Security · Phishing

Address Poisoning Scams: How They Work and How to Avoid Them

Address poisoning relies on the human habit of verifying only the start and end of a crypto address. Here's how scammers exploit this and how to stay safe.

Ashir Khan
By Ashir Khan3 min read

Ashir Khan writes about cryptocurrency security, self-custody, macro market analysis, and regulatory policy at CryptoBeacon.

Last updated:

Never copy-paste an address from your transaction history. Always verify the full address, not just the first and last characters.

How Address Poisoning Works

The mechanics of an address poisoning attack are simple but highly effective because they exploit human convenience rather than complex smart contract vulnerabilities.

  1. Monitoring: Scammers use bots to monitor blockchain networks (like Ethereum, Polygon, or BNB Chain) for regular transactions between two wallets.
  2. Generation: The scammer uses a vanity address generator to create a custom address that shares the exact first 4-5 and last 4-5 characters of the address you regularly send funds to.
  3. Poisoning: The scammer sends a transaction of $0.00 to your wallet from the spoofed address. This "poisons" your transaction history, placing the fake address right next to the real one.
  4. The Trap: The next time you want to send crypto, you might open your wallet, go to your transaction history, copy the most recent address that "looks right," and send a large sum. The funds go directly to the scammer.

The Attack Flowchart

1. ObservationUser sends 1 ETH to `0xAb...C123`
2. SpoofingBot generates `0xAb...dC123` (fake)
3. PoisoningBot sends 0 ETH from fake address to User
4. ExecutionUser copies fake address from history and sends funds

How to Avoid Address Poisoning

Preventing address poisoning is entirely about changing your habits when initiating transactions:

  • Never copy-paste from transaction history: This is the most crucial rule. Always get the address directly from the recipient or a trusted saved address book.
  • Verify the entire address: Do not just check the first and last four characters. Verify every single character, or at least a random chunk in the middle.
  • Use the address book feature: Most modern wallets allow you to save trusted addresses to an address book. Use this feature and label your addresses clearly.
  • Use ENS or Web3 Domains: Whenever possible, send to human-readable names like alice.eth instead of raw hexadecimal strings.

What is address poisoning?

Address poisoning is a scam where an attacker sends a tiny or zero-value transaction to your wallet from an address that closely resembles one you frequently use, hoping you'll copy it from your transaction history for future transfers.

Can address poisoning drain my wallet?

No. The scammer does not gain access to your wallet or private keys. The only way you lose funds is if you mistakenly copy the poisoned address and send crypto to it.

How do scammers get an address that looks like mine?

They use vanity address generators to brute-force an address that matches the first and last 4-6 characters of a legitimate address in your transaction history.