Home / Blog / Crypto investigations

Address poisoning: how scammers spoof a wallet address in your transaction history

8 min read Crypto investigations
Address poisoning: how scammers spoof a wallet address in your transaction history
Many users send USDT and other assets to the same addresses repeatedly and, for convenience, copy payment details from previous transaction history. That habit is the foundation of an address poisoning attack: a scammer creates an address that looks similar to a legitimate recipient’s address and inserts it into the victim’s history through a zero-value or micro transaction.
Wallets and blockchain explorers often shorten long addresses, showing only the first and last characters. If those look alike, the substitution can go unnoticed. The user copies the address from the wrong line, signs a real transaction — and the funds go irreversibly to the attacker’s wallet.

How address poisoning works and why lookalike addresses appear in history

Cryptocurrency wallet addresses are long, so people rarely check every character. Attackers monitor public transfers of popular tokens and find addresses that interact regularly. Using automated generation, they then create their own address with the same characters at the beginning and the end.
After that, the scammer sends a zero-value or very small transfer from the prepared address. In some cases the token history may show an entry that visually resembles a previous user operation. The goal is not to infect the blockchain or take control of the wallet. The task is to make the fake address visible in history and wait until the owner copies it for a later payment.
A typical scheme looks like this:
  1. A company or user transfers USDT to a regular counterparty.
  2. The attacker sees the public transaction and generates a lookalike address.
  3. A zero-value or micro transfer arrives at the victim’s address, adding a new history entry.
  4. On the next payment, the victim copies the shortened address from the wrong line.
  5. The wallet executes exactly the operation the user confirmed, so the network does not treat it as fraudulent.
Address poisoning should be distinguished from clipboard hacking. In the first case, the user themselves copies a similar address from poisoned history. In the second, malware on the device automatically replaces the address in the clipboard. The outward result is the same — funds go to the wrong place — but the compromise method and follow-up checks differ. Official explanations: Address poisoning scams and Clipboard hacking in MetaMask Help.
Get a consultation A quick case assessment — no obligation

How to protect yourself from address substitution when transferring cryptocurrency

Never treat transaction history as an address book. The presence of an address in a previous entry does not prove it belongs to the intended counterparty. Take payment details from an agreed source, or use a verified contact list and an allowlist on the platform.
  • Verify the full address. Checking only the first and last four characters is not enough — those are exactly what scammers try to reproduce. Compare the middle of the address as well, or use an exact-match feature.
  • Confirm details through another channel. For significant amounts, contact the recipient via a known phone number, corporate email, or another independent channel. Do not rely solely on a chat message where the account may have been taken over.
  • Use an address book and allowlist. Save verified addresses with clear labels, and on exchanges enable an allowed-address list and a delay for adding new details where available.
  • Check the address on the device screen. Before signing, match the details in the app and on the wallet display. This also helps catch clipboard substitution.
  • Use dual control. In companies, a second authorised person should independently verify the address and amount. For regular payments, document the procedure for changing a counterparty’s details.
  • Do not ignore wallet warnings. Some interfaces flag suspicious zero-value transfers or hide them. That is helpful, but it does not replace manual verification.
A small test transfer reduces the risk of a technical error, but by itself it does not eliminate address poisoning. If after the test the attacker adds a lookalike address to history, the user may still pick the wrong line for the main payment. For the second transaction, use already verified details — do not copy the latest address from the log.
For business payments it is useful to store the full address together with the network name, verification date, and contact person. Changes to payment details should be confirmed separately. That simple process protects not only against address poisoning, but also against compromise of corporate email or messaging.

What to do if funds have already been sent to a spoofed address

If the transaction is still awaiting confirmation, whether it can be replaced or cancelled depends on the network, wallet type, and current status. Do not create additional transactions at random. Once the operation is finally confirmed by the blockchain, it cannot be reversed with an ordinary button: control of the funds has passed to the owner of the destination address.
Record immediately:
  • the hash of the false transaction, network, token, amount, and time;
  • the correct counterparty address and the spoofed attacker address;
  • the prior legitimate operation and any zero-value or micro transactions that may have poisoned history;
  • screenshots from the wallet, blockchain explorer, and the source from which the details were copied;
  • correspondence with the recipient and internal payment approvals;
  • device data if clipboard address substitution is suspected.
Next, trace the movement of funds. If they reach a known centralised platform, contact its security team promptly with hashes, addresses, and official incident documents. In parallel, depending on the amount and circumstances, file a report with law enforcement. The platform may require a request from a competent authority, and merely identifying an exchange address does not guarantee freezing or return of assets.
Do not send additional “verification” payments to the scammer’s address, and do not trust strangers who promise an instant return for an advance fee. If the problem was not poisoning but the wrong network or incorrect details, see cryptocurrency sent to the wrong network or address. For intentional theft, see the step-by-step guide after cryptocurrency theft.

Sent cryptocurrency to a lookalike address? Act quickly to preserve evidence

The ProDefence team performs professional blockchain analysis: separating the legitimate address from the attacker’s address, reconstructing the poisoning transaction sequence, tracing further asset movement, and preparing materials for submissions to platforms and competent authorities.
Contact ProDefence as early as possible. At the initial consultation we review the source data, assess the route, and propose a realistic action plan. No outcome can be guaranteed, but a properly recorded transactional picture and a fast response increase the practical value of further submissions.

Address poisoning

Sent funds to a lookalike address from history?

Send the TXID, network, and both addresses. ProDefence will reconstruct the poisoning picture and prepare materials for submissions — without asking for a seed phrase.

Analyse the transfer

No “100% recovery” promises.