Prices: CoinGecko

Address poisoning: how lookalike addresses trick you into misdirected transfers

Address poisoning plants lookalike wallet addresses in your transaction history. Learn how the scam works, real data on its scale, and how to avoid it.

Intermediate4 min readUpdated October 4, 20264 sources
On this page
  1. How address poisoning works
  2. How big the problem is
  3. Warning signs
  4. How to protect yourself
  5. If you sent funds to a poisoned address

Key takeaways

  • Address poisoning works by sending you tiny or fake transfers from an address that matches the first and last characters of one you use, hoping you copy it from your history later.
  • Researchers counted about 270 million poisoning attempts on Ethereum and BNB Smart Chain over two years, with at least $83.8 million lost.
  • Never copy addresses from transaction history; use a saved address book, verify the full address and send a test amount for large transfers.

Address poisoning is a scam that relies on a shortcut many people take: copying a wallet address from recent transactions. Attackers plant a lookalike address in your history and wait for you to paste the wrong one.

How address poisoning works

Crypto addresses are long strings, so wallets often shorten them to the first and last few characters, like 0xd9A1…a3F2. Attackers exploit that.

  1. They watch. Automated tools scan public blockchains for wallets that regularly send to the same addresses, such as an exchange deposit address or a business partner.
  2. They generate a lookalike. Software creates new addresses until one matches the start and end of the address you use.
  3. They poison your history. The attacker sends a tiny amount, a zero-value token transfer, or a counterfeit token from the lookalike address, so it shows up in your recent activity.
  4. They wait. Next time you copy an address from your history, you may grab theirs. Because blockchain transfers are final, the money is gone.

Chainalysis notes that ready-made address poisoning toolkits are sold on darknet markets, which makes the attack easy to run at scale.

How big the problem is

A study by Carnegie Mellon University researchers, “Blockchain Address Poisoning,” measured two years of activity on Ethereum and BNB Smart Chain. It found about 270 million attack attempts aimed at 17 million victims between July 2022 and June 2024. At least 6,633 attempts succeeded, causing at least $83.8 million in losses.

The largest cases are dramatic. Chainalysis describes a May 2024 incident in which a holder sent about $68 million in wrapped bitcoin to a poisoned address that matched only the first characters of the intended one. The attacker later returned the funds after negotiations, an unusual outcome that should not be expected.

The researchers also found that attackers time their poisoning transfers shortly after a victim's real transactions and pick addresses with as many matching characters as they can generate, some using powerful GPUs.

Warning signs

  • Incoming transfers of zero value or tiny amounts from addresses you do not recognize.
  • Unknown tokens appearing in your wallet, sometimes named like a real stablecoin.
  • Two entries in your history that look identical at a glance but differ in the middle characters.
  • Activity that appears right after you send a test transaction.

How to protect yourself

  1. Never copy addresses from transaction history. Get the address from the source: the exchange's deposit page, the recipient directly, or a saved contact.
  2. Use your wallet's address book for addresses you send to often, and label them clearly.
  3. Check the full address, not just the first and last characters. Compare it in chunks, including the middle.
  4. Verify on a hardware wallet screen where possible, since malware can also swap addresses in your clipboard.
  5. Send a test amount for large transfers, confirm it arrived, then re-check the address before the main transfer.
  6. Hide or ignore spam tokens. Do not try to sell or swap them.
  7. Consider wallets that flag poisoning. Some wallets now warn about lookalike addresses or hide zero-value transfers. Treat this as a backup, not a replacement for checking.

If you sent funds to a poisoned address

Act quickly. If the funds were on a regulated exchange or are a stablecoin, contact the exchange or issuer through official channels and report the transaction. File at ic3.gov, add the address to Chainabuse, and keep the transaction hash. As the FTC explains, crypto payments typically can only be reversed if the recipient sends them back, so be wary of anyone offering paid recovery.

For related threats, read about phishing and wallet drainers or return to the security and scams hub.

Frequently asked questions

Did the attacker get access to my wallet?

No. Receiving a poisoning transfer does not give anyone control of your wallet. The danger is only that you might later send funds to the lookalike address by mistake.

Should I interact with the strange tokens in my wallet?

No. Ignore or hide unknown tokens and zero-value transfers. Trying to sell or move them can lead you to a phishing site or a malicious contract.

Does a test transaction protect me?

It helps confirm the recipient, but attackers sometimes poison your history right after a test. Verify the full address again before the main transfer.

Sources

  1. Anatomy of an Address Poisoning Scam — Chainalysis
  2. Blockchain Address Poisoning — arXiv (Carnegie Mellon University researchers)
  3. CyLab study uncovers 270 million crypto phishing attempts — Carnegie Mellon University CyLab
  4. What To Know About Cryptocurrency and Scams — Federal Trade Commission

Updated October 4, 2026 by The Crypto Guide editorial team. Educational content, not financial, legal or tax advice. Spot an error? Request a correction.