How the attack works
How it works
Four steps, and the third is where the money goes.
The attacker watches the chain for addresses that transact regularly. They generate a lookalike: an address whose first and last few characters match one you send to often. Generating these is cheap, because only the visible ends need to match.
They then send a tiny transfer, sometimes a fraction of a cent, from the lookalike to your wallet. That transaction now sits in your history, showing an address that resembles your usual destination.
Later you send a payment, glance at your history, copy what looks right, and the funds go to the attacker. The transfer confirms normally, and no mechanism exists to reverse it.
Why the ends match and the middle does not
Wallets abbreviate addresses for display, showing something like 0x71C7…F3a2. That abbreviation is the vulnerability.
An attacker matching the first four and last four characters produces a string that is visually identical wherever it is abbreviated, and completely different in full. Checking the abbreviated form therefore confirms nothing, which inverts the usual advice about comparing the beginning and the end.
The dust attack variant
A related technique with a different goal.
Sending tiny amounts to many addresses and watching which ones later combine those amounts with other funds reveals which addresses belong to the same wallet. This is clustering from the attacker’s side rather than theft, and it feeds deanonymisation, which the entry on tracing covers.
The defence is not to spend dust you did not expect. Most wallets now let you mark such outputs as unspendable.
How to stop it
Four habits, in order of how much they help.
Never copy an address from transaction history
Copy from the source: the invoice, the message, the exchange withdrawal screen. This single habit removes the attack entirely.
Use an address book
Save destinations you use repeatedly under names, and select them by name rather than by string.
Check the middle, not just the ends
If you verify by comparing characters, compare a section from the middle as well.
Send a test amount first
For anything large, a small transfer confirms the destination before the rest follows. The funding entry covers the wider set of checks.
Relevance to a merchant
Two sides, and they differ.
On incoming payments, a payment gateway generates a fresh address per order and shows it on the checkout page, so the customer copies from the invoice rather than from history. That structure removes the exposure for them.
On outgoing payouts the merchant is exposed like anyone else, and more so at volume, since payout runs involve repeated transfers to the same recipients. An address book with verified entries and an approval step above a threshold is the practical answer, which is part of what a merchant wallet provides.