Wallets & keys

What Is Address Poisoning?

Basics Also known as what is address poisoning address poisoning attack dust attack crypto lookalike address scam

In short

Address poisoning plants an address that looks like one you already use into your own transaction history, in the hope that you copy it from there instead of from the real source. It requires no hacking, no malware and no access to anything of yours. It works entirely on habit.

How the attack works

How it works

Four steps, and the third is where the money goes.

The attacker watches the chain for addresses that transact regularly. They generate a lookalike: an address whose first and last few characters match one you send to often. Generating these is cheap, because only the visible ends need to match.

They then send a tiny transfer, sometimes a fraction of a cent, from the lookalike to your wallet. That transaction now sits in your history, showing an address that resembles your usual destination.

Later you send a payment, glance at your history, copy what looks right, and the funds go to the attacker. The transfer confirms normally, and no mechanism exists to reverse it.

Why the ends match and the middle does not

Wallets abbreviate addresses for display, showing something like 0x71C7…F3a2. That abbreviation is the vulnerability.

An attacker matching the first four and last four characters produces a string that is visually identical wherever it is abbreviated, and completely different in full. Checking the abbreviated form therefore confirms nothing, which inverts the usual advice about comparing the beginning and the end.

The dust attack variant

A related technique with a different goal.

Sending tiny amounts to many addresses and watching which ones later combine those amounts with other funds reveals which addresses belong to the same wallet. This is clustering from the attacker’s side rather than theft, and it feeds deanonymisation, which the entry on tracing covers.

The defence is not to spend dust you did not expect. Most wallets now let you mark such outputs as unspendable.

How to stop it

Four habits, in order of how much they help.

Never copy an address from transaction history

Copy from the source: the invoice, the message, the exchange withdrawal screen. This single habit removes the attack entirely.

Use an address book

Save destinations you use repeatedly under names, and select them by name rather than by string.

Check the middle, not just the ends

If you verify by comparing characters, compare a section from the middle as well.

Send a test amount first

For anything large, a small transfer confirms the destination before the rest follows. The funding entry covers the wider set of checks.

Relevance to a merchant

Two sides, and they differ.

On incoming payments, a payment gateway generates a fresh address per order and shows it on the checkout page, so the customer copies from the invoice rather than from history. That structure removes the exposure for them.

On outgoing payouts the merchant is exposed like anyone else, and more so at volume, since payout runs involve repeated transfers to the same recipients. An address book with verified entries and an approval step above a threshold is the practical answer, which is part of what a merchant wallet provides.

Frequently asked

No. It relies on you sending funds voluntarily to the wrong address.

Receiving it does nothing. The risk is spending it or copying the sender's address.

No. The chain is permanent. Some wallets let you hide them.

Only the abbreviated form matched. The full strings differ entirely.

No. A confirmed transfer to the wrong address is final.

Was this article helpful?

See also