Address poisoning: how a lookalike in your history steals your next paste
In May 2024, a single copy from a transaction history sent 1,155 WBTC — about $68 million — to a stranger who had seeded a near-identical address. Here's how the trap works, and the rule that defeats it.
On May 3, 2024, an Ethereum whale sent 1,155 Wrapped Bitcoin — worth about $68 million at the time — to an address they never intended to use. Security firms Cyvers and CertiK and the on-chain investigator ZachXBT flagged the transfer. The money had gone to an attacker who planted the trap ahead of time and simply waited for a careless paste.
The technique is called address poisoning, sometimes a "dust" attack, and it preys on a habit nearly every crypto user shares: trusting an address because its ends look right, and reusing one that already sits in your own history.
How the trap is set
The attacker pre-generated a wallet address whose first six and last six characters matched an address the victim used frequently. They then seeded the victim's transaction history with a tiny dust transfer from that lookalike, so it would sit in the ledger looking like a familiar counterparty.
The trap sprang after the victim made a genuine small test transfer to the real address. Minutes later, needing to move the full balance, they copied an address from their own transaction history — and copied the poisoned lookalike instead. About $68 million left the wallet in a single transaction.
This was not a lone stroke of luck. Per Chainalysis, the theft was one hit in a 66-day campaign running February 28 to May 4, 2024, in which eight seeder wallets poisoned roughly 82,031 addresses and ensnared about 2,774 victim addresses. Because WBTC appreciated afterward, some outlets such as The Block valued this single loss nearer $71 million.
Why checking the first and last characters fails
Wallet interfaces truncate long addresses to something like 0x1234…5678, and users learn to verify only those ends. Address poisoning is engineered against that exact shortcut: the head and tail match while the invisible middle is entirely different. A glance at the first and last characters confirms a forgery.
The only durable defenses treat both your clipboard and your transaction history as untrusted.
- Never copy a destination address from your transaction history — history is precisely where the attacker plants the lookalike.
- Paste only from a source you control: a saved contact or whitelist, a hardware-wallet screen, or an address the recipient confirmed directly.
- Verify the entire string, not just the first and last few characters, or check it character-by-character against the trusted source.
- Send a small test amount and have the recipient confirm receipt before you send the balance.
- Treat unexpected dust — tiny, unsolicited transfers from near-familiar addresses — as a sign you are being targeted, not as a real payment.
An unusual ending — and why it is no reassurance
This case is remembered partly for how it closed. Between roughly May 5 and 9, the victim negotiated directly on-chain, embedding messages in small ETH transfers — including a veiled warning to the thief: "We both know there's no way to clean this funds. You will be traced."
Starting around May 9 and 10, the attacker returned about 22,960 ETH — roughly $65.7 million, over 96% of the original dollar value — across some 225 transactions. Blockchain-investigation firm Match Systems and the U.K.-based exchange Cryptex each claimed credit for tracing the assets and facilitating the return.
Do not read that as a happy ending. The perpetrator was never publicly identified, and no arrests, charges, or regulatory action were reported; the recovery came through private negotiation, not any official proceeding. The thief remains at large, and the next victim of a poisoned paste is unlikely to get a refund.
— Sources: [Chainalysis](https://www.chainalysis.com/blog/address-poisoning-scam/) · [CoinDesk](https://www.coindesk.com/business/2024/05/03/exploiter-steals-68m-worth-of-crypto-through-address-poisoning) · [Cointelegraph](https://cointelegraph.com/news/wbtc-address-poisoner-all-funds-negotiations) · [Unchained](https://unchainedcrypto.com/68-million-stolen-in-dust-attack-returned-to-victim/)
NOT FINANCIAL ADVICE · VERIFY EVERYTHING