Tuesday, September 29, 2026Live markets
BBTC$83,534.37 +0.12%EETH$2,678.05 -0.18%BBNB$758.07 -0.42%XXRP$1.49 +0.15%SSOL$119.01 +0.74%TTRX$0.3347 -0.33%ZZEC$1,409.68 -4.06%HHYPE$86.28 -1.02%DDOGE$0.0940 +0.87%LLINK$14.70 -2.67%XXMR$542.66 +0.35%AADA$0.2448 -0.02%XXLM$0.2234 -0.47%NNEAR$4.96 +3.82%
Security

Address Poisoning Attacks: How to Avoid Sending Funds to the Wrong Address

Address poisoning tricks you into sending crypto to a lookalike address. Learn how these attacks work and simple steps to avoid losing funds.

CDBy CryptoNewsroom Desk · · 5 min read
Address Poisoning Attacks: How to Avoid Sending Funds to the Wrong Address

Key points

  • Address poisoning is a scam where attackers send tiny transactions from an address that looks similar to one you use, hoping you copy it from your history.
  • Always verify the full recipient address on your own device, not from transaction history or a block explorer.
  • Use address book whitelisting and send a small test transaction before sending large amounts.

What Is an Address Poisoning Attack?

An address poisoning attack is a trick that aims to make you send cryptocurrency to a scammer’s address instead of the one you intended. The attacker creates a wallet address that looks very similar to an address you already use — often matching the first and last few characters — and then sends a tiny transaction from that lookalike address to your wallet. That transaction appears in your history. Later, when you copy an address from your history to send funds, you might accidentally grab the attacker’s address instead of the real one. Once you send funds there, they are gone.

This attack does not exploit a bug in blockchain software. It exploits human habits: copying addresses from transaction history, trusting the first few characters, and not double-checking the full string.

How Address Poisoning Works

The attack typically follows a simple pattern:

  1. Create a lookalike address. The attacker generates a new wallet address that shares the same starting and ending characters as an address you frequently interact with. Because crypto addresses are long, many people only check the beginning and end.
  2. Send a tiny transaction. The attacker sends a very small amount of a token or coin (sometimes zero-value) from the lookalike address to your wallet. This transaction gets recorded on the blockchain and shows up in your wallet’s transaction history.
  3. Wait for you to copy the wrong address. The next time you need to send funds to that same recipient, you might scroll through your history, see the lookalike address, and copy it — thinking it is the one you used before.
  4. You send funds to the attacker. If you send without verifying the full address, your funds go to the attacker’s wallet. The attacker can then move them elsewhere.

Some attackers also poison the address book inside a wallet app if the app automatically suggests addresses from history. The core idea is always the same: get a lookalike address in front of you at the moment you are copying.

Why It Works: The Human Factor

Crypto addresses are long strings of letters and numbers. For example, an Ethereum address is 42 characters long. Checking every character is tedious, so many people develop a habit of checking only the first four and last four characters. Attackers know this and design their addresses to match those parts.

Transaction history is also a convenient place to find addresses. Instead of asking the recipient for their address again, you might just copy it from a past transaction. That convenience is exactly what the attacker counts on.

How to Protect Yourself

You can avoid address poisoning with a few simple habits. None of them require technical expertise.

1. Always Verify the Full Address

Before sending any cryptocurrency, compare the full recipient address character by character with the address you intended to use. Do this on your own device, not from a screenshot or a message. If you are sending to someone else, ask them to confirm the address through a separate channel (for example, a phone call or a different messaging app).

2. Use an Address Book

Most wallets and exchanges let you save addresses in an address book. Once you save a verified address, you can select it by name instead of copying the string. This removes the risk of copying a lookalike from your history. Make sure the address book itself is protected — if someone gains access to your device, they could change the saved address.

3. Send a Small Test Transaction First

When sending a large amount to a new address, send a small test amount first. Wait for it to confirm, and verify that the recipient received it. Then send the rest. This costs a little in network fees but can save you from a costly mistake.

4. Don’t Copy Addresses from Transaction History

Avoid copying addresses directly from your wallet’s transaction history or a block explorer. Instead, get the address from a trusted source: the recipient’s own message, your saved address book, or a QR code you scan directly from their device.

5. Check the Entire Address, Not Just the Ends

If you must copy from history, at least verify the middle characters as well. Attackers often cannot match the entire string, so a mismatch in the middle is a clear warning sign.

6. Be Cautious with Zero-Value Transactions

Some poisoning attacks use zero-value transactions or tiny amounts of a token you don’t recognize. If you see an unexpected transaction in your history, do not interact with it. You can often hide it in your wallet settings.

Common Mistakes and Risks

Even careful users can fall for address poisoning. Here are some common pitfalls:

  • Trusting the first and last characters only. This is the most common mistake. Attackers specifically target those characters.
  • Copying from a block explorer. Block explorers show all transactions, including the attacker’s tiny transaction. If you copy from there, you might grab the wrong address.
  • Rushing. When you are in a hurry, you are more likely to skip verification. Slow down for any transaction.
  • Using a compromised device. If malware is on your computer or phone, it can replace a copied address with the attacker’s address. Keep your devices secure and use a hardware wallet for large amounts.
  • Not double-checking after pasting. Some malware changes the address after you paste it. Always verify the pasted address before confirming the transaction.

The risk is real: once a transaction is confirmed on the blockchain, it cannot be reversed. There is no customer support to call. That is why prevention is the only defense.

What to Do If You Think You’ve Been Targeted

If you notice a suspicious transaction in your history, do not panic. First, do not interact with it. Second, check your saved addresses and recent transactions to see if you have sent funds to a lookalike. If you have, the funds are likely gone, but you can report the address to your wallet provider or exchange. They may flag it, but they cannot recover your funds.

To reduce future risk, review your address book and remove any addresses you do not recognize. Enable any security features your wallet offers, such as transaction confirmation prompts or address whitelisting.

Summary

Address poisoning attacks rely on confusion and haste. Attackers create lookalike addresses and send tiny transactions to get them into your history. When you copy an address to send funds, you might grab the wrong one. The defense is straightforward: always verify the full address, use an address book, send a test transaction for large amounts, and never copy addresses from transaction history or block explorers. These habits take a few extra seconds but can save you from losing your crypto.

Disclaimer: This article is for information only and is not investment, financial or trading advice. Cryptocurrency prices are highly volatile. Always do your own research.

CD
CryptoNewsroom Desk

The CryptoNewsroom editorial desk covers Bitcoin, Ethereum, altcoins, DeFi, regulation and crypto markets. Editorial policy

Related stories

The Morning Block

Our upcoming daily email with the top crypto stories and market moves. Join the list and get the first edition. Free, no spam, unsubscribe any time.