the address checker →How to Protect Yourself
- Verify the WHOLE address, character by character — never just the first and last few.
- Never copy an address from your transaction history. Get it from the original, trusted source every time.
- Save trusted addresses to a whitelist or address book and reuse those, not your history.
- For any large transfer, send a small test amount first and confirm it arrives before sending the rest.
- Use a hardware wallet, which makes you confirm the real destination on a separate screen.
Our pick
A hardware wallet is the strongest defence — it makes you confirm the real destination on a separate screen, even if malware or a poisoned address is in play. We recommend Ledger.
Partner link — it may earn us a commission at no cost to you. Learn how we make money.
Can You Get Your Money Back?
Honest answer: it depends almost entirely on how you paid and how fast you act. Speed is everything — report within hours, not days.
- Credit cardOften
You can dispute the charge (a “chargeback”) through your card network. The strongest protection of any payment type.
- Bank transfer, UPI or debit cardSometimes — if you’re fast
Report within hours so the bank can try to freeze the receiving account before the money is moved on. In India, call 1930 or file at cybercrime.gov.in immediately.
- Payment apps (Zelle, Venmo, Cash App, PayPal)Varies
Often treated like cash. PayPal “Goods & Services” has buyer protection; “friends & family” and most instant transfers usually don’t. Report to the app and your bank.
- Gift cardsRare
Contact the card issuer immediately — occasionally they can freeze an unredeemed balance. After that, it’s almost always gone.
- CryptocurrencyHardest — usually not
Crypto transfers are irreversible and cross-border. Recovery is rare, but act fast: report the transaction (with the wallet address and transaction hash) to the exchange involved and to law enforcement. If the funds land in a regulated exchange, it can sometimes freeze them.
What Actually Helps
- 1Act immediately — the faster you report, the better any chance of a freeze or reversal.
- 2Contact your bank, card issuer, or payment app now and ask them to dispute, recall, or freeze the payment.
- 3Report it to the authorities — here’s who to contact wherever you live. You often need a police or report reference number to pursue a dispute.
- 4Save everything: transaction IDs, wallet addresses, screenshots, phone numbers and usernames.
!Beware “recovery” scams
After you’ve been scammed, you may be contacted by someone promising to recover your money for an upfront fee, a “tax”, or a crypto payment. That is a second scam — often run by the same people, working from lists of known victims. No legitimate agency, lawyer, or service guarantees recovery or asks you to pay up front, and real police and banks never charge you to investigate. Never pay anyone to get your money back.
Where to Report — Wherever You Are
If the crypto moved to an exchange, report it to that exchange immediately with the transaction hash — accounts can sometimes be frozen. Reporting fast gives the best chance of freezing the money before it’s gone. Then file with your national authority:
India — Helpline 1930 · cybercrime.gov.in
Report in the first hours (the “golden hour”) to freeze funds. Run by I4C, Ministry of Home Affairs.
United States — FTC · FBI IC3
reportfraud.ftc.gov and ic3.gov.
United Kingdom — Action Fraud
actionfraud.police.uk · 0300 123 2040 (in Scotland, call Police Scotland on 101).
Australia — Scamwatch (National Anti-Scam Centre)
scamwatch.gov.au.
Canada — Canadian Anti-Fraud Centre
antifraudcentre-centreantifraude.ca · 1-888-495-8501.
Anywhere else: contact your bank and local police right away, and search “report a scam” plus your country. For cross-border cases, econsumer.gov collects international complaints. Beware anyone who later offers to “recover” your money for an upfront fee — that is a second scam.
Frequently Asked Questions
What is a zero-value transfer?
A quirk of the ERC-20 token standard lets anyone move zero tokens “from” any address without permission, paying only a little gas. Attackers use it to make a lookalike address appear in your history as if you’d interacted with it — no dust needed.
Can I get funds back if I sent them to a poisoned address?
Almost never — blockchain transactions are irreversible. If the funds land at an exchange you can report it fast and they may freeze the account, but recovery is rare. And beware anyone who contacts you promising to recover funds for a fee; that’s a follow-up scam.
How do I check an address before sending?
Verify the whole address, not just the ends, and compare it against a saved contact or the original trusted source — never your transaction history. Our free Crypto Address Checker compares two addresses and flags the poisoning pattern for you.
Does a hardware wallet help?
Yes. A hardware wallet makes you confirm the real destination on a separate screen, which defeats many address swaps and malware — though you still must verify the full address.
Keep going: check an address now, or browse all our scam guides.
Sources: ScamSniffer and on-chain security research; academic analysis of BNB Chain and Ethereum poisoning attempts; 2025–2026 incident reporting. Figures are drawn from public reporting and should be verified against primary sources.