Address Poisoning Scams: How They Work and How to Avoid Them
Address poisoning scams plant look-alike addresses in your wallet history so you copy the wrong one. See how the trick works and the habits that stop it.
Key takeaways
- Address poisoning plants a look-alike address in your history, hoping you copy it for your next transfer.
- The look-alike matches only the ends. In our example, the 32 middle characters, 80% of the address, are all different.
- Zero-value, tiny and fake-token entries are bait. They can't move your funds, and there is nothing to revoke.
- One study counted 270 million poisoning attempts against 17 million addresses, about 16 attempts per targeted address.
- Never copy an address from transaction history. Use a verified address book entry or get it fresh from the recipient.
On this page
How does address poisoning work?
Address poisoning targets a habit, not a wallet. Many people send funds to the same place again and again, such as an exchange deposit address, and copy it from their recent transactions to save time. The scam makes a look-alike address appear in that history.
The scammer generates an address whose first and last characters match one you have used, then creates activity between that address and yours. Wallets and explorers often shorten addresses to their ends, like 0x3fa9...c71e, so the fake and the real one look identical at a glance. Copy the fake, send to it, and the funds go to the scammer. A confirmed transfer can’t be reversed.
It happens at scale. A study presented at the USENIX Security Symposium in 2025 counted 270 million poisoning attempts aimed at 17 million victims on Ethereum and BNB Smart Chain between July 2022 and June 2024. That is about 16 attempts per targeted address. Only 6,633 attempts succeeded, roughly one per 40,700, but those cost at least $83.8 million. The scam is cheap to spray, and it needs just one careless copy.
The three kinds of bait
The researchers describe three ways scammers get a look-alike into your history, each built around a real transfer you just made:
- Zero-value transfer. A transfer of zero tokens that appears to go from your address to the look-alike. The token standard says zero-value transfers “MUST be treated as normal transfers” and recorded like any other, so it shows up even though you never signed it. It moves nothing.
- Tiny transfer. The look-alike sends you a small amount of the same token you just sent, so it appears as a recent counterparty.
- Counterfeit token transfer. A fake token, created by the scammer and often named like the real one, shows the same amount you sent going from your address to the look-alike.
None of these can take anything from your wallet. There is no approval to revoke and no key to replace, because the scammer never received any permission. The danger is entirely in what you copy next.
- Minute 0You send 5,000 Token X to your usual address
- Within 20 minZero-value transfer to a look-alike appears
- Within 20 minTiny transfer and fake-token entry arrive
- Days laterYou copy the look-alike from your history
- Once confirmedFunds reach the scammer; no reversal
Worked example: reading a poisoned history
Example: On Monday at 09:12 you send 5,000 Token X to your exchange deposit address. Three days later you open your history to send again. These are the entries involving an address that starts 0x3fa9 and ends c71e (hypothetical data).
| Time | Direction | Token | Amount | Counterparty as shown | What it is |
|---|---|---|---|---|---|
| Mon 09:12 | Out | Token X | 5,000 | 0x3fa9...c71e | Your real transfer |
| Mon 09:14 | Out | Token X | 0 | 0x3fa9...c71e | Zero-value bait |
| Mon 09:16 | Out | “Token X” (unverified) | 5,000 | 0x3fa9...c71e | Counterfeit token |
| Mon 09:19 | In | Token X | 0.01 | 0x3fa9...c71e | Tiny transfer bait |
Three of the four entries, 75%, point to the look-alike, and the most recent one is bait. A hurried copy of the latest entry picks the scammer’s address. Here are the two full addresses, split into groups of four:
- Real:
0x3fa9 7d20 5b1e 44c9 a0f3 91be 2d6c 8e05 17aa c71e - Look-alike:
0x3fa9 e41b 90d2 7f3a 6c58 0b17 d9e4 2a6f 83c0 c71e
The first four and last four characters match. The 32 characters in between, 80% of the address, differ at every position. Matching the ends is cheap for a scammer; matching the full address is not, as the math in our guide to verifying a crypto address shows.
