Security

Address Poisoning

A scam that seeds your history with a look-alike address, hoping you copy the wrong one later.

Address poisoning preys on how people reuse addresses from transaction history. The attacker generates a vanity address whose first and last characters match one you transact with, then sends you a tiny or zero-value transfer. Now their look-alike sits in your history.

The hope is that next time you copy an address from past transactions, you grab theirs and send funds to the attacker. The defense is plain: verify the full address, not just the ends, and use a saved address book instead of copying from history. Always send a small test amount first.

Related terms