Address Poisoning Attacks: How Scammers Trick You Into Wrong Transfers
In this guide
Address poisoning is one of the most psychologically clever scams in crypto, because it doesn’t attack your wallet at all — it attacks your habits. Specifically, it exploits the way almost everyone copies addresses: by glancing at the first and last few characters and copying from recent transaction history. The scammer plants a lookalike address in your history so that the next time you copy-paste, you send your funds to them. This guide explains exactly how it works and the simple habits that make it impossible to fall for.
What makes address poisoning so insidious is that the victim does everything ‘normally.’ You go to send funds, you copy an address that looks right, you paste it, you confirm. There’s no malicious signature to spot, no fake site, no approval to reject. The only mistake is copying the wrong address — one the scammer deliberately made look like the right one, and deliberately placed where you’d reach for it. Because blockchain transfers are irreversible, that single copy-paste error can mean total, unrecoverable loss.
It’s worth appreciating what category of scam this is, because it’s genuinely different from most. There’s no malware, no stolen password, no phishing site to detect, and no malicious signature to reject. Every part of the transaction you eventually make is legitimate in the technical sense — you really are sending your funds, from your wallet, with your own confirmation. The only thing wrong is the destination. This makes address poisoning invisible to most security tools and safeguards, which are looking for malicious code or signatures, not a correct-looking transfer to the wrong place. The defense can’t be technical; it has to be a habit change on your part.
How address poisoning works
The attack has a clear structure, and seeing it laid out reveals how to break it. The scammer is patient and methodical.
First, the scammer monitors the blockchain for wallets making transactions — often watching addresses you frequently send to. Then they generate a lookalike address that matches the start and end of a real address you use. They send a tiny transaction (dust) or even a fake zero-value one from that lookalike, so it appears in your transaction history. Now the trap is set: the next time you go to send funds and copy an address from your recent history, you might grab the scammer’s lookalike instead of the real one. You paste, confirm, and your funds go to them.
Why lookalike addresses fool us
The genius of the attack is that it targets a specific, near-universal human shortcut. Crypto addresses are long strings of random characters that no one memorizes or reads in full — so we verify them by checking the beginning and end.
A real address like 0x7a3f…4f2b gets mentally reduced to ‘7a3f at the start, 4f2b at the end.’ The scammer knows this, so they generate a lookalike that matches exactly those visible characters — the first few and the last few — while the unchecked middle is completely different. When you glance at the two, they look identical, because you’re only looking at the parts that do match. The attack succeeds precisely because it mimics the shortcut you rely on. The middle of the address, which you never verify, is where the difference hides.
The core vulnerability is verifying an address by its first and last characters. Scammers can generate addresses matching any specific start and end, so checking only the ends provides a false sense of security — it’s exactly the check the attack is designed to defeat.
A useful way to hold all these variants in mind is to focus on the one thing they can’t change: the full address. No matter how the scammer dresses up the decoy — dust, fake token, zero-value transaction, spoofed display — the malicious address they want you to copy will differ from the real one somewhere in its full length. They can match the first and last characters you glance at, but they cannot produce an address that is identical to the real one everywhere, because that would require breaking the cryptography itself. This is why full-address verification is a complete defense: it checks the one property the attacker is fundamentally unable to fake.
Variants of the attack
Address poisoning comes in several forms, but they all share the same objective: get a lookalike address into your transaction history where you might copy it.
The dust transfer sends a tiny real amount from the lookalike. The zero-value transfer uses a contract trick to make a transaction appear in your history without actually sending anything. The fake token variant sends a worthless token mimicking a real one you hold, from a lookalike address. And contract-spoofed entries manipulate how transactions display. The technical details differ, but the endgame is identical every time: plant a decoy address you might later copy by mistake. Recognizing the shared goal means you can defend against all variants with the same habits.
The moment of danger
It’s worth dwelling on how the loss actually happens, because it clarifies why prevention matters so much. The dust or fake transaction itself is harmless — it can’t take anything. The danger is entirely in your next transfer.
Everything is fine until the day you go to send a meaningful amount to an address you use regularly. You open your wallet, copy what looks like the right address from your recent transactions, and send. If you grabbed the lookalike, your funds are now the scammer’s — irreversibly. The attack converts a routine, confident transfer into a catastrophic loss, and it does so at the one moment you’re least suspicious, because you’re just doing something you’ve done a hundred times before.
Why this scam is growing
Address poisoning has become more common for a simple reason: it’s cheap to run at massive scale and it costs the attacker almost nothing per attempt. Generating lookalike addresses and sending dust to thousands of wallets is inexpensive, and the scammer only needs a tiny fraction of recipients to slip up once for the campaign to be wildly profitable. Unlike attacks that require tricking you into signing something, poisoning just plants a decoy and waits — patience is free. This asymmetry, where one success can outweigh thousands of failures, is what makes it attractive to scammers and persistent as a threat.
