Start your 3-day free trial
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.


Wallet address poisoning is a scam in which an attacker sends a tiny transfer, or creates a zero-value token event, so a look-alike address appears in a victim's transaction history. The attacker hopes the victim later copies that planted address instead of a trusted destination. The history entry does not by itself mean the wallet or private key was compromised.
Key Takeaways
- A poisoned entry is bait in a public transaction record, not proof that an attacker controls your wallet.
- Attackers choose an address that resembles a real contact, especially at the beginning and end.
- Checking only the first and last few characters is not enough.
- Retrieve the destination from a trusted source, compare the complete address on an independent display, and use a credited test transfer where appropriate.
- A mistaken on-chain transfer is usually irreversible; prevention matters more than cleanup.
Public blockchains let anyone inspect addresses and transfers. An attacker can watch for a payment between two addresses, generate many candidate addresses, and select one whose visible prefix or suffix resembles the legitimate destination. The attacker then causes that look-alike to appear near the genuine address in the victim's history. MetaMask describes this pattern as an address-poisoning scam designed to exploit the habit of copying addresses from prior transactions.[1]
The attacker does not need to guess the victim's private key. The trap depends on presentation and human recognition: a long hexadecimal or base-encoded string is hard to compare, while many wallets abbreviate it to a few characters at each end. If those fragments match, the fake entry can look familiar in a crowded activity list.
| Stage | What the attacker does | What the victim may see |
|---|---|---|
| Observe | Finds a frequently used public address pair | Nothing unusual |
| Imitate | Generates an address with a similar prefix or suffix | A destination that looks familiar when shortened |
| Plant | Sends dust or triggers a zero-value token transfer | A new incoming or outgoing-looking history row |
| Wait | Relies on the victim reusing transaction history | The fake address near genuine transfers |
| Profit | Receives funds sent to the copied fake address | A valid but unintended blockchain transfer |
Some explorers and wallets label suspicious zero-value events, but interfaces vary. A label is useful warning context, not a substitute for destination verification.
Comparing four characters at the front and four at the end may feel precise, yet an attacker can generate large numbers of addresses until those small visible regions resemble a target. The middle is where the mismatch often remains. Truncated displays make the deception cheaper because the user never sees most of the value.
A checksum can catch some typing mistakes, but it does not prove that an address belongs to the intended person or service. A malicious address can be syntactically valid and checksum-valid. Likewise, a transaction history proves only that a blockchain event occurred; it does not certify the identity or intent of either endpoint.
The safe comparison is the complete destination obtained from a trusted source. Group the string visually, compare it from beginning to end, and recheck after every copy, paste, QR scan, network change, or address-book selection. When a signer has a trusted display, verify the destination there rather than relying only on the computer screen.
Address poisoning and clipboard hijacking can lead to the same loss, but the delivery mechanism differs. Poisoning places a deceptive value in transaction history and waits for the user to select it. Clipboard hijacking uses malware to replace a copied address before it is pasted. Microsoft's research on cryware documents clipboard monitoring and replacement as a cryptocurrency theft technique.[2]
| Signal | Address poisoning | Clipboard hijacking |
|---|---|---|
| Where the wrong address appears | Transaction history or token activity | Paste field after copying |
| Malware on the device required | Not necessarily | Usually |
| Wallet compromise proved | No | Possible device compromise, but not automatically key theft |
| Immediate response | Stop, discard the history entry, verify destination | Stop using the device for signing and investigate it |
If the copied value changes between a trusted source and the paste field, treat the device as potentially compromised. Follow the clipboard hijacking guide before authorizing another transaction.
Start from the receiving side. Open the recipient's official application, type a known domain, or contact the person through a previously verified channel. Generate or display a current receiving instruction. For an exchange deposit, treat the asset, network, address, and any memo or tag as one inseparable record.
Next, compare the full address in the sending wallet. Do not select an address merely because it appears in recent activity. If you use an address book, confirm how the entry was originally verified and whether the recipient has changed its deposit instructions. Hardware-wallet guidance from Ledger recommends checking details on the device display and using a small test transaction when appropriate.[3]
Then send a meaningful small test that meets the recipient's minimum. Wait for the intended recipient or account to credit it; a transaction ID alone does not prove the right party received it. Repeat the full comparison before sending the remainder because the destination field can change between transactions.
Use this checklist before approval:
The deposit-address verification guide covers this workflow in more detail. The broader online security guide helps assess account, device, and recovery risks around it.
Do not send anything to the suspicious address and do not try to “clean” the history by interacting with it. Record the legitimate destination in a verified address book if your wallet supports one, hide or report the suspicious event where the interface allows, and warn the intended recipient if the attacker appears to be targeting a recurring payment relationship.
If you already sent funds to the wrong address, stop and preserve the transaction ID, timestamp, network, asset, and destination. Contact the sending platform and, if identifiable, the receiving service through official channels. Do not pay strangers who promise guaranteed recovery. A valid final transfer usually cannot be reversed, and recovery claims often become a second scam.
Also determine whether the event was only poisoning or whether another warning sign exists. Unexpected signatures, unknown approvals, seed exposure, or transfers you did not authorize justify the incident steps in the crypto hacks guide. A tiny unsolicited asset alone may instead fit the privacy pattern explained in the crypto dusting attack guide.
Wallet address poisoning manipulates the list a user sees, not necessarily the wallet itself. The defense is to reject transaction history as an address authority, retrieve a fresh destination from a trusted source, compare the complete value on the final display, and confirm a credited test before sending more. If a transfer already went to the attacker's valid address, preserve evidence and use official support, but assume reversal may be impossible.
No. Anyone can usually send an asset or create a public event involving an address. Investigate further only if you also see unauthorized signatures, approvals, or outgoing transfers.
Not feasibly under normal cryptographic assumptions. The scam normally uses a different address whose shortened beginning or ending looks similar.
It may not move your balance, but it can serve as deceptive history. Do not copy its counterparty address or interact with an unknown token or contract.
No. Confirmed public records are generally permanent. Some wallets let you hide or report a row locally, but that does not remove it from the chain.
No. A checksum detects certain input errors; it does not establish who controls a valid address.
Use one when fees, minimums, and the amount make it practical. The test counts only after the intended receiving account credits it. Before sending the remainder, compare the complete destination again: a successful test does not prevent a later address substitution.
It cannot stop bait from appearing, but its trusted display can help you compare the final destination before signing.
Sometimes a regulated service can identify or freeze funds, but there is no guarantee. Preserve evidence and avoid recovery scammers.
Disclaimer: This article provides general security information, not legal, financial, investment, or recovery advice.
Sources checked 8 September 2026.
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.