Stand Against Crime

Emerging Scams · Crypto Security

Crypto Address Poisoning

The scam that turns your own transaction history against you — by slipping in a wallet address that looks almost exactly like one you trust.

Updated Aug 2026 · 6 min read

Address Poisoning

Wallet · transaction history

0xA1b2C3…f8AABB — looks familiar, but isn’t

Lookalike address

In December 2025, someone sent a $50 test transaction, saw it arrive, and then moved the real amount — 49,999,950 USDT. Twenty-six minutes later it was gone. They hadn’t been hacked. They’d copied a wallet address from their own history that looked right but wasn’t.

That’s address poisoning: an attacker plants a lookalike address in your transaction history so that, next time you pay, you copy theirs by mistake. It exploits a simple human habit — we recognize a wallet address by its first and last few characters, never the middle.

Why It’s So Costly

It has scaled into an industry. One study counted over 270 million poisoning attempts on BNB Chain and Ethereum in two years; the successful ones drove tens of millions in losses. The pace hasn’t slowed — Ethereum users alone lost a reported $62 million to address poisoning across December 2025 and January 2026, including a single $12.4 million mistake after the victim’s wallet had been quietly “dusted” for two months. The losses are large because the attack targets the one moment you’re moving real money. Zoom out and the scale is staggering — worldwide scam losses reached roughly $1 trillion in 2024, and crypto is a fast-growing slice of it.

How the Attack Works

1

They watch your wallet

Automated bots scan the blockchain for wallets that just moved funds to a counterparty — an exchange deposit address, a friend, a business.

2

They craft a lookalike

They generate a “vanity” address whose first and last few characters match that counterparty’s. At a glance — which is all most people check — it looks identical.

3

They poison your history

They send you a tiny “dust” transfer, or even a zero-value token transfer, from the lookalike address. Now it sits in your transaction history, looking like an address you’ve used before.

4

You copy the wrong one

Next time you pay that counterparty, you copy the address from your history to save time — and grab the poisoned lookalike instead. The crypto goes to the attacker, and because blockchain transactions are irreversible, it’s gone.

Red Flags in Your Wallet

  • A tiny or zero-value transfer from an address that “almost” matches one you’ve paid before.
  • Unexpected token spam or dust landing in your wallet, especially just after you sent a payment.
  • Clusters of small transactions appearing near the time you last paid a counterparty.
Free tool · runs in your browser

Check an Address Before You Send

Paste the address you’re about to send to and the one you meant to use. Our checker highlights the matching ends versus the different middle — and flags the poisoning pattern instantly.

Open the address checker →

How to Protect Yourself

  1. Verify the WHOLE address, character by character — never just the first and last few.
  2. Never copy an address from your transaction history. Get it from the original, trusted source every time.
  3. Save trusted addresses to a whitelist or address book and reuse those, not your history.
  4. For any large transfer, send a small test amount first and confirm it arrives before sending the rest.
  5. Use a hardware wallet, which makes you confirm the real destination on a separate screen.

Our pick

A hardware wallet is the strongest defence — it makes you confirm the real destination on a separate screen, even if malware or a poisoned address is in play. We recommend Ledger.

Partner link — it may earn us a commission at no cost to you. Learn how we make money.

If you already sent to a poisoned address: blockchain transactions can’t be reversed. Act fast anyway — if the funds moved to an exchange, report it to that exchange immediately with the transaction hash; they can sometimes freeze the account. Document everything, and ignore any “recovery” service that asks for an upfront fee.

Can You Get Your Money Back?

Honest answer: it depends almost entirely on how you paid and how fast you act. Speed is everything — report within hours, not days.

  • Credit cardOften

    You can dispute the charge (a “chargeback”) through your card network. The strongest protection of any payment type.

  • Bank transfer, UPI or debit cardSometimes — if you’re fast

    Report within hours so the bank can try to freeze the receiving account before the money is moved on. In India, call 1930 or file at cybercrime.gov.in immediately.

  • Payment apps (Zelle, Venmo, Cash App, PayPal)Varies

    Often treated like cash. PayPal “Goods & Services” has buyer protection; “friends & family” and most instant transfers usually don’t. Report to the app and your bank.

  • Gift cardsRare

    Contact the card issuer immediately — occasionally they can freeze an unredeemed balance. After that, it’s almost always gone.

  • CryptocurrencyHardest — usually not

    Crypto transfers are irreversible and cross-border. Recovery is rare, but act fast: report the transaction (with the wallet address and transaction hash) to the exchange involved and to law enforcement. If the funds land in a regulated exchange, it can sometimes freeze them.

What Actually Helps

  1. 1Act immediately — the faster you report, the better any chance of a freeze or reversal.
  2. 2Contact your bank, card issuer, or payment app now and ask them to dispute, recall, or freeze the payment.
  3. 3Report it to the authorities — here’s who to contact wherever you live. You often need a police or report reference number to pursue a dispute.
  4. 4Save everything: transaction IDs, wallet addresses, screenshots, phone numbers and usernames.

!Beware “recovery” scams

After you’ve been scammed, you may be contacted by someone promising to recover your money for an upfront fee, a “tax”, or a crypto payment. That is a second scam — often run by the same people, working from lists of known victims. No legitimate agency, lawyer, or service guarantees recovery or asks you to pay up front, and real police and banks never charge you to investigate. Never pay anyone to get your money back.

Where to Report — Wherever You Are

If the crypto moved to an exchange, report it to that exchange immediately with the transaction hash — accounts can sometimes be frozen. Reporting fast gives the best chance of freezing the money before it’s gone. Then file with your national authority:

Anywhere else: contact your bank and local police right away, and search “report a scam” plus your country. For cross-border cases, econsumer.gov collects international complaints. Beware anyone who later offers to “recover” your money for an upfront fee — that is a second scam.

Frequently Asked Questions

What is a zero-value transfer?

A quirk of the ERC-20 token standard lets anyone move zero tokens “from” any address without permission, paying only a little gas. Attackers use it to make a lookalike address appear in your history as if you’d interacted with it — no dust needed.

Can I get funds back if I sent them to a poisoned address?

Almost never — blockchain transactions are irreversible. If the funds land at an exchange you can report it fast and they may freeze the account, but recovery is rare. And beware anyone who contacts you promising to recover funds for a fee; that’s a follow-up scam.

How do I check an address before sending?

Verify the whole address, not just the ends, and compare it against a saved contact or the original trusted source — never your transaction history. Our free Crypto Address Checker compares two addresses and flags the poisoning pattern for you.

Does a hardware wallet help?

Yes. A hardware wallet makes you confirm the real destination on a separate screen, which defeats many address swaps and malware — though you still must verify the full address.

Sources: ScamSniffer and on-chain security research; academic analysis of BNB Chain and Ethereum poisoning attempts; 2025–2026 incident reporting. Figures are drawn from public reporting and should be verified against primary sources.

Warn someone — share this