The scale also explains why you shouldn’t take receiving poison dust personally or as a sign you’ve been specifically targeted. You’re almost certainly one of thousands of wallets caught in an automated net, not the focus of a dedicated attacker. That’s reassuring in one sense — there’s no one specifically after you — but it also means the dust will keep coming, so the defense has to be a permanent habit rather than a one-time reaction. Treat every transfer with the same full-address discipline, and the volume of attempts becomes irrelevant because none of them can land.
How to protect yourself
The good news is that address poisoning is one of the most completely preventable scams, because it relies on a specific bad habit that you can simply replace. Adopt these and the attack cannot land.
- Verify the full address: check the entire string, not just the first and last characters. This single habit defeats the core of the attack.
- Use a saved address book: save trusted addresses once (verified in full) and always send from your saved list, never from transaction history.
- Send a test transfer first: for any large amount, send a small test and confirm it arrives at the right place before sending the rest.
- Never copy from history: your transaction history is exactly where the decoy lives. Break the habit of copying addresses from it.
- Ignore unexpected dust: if unfamiliar dust or tokens appear, don’t interact — hide or ignore them.
One reason this routine is worth building into muscle memory is that address poisoning specifically targets your moments of routine confidence — the transfers you make without thinking because you’ve done them a hundred times. The defense, therefore, has to live in the habit itself, not in your alertness, because alertness fades exactly when familiarity grows. By making full-address verification and a test transfer part of the mechanical process of sending — something you do every time, automatically — you remove the dependence on being suspicious in the one moment you’re least likely to be.
The safe transfer routine
Bundle these habits into a single routine you run for every meaningful transfer. It takes seconds and makes the scam impossible.
Get the address from a trusted source
Retrieve the recipient address from a verified, trusted source — a saved address book, the recipient directly through a secure channel — not from your transaction history.
Verify it in full
Check the entire address, character by character or in meaningful chunks — not just the ends. If anything differs, stop.
Send a small test
For any significant amount, send a small test transfer first and confirm it arrives at the intended destination.
Send the rest with confidence
Once the test confirms, send the remainder knowing the address is correct.
Address book versus copying from history
The single most protective structural change is to stop copying addresses from transaction history entirely, and use a verified address book instead.
Copying from history is fast but dangerous — it’s the exact behavior the attack exploits, since the decoy lives in your history. A saved address book, where each address was verified in full when you added it, removes the risk almost entirely: you send from a trusted list, not from a feed the scammer can inject into. It’s marginally slower to set up, but for any address you use more than once — and certainly for large transfers — it’s the safe default. Build your address book, and address poisoning loses its landing spot.
If you receive suspicious dust
Since the attack starts with unexpected dust or fake tokens arriving, it helps to know the correct response: do nothing with them.
If unfamiliar dust, a strange token, or an unexpected transaction appears in your wallet, treat it as bait. Do not interact with the token, do not copy the sender’s address, do not visit any website it references, and never sign anything it prompts. Simply hide or ignore the entry. The dust itself is harmless as long as you don’t act on it — the danger only materializes if you copy that lookalike address later. The safest response to unexpected dust is complete non-engagement.
FindCoin can help you spot poisoning attempts — flagging lookalike addresses near ones you use and letting you verify a recipient before you send. Combined with a test transfer, it turns every large send into a safe, deliberate action rather than a risky copy-paste.
Key takeaways
- Address poisoning attacks your habits, not your wallet — it plants a lookalike address in your history so you copy the wrong one.
- It works because we verify addresses by their first and last characters; scammers generate lookalikes matching exactly those visible ends.
- The dust or fake transaction is harmless itself — the loss only happens when you later copy the decoy and send funds to it, irreversibly.
- Defeat it by verifying the full address, using a saved address book instead of copying from history, and sending a test transfer for large amounts.
- If unexpected dust or tokens arrive, do nothing — don’t interact, don’t copy the sender, don’t sign anything; simply ignore or hide it.
Frequently asked questions
What is address poisoning?
A scam where an attacker plants a lookalike address in your transaction history — via dust, a fake token, or a zero-value transfer — hoping you’ll copy it by mistake on your next transfer and send funds to them instead of the real recipient.
How does a lookalike address fool me?
Because people verify addresses by the first and last few characters, scammers generate an address that matches exactly those visible ends while differing in the unchecked middle. At a glance, it looks identical to the real one.
Is the dust they send dangerous by itself?
No — receiving dust or a fake token can’t take your funds. The danger is entirely in your next transfer, if you copy the scammer’s lookalike address from your history. Don’t interact with the dust, and it can’t hurt you.
How do I prevent address poisoning?
Verify the full address rather than just the ends, use a saved address book instead of copying from transaction history, and send a small test transfer before any large amount. These habits make the attack impossible to land.
What should I do if I get suspicious dust?
Nothing — treat it as bait. Don’t interact with the token, don’t copy the sender’s address, don’t visit any linked site, and never sign anything it prompts. Just hide or ignore the entry.
Disclaimer: This article is for information and education only and is not financial advice. Crypto assets are volatile and risky — always do your own research and never invest more than you can afford to lose.
Before you buy any token — check it
Paste a contract address and get a plain-language scam report in seconds.
Open the scam checker →