How do you spot bait in your history?
| What you see | What it means | What to do |
|---|---|---|
| A 0-token transfer you don’t remember making | Zero-value bait | Ignore it; nothing to revoke |
| A tiny deposit from an address resembling a contact | Tiny transfer bait | Never copy that address |
| A familiar token symbol you never bought | Counterfeit token | Don’t trade it or visit links in its name |
| An entry minutes after a real transfer, same ends | Look-alike planted after your activity | Compare the full address |
The timing is a tell. In the study, the researchers looked for poisoning transfers within a 20-minute window after each victim’s real transfer. New, unfamiliar entries that appear right after you send funds deserve suspicion.
Counterfeit and spam tokens deserve extra caution. Some carry a website address in their name, inviting you to “claim” or swap them, and those pages work like fake airdrop and claim sites: they ask for approvals or signatures that can drain real tokens.
Habits that stop address poisoning
- Never copy addresses from transaction history, yours or a block explorer’s. Treat history as a record of the past, not an address book.
- Keep verified addresses in an address book or allowlist. Save each one once, after checking it against the source, with a clear label. The researchers also recommend allowlists of trusted addresses.
- Get new addresses from the source: the recipient’s own wallet, their QR code or your exchange’s deposit page.
- Compare the whole address in chunks before sending, not just the first and last characters.
- Hide or filter spam where your wallet allows it. Hiding suspected poisoning transfers is one of the wallet-level fixes the study proposes.
- Send a small test first for large transfers, and wait for the recipient to confirm it arrived.
A related trick swaps the address after you copy it, inside your device’s clipboard. If a pasted address ever differs from what you copied, read our guide to clipboard hijacker malware before using that device again.
What if you already sent funds to a look-alike?
A confirmed transfer can’t be pulled back, but a fast response still matters. Save the transaction hash and the look-alike address, notify the exchange if the funds pass through one, and file reports with the authorities; our guide on how to report a crypto scam lists where. Expect follow-up offers from “recovery experts,” and treat any upfront fee as a red flag from our list of crypto scam warning signs. No real investigator needs your recovery phrase: never share it or type it into a website to “trace” funds.
For the rest of your setup, work through the crypto wallet security checklist.
The bottom line
Address poisoning doesn’t break into your wallet; it waits for you to copy the wrong line from your own history. The look-alike matches only the ends, so the fix is a habit: never copy from history, send from a verified address book, and compare the whole address before you confirm. Bait entries are harmless as long as you ignore them.
Frequently asked questions
Can address poisoning steal crypto directly from my wallet?
No. Poisoning transfers don't give the scammer any access to your wallet, your keys or your tokens. A zero-value transfer moves nothing, a tiny transfer only adds a little to your balance, and a counterfeit token is worthless. The scam works only if you later copy the look-alike address and send funds to it yourself, which is why the defense is about how you pick addresses.
Why do I see a zero-value transfer I didn't make?
The token standard treats a transfer of zero tokens as a normal transfer and records it as an event, so a scammer can make a 0-token transfer from your address to their look-alike appear in your history without your signature. It moves none of your tokens. Its only purpose is to put the look-alike address next to your real activity. Ignore it, and don't copy that address.
Should I revoke approvals or change my recovery phrase after a poisoning attempt?
Not because of the poisoning itself. No approval was granted and your keys were never exposed, so there is nothing to revoke and no reason to replace your phrase. It is different if you clicked links in a counterfeit token's name or signed something on a site it led you to. In that case, review your approvals and treat the wallet as possibly compromised.
Can I get my crypto back after sending it to a poisoned address?
Usually not. A confirmed transfer is final, and the scammer controls the look-alike address. Record the transaction hash, report the theft to the authorities where you live, and tell the exchange involved if the funds pass through one. Be wary of anyone who contacts you promising to recover the funds for a fee, because recovery offers are a common follow-up scam.
Sources
- Blockchain Address Poisoning (USENIX Security 2025) — Tsuchiya, Dong, Soska and Christin, USENIX
- ERC-20: Token Standard — Ethereum Improvement Proposals
This content is for education only and is not financial, investment, tax or legal advice. Crypto assets are volatile and you can lose money. Examples use hypothetical numbers. See our disclaimer and editorial policy.