How address poisoning turns your own transaction history into bait
Attackers seed your wallet log with near-identical lookalike addresses, betting one hurried copy-paste sends your funds to them. Chainalysis traced a single campaign across 82,031 spoofed addresses.
Most crypto thefts break in through the front door — a stolen seed phrase, a signed malicious transaction. Address poisoning is quieter, and it never touches your keys. Instead it corrupts the one record you trust without a second thought: your own transaction history. The mechanics are cheap, scalable, and aimed squarely at habit rather than any flaw in the cryptography.
How the trap is set
The attacker first watches the chain for active, high-balance wallets, per Chainalysis. Using software that grinds through millions of keypairs, they generate a 'vanity' address whose opening and closing characters match one you deal with often — an exchange deposit address, say, or a frequent counterparty. Because most wallet apps abbreviate addresses to their first and last few characters, the counterfeit looks identical at a glance.
They then send you a tiny transfer, or even a zero-value one, from that lookalike so it lands in your history. A later refinement abuses Ethereum's transferFrom function to log a transfer of no value that you never signed. The entry costs the attacker almost nothing and needs no access to your wallet. It simply sits in your ledger, waiting for the day you scroll back, copy a 'recent' address, and pay the wrong party.
What the numbers reveal
Chainalysis dissected one campaign that ran 66 days, from February 28 to May 4, 2024. Eight coordinating 'seeder' wallets generated 82,031 spoofed addresses and tried to redirect $69,720,993 across 2,774 victim addresses, per Chainalysis. Only about 0.03% of the fake addresses ever received more than $100 — but the targets were chosen for size, holding an average of $338,900. Even after much of the money was returned, roughly $1.49 million was actually stolen, against a typical 2024 scam profit of around $400.
The economics explain the patience. A single successful hit dwarfs thousands of failures, so attackers spray lookalikes across tens of thousands of wallets and simply wait for one careless transfer.
- Never copy a payment address out of your transaction history; use a saved, verified contact or an address the recipient just shared.
- Check the entire string, not only the first and last four characters — poisoned addresses match only the ends.
- Send a small test amount and confirm receipt before moving a large balance, as Chainalysis advises.
- Use your wallet's address book or allowlist so known destinations are labeled and locked in.
- Treat any unexpected tiny or zero-value incoming transfer as a warning sign, not a curiosity.
Address poisoning works precisely because it asks nothing of you but a moment's inattention. The defense is dull and dependable: verify the whole address, every time, from a source you control rather than one an attacker may have quietly written into your log.
— Sources: [Chainalysis](https://www.chainalysis.com/blog/address-poisoning-scam/)
NOT FINANCIAL ADVICE · VERIFY EVERYTHING