FindCoin / Blog / Address Poisoning Attacks: How Scammers Trick You Into Wrong Transfers

Scam Detection

Address Poisoning Attacks: How Scammers Trick You Into Wrong Transfers

July 13, 2026 · 12 min read

Address poisoning is one of the most psychologically clever scams in crypto, because it doesn’t attack your wallet at all — it attacks your habits. Specifically, it exploits the way almost everyone copies addresses: by glancing at the first and last few characters and copying from recent transaction history. The scammer plants a lookalike address in your history so that the next time you copy-paste, you send your funds to them. This guide explains exactly how it works and the simple habits that make it impossible to fall for.

SCAM DETECTION · FINDCOIN Address Poisoning:How a LookalikeSteals Your Transfer 0x7a…4f2b
FIG 01This scam doesn’t break your wallet — it exploits how you copy addresses.

What makes address poisoning so insidious is that the victim does everything ‘normally.’ You go to send funds, you copy an address that looks right, you paste it, you confirm. There’s no malicious signature to spot, no fake site, no approval to reject. The only mistake is copying the wrong address — one the scammer deliberately made look like the right one, and deliberately placed where you’d reach for it. Because blockchain transfers are irreversible, that single copy-paste error can mean total, unrecoverable loss.

It’s worth appreciating what category of scam this is, because it’s genuinely different from most. There’s no malware, no stolen password, no phishing site to detect, and no malicious signature to reject. Every part of the transaction you eventually make is legitimate in the technical sense — you really are sending your funds, from your wallet, with your own confirmation. The only thing wrong is the destination. This makes address poisoning invisible to most security tools and safeguards, which are looking for malicious code or signatures, not a correct-looking transfer to the wrong place. The defense can’t be technical; it has to be a habit change on your part.

How address poisoning works

The attack has a clear structure, and seeing it laid out reveals how to break it. The scammer is patient and methodical.

HOW ADDRESS POISONING WORKS1Scammer watchesyour transactions2Sends dustfrom a lookalike3It landsin your history4You copy itby mistake
FIG 02The attack plants a decoy in your own transaction history.

First, the scammer monitors the blockchain for wallets making transactions — often watching addresses you frequently send to. Then they generate a lookalike address that matches the start and end of a real address you use. They send a tiny transaction (dust) or even a fake zero-value one from that lookalike, so it appears in your transaction history. Now the trap is set: the next time you go to send funds and copy an address from your recent history, you might grab the scammer’s lookalike instead of the real one. You paste, confirm, and your funds go to them.

Why lookalike addresses fool us

The genius of the attack is that it targets a specific, near-universal human shortcut. Crypto addresses are long strings of random characters that no one memorizes or reads in full — so we verify them by checking the beginning and end.

WalletSendRecipient address0x7a3f…4f2bLookalike detected — check middleAmount1.0 ETHNetwork fee (gas)~0.0012 ETHSend test transaction firstSend
FIG 03Lookalike addresses match the start and end you actually check.

A real address like 0x7a3f…4f2b gets mentally reduced to ‘7a3f at the start, 4f2b at the end.’ The scammer knows this, so they generate a lookalike that matches exactly those visible characters — the first few and the last few — while the unchecked middle is completely different. When you glance at the two, they look identical, because you’re only looking at the parts that do match. The attack succeeds precisely because it mimics the shortcut you rely on. The middle of the address, which you never verify, is where the difference hides.

The core vulnerability is verifying an address by its first and last characters. Scammers can generate addresses matching any specific start and end, so checking only the ends provides a false sense of security — it’s exactly the check the attack is designed to defeat.

A useful way to hold all these variants in mind is to focus on the one thing they can’t change: the full address. No matter how the scammer dresses up the decoy — dust, fake token, zero-value transaction, spoofed display — the malicious address they want you to copy will differ from the real one somewhere in its full length. They can match the first and last characters you glance at, but they cannot produce an address that is identical to the real one everywhere, because that would require breaking the cryptography itself. This is why full-address verification is a complete defense: it checks the one property the attacker is fundamentally unable to fake.

Variants of the attack

Address poisoning comes in several forms, but they all share the same objective: get a lookalike address into your transaction history where you might copy it.

VARIANTS OF THE ATTACKZero-value transfer (fake tx)80Dust from a lookalike address75Fake token mimicking a real one70Contract-spoofed history entry85All variants share one goal: get a lookalike address into your history.
FIG 04Several techniques, one objective — plant a decoy you’ll copy.

The dust transfer sends a tiny real amount from the lookalike. The zero-value transfer uses a contract trick to make a transaction appear in your history without actually sending anything. The fake token variant sends a worthless token mimicking a real one you hold, from a lookalike address. And contract-spoofed entries manipulate how transactions display. The technical details differ, but the endgame is identical every time: plant a decoy address you might later copy by mistake. Recognizing the shared goal means you can defend against all variants with the same habits.

The moment of danger

It’s worth dwelling on how the loss actually happens, because it clarifies why prevention matters so much. The dust or fake transaction itself is harmless — it can’t take anything. The danger is entirely in your next transfer.

THE MOMENT OF DANGEROne careless copy-paste and a large transfer goes to the scammer, irreversibly.
FIG 05Address poisoning turns a routine transfer into a total loss.

Everything is fine until the day you go to send a meaningful amount to an address you use regularly. You open your wallet, copy what looks like the right address from your recent transactions, and send. If you grabbed the lookalike, your funds are now the scammer’s — irreversibly. The attack converts a routine, confident transfer into a catastrophic loss, and it does so at the one moment you’re least suspicious, because you’re just doing something you’ve done a hundred times before.

Why this scam is growing

Address poisoning has become more common for a simple reason: it’s cheap to run at massive scale and it costs the attacker almost nothing per attempt. Generating lookalike addresses and sending dust to thousands of wallets is inexpensive, and the scammer only needs a tiny fraction of recipients to slip up once for the campaign to be wildly profitable. Unlike attacks that require tricking you into signing something, poisoning just plants a decoy and waits — patience is free. This asymmetry, where one success can outweigh thousands of failures, is what makes it attractive to scammers and persistent as a threat.

The scale also explains why you shouldn’t take receiving poison dust personally or as a sign you’ve been specifically targeted. You’re almost certainly one of thousands of wallets caught in an automated net, not the focus of a dedicated attacker. That’s reassuring in one sense — there’s no one specifically after you — but it also means the dust will keep coming, so the defense has to be a permanent habit rather than a one-time reaction. Treat every transfer with the same full-address discipline, and the volume of attempts becomes irrelevant because none of them can land.

How to protect yourself

The good news is that address poisoning is one of the most completely preventable scams, because it relies on a specific bad habit that you can simply replace. Adopt these and the attack cannot land.

HOW TO PROTECT YOURSELF Verify the FULL address, not just the ends Use a saved address book / whitelist Send a small test transfer first Never copy addresses from tx history Ignore and hide dust you didn’t expect
FIG 06Five habits that make address poisoning impossible to land.
  • Verify the full address: check the entire string, not just the first and last characters. This single habit defeats the core of the attack.
  • Use a saved address book: save trusted addresses once (verified in full) and always send from your saved list, never from transaction history.
  • Send a test transfer first: for any large amount, send a small test and confirm it arrives at the right place before sending the rest.
  • Never copy from history: your transaction history is exactly where the decoy lives. Break the habit of copying addresses from it.
  • Ignore unexpected dust: if unfamiliar dust or tokens appear, don’t interact — hide or ignore them.

One reason this routine is worth building into muscle memory is that address poisoning specifically targets your moments of routine confidence — the transfers you make without thinking because you’ve done them a hundred times. The defense, therefore, has to live in the habit itself, not in your alertness, because alertness fades exactly when familiarity grows. By making full-address verification and a test transfer part of the mechanical process of sending — something you do every time, automatically — you remove the dependence on being suspicious in the one moment you’re least likely to be.

The safe transfer routine

Bundle these habits into a single routine you run for every meaningful transfer. It takes seconds and makes the scam impossible.

THE SAFE TRANSFER ROUTINE1Get addressfrom trusted source2Verify in fullevery character3Test smallconfirm arrival4Send restwith confidence
FIG 07A deliberate routine defeats the scam entirely.
1

Get the address from a trusted source

Retrieve the recipient address from a verified, trusted source — a saved address book, the recipient directly through a secure channel — not from your transaction history.

2

Verify it in full

Check the entire address, character by character or in meaningful chunks — not just the ends. If anything differs, stop.

3

Send a small test

For any significant amount, send a small test transfer first and confirm it arrives at the intended destination.

4

Send the rest with confidence

Once the test confirms, send the remainder knowing the address is correct.

Address book versus copying from history

The single most protective structural change is to stop copying addresses from transaction history entirely, and use a verified address book instead.

COPY FROM HISTORY vs. SAVED ADDRESS BOOK

Risk of copying a decoy 90 10 Speed 70 80 Safe for large transfers 15 92 Recommended 20 90

FIG 08Left (red)=copying from history. Right (violet)=a verified address book.

Copying from history is fast but dangerous — it’s the exact behavior the attack exploits, since the decoy lives in your history. A saved address book, where each address was verified in full when you added it, removes the risk almost entirely: you send from a trusted list, not from a feed the scammer can inject into. It’s marginally slower to set up, but for any address you use more than once — and certainly for large transfers — it’s the safe default. Build your address book, and address poisoning loses its landing spot.

If you receive suspicious dust

Since the attack starts with unexpected dust or fake tokens arriving, it helps to know the correct response: do nothing with them.

IF YOU RECEIVE SUSPICIOUS DUST Do not interact with the token Do not copy the sender’s address Do not visit any linked site Hide or ignore the entry Never sign anything it prompts
FIG 09Unexpected dust is bait — the safe response is to do nothing.

If unfamiliar dust, a strange token, or an unexpected transaction appears in your wallet, treat it as bait. Do not interact with the token, do not copy the sender’s address, do not visit any website it references, and never sign anything it prompts. Simply hide or ignore the entry. The dust itself is harmless as long as you don’t act on it — the danger only materializes if you copy that lookalike address later. The safest response to unexpected dust is complete non-engagement.

YOUR SUSCEPTIBILITY 20 LOW RISK Full-address checks · address book · test transfers
FIG 10Good transfer habits drop your risk close to zero.

FindCoin can help you spot poisoning attempts — flagging lookalike addresses near ones you use and letting you verify a recipient before you send. Combined with a test transfer, it turns every large send into a safe, deliberate action rather than a risky copy-paste.

STAY SAFE WITH FINDCOIN1Scan a sendersuspicious dust?2Flag lookalikesnear your addresses3Verify addressesbefore sending4Transfer safelytest first
FIG 11FindCoin helps you spot poisoning attempts and verify before you send.

Key takeaways

  • Address poisoning attacks your habits, not your wallet — it plants a lookalike address in your history so you copy the wrong one.
  • It works because we verify addresses by their first and last characters; scammers generate lookalikes matching exactly those visible ends.
  • The dust or fake transaction is harmless itself — the loss only happens when you later copy the decoy and send funds to it, irreversibly.
  • Defeat it by verifying the full address, using a saved address book instead of copying from history, and sending a test transfer for large amounts.
  • If unexpected dust or tokens arrive, do nothing — don’t interact, don’t copy the sender, don’t sign anything; simply ignore or hide it.

Frequently asked questions

What is address poisoning?

A scam where an attacker plants a lookalike address in your transaction history — via dust, a fake token, or a zero-value transfer — hoping you’ll copy it by mistake on your next transfer and send funds to them instead of the real recipient.

How does a lookalike address fool me?

Because people verify addresses by the first and last few characters, scammers generate an address that matches exactly those visible ends while differing in the unchecked middle. At a glance, it looks identical to the real one.

Is the dust they send dangerous by itself?

No — receiving dust or a fake token can’t take your funds. The danger is entirely in your next transfer, if you copy the scammer’s lookalike address from your history. Don’t interact with the dust, and it can’t hurt you.

How do I prevent address poisoning?

Verify the full address rather than just the ends, use a saved address book instead of copying from transaction history, and send a small test transfer before any large amount. These habits make the attack impossible to land.

What should I do if I get suspicious dust?

Nothing — treat it as bait. Don’t interact with the token, don’t copy the sender’s address, don’t visit any linked site, and never sign anything it prompts. Just hide or ignore the entry.

Disclaimer: This article is for information and education only and is not financial advice. Crypto assets are volatile and risky — always do your own research and never invest more than you can afford to lose.

Before you buy any token — check it

Paste a contract address and get a plain-language scam report in seconds.

Open the scam checker →