Wallet safety / Updated 2026-07-23

Address Poisoning: The Lookalike Wallet Address Hiding in Your Transaction History

Address poisoning plants a lookalike wallet address in your history so you copy it by mistake. Learn how the zero-value transfer trick works and the habits that defeat it.

How this guide is checked

Official sources first, no wallet connection, no guaranteed returns.

Reviewed on 2026-07-23 by WildWildCrypto Safety Desk. Method: Human editorial review with official-source checks, affiliate-disclosure checks, and no-financial-advice checks.

Publisher: WildWildCrypto Editorial. Corrections go through the contact page. We do not ask for seed phrases or tell you what to buy.

address poisoning scam matters because You check the first four characters and the last four, they match, and you hit send. That habit is exactly what an address-poisoning attacker is counting on.

This guide explains how the lookalike-address trick works, why it is exploding, and the small set of habits that make it fail.

You will learn what a zero-value transfer is, why copying from history is the weak point, and how an address book or a hardware wallet closes the gap.

What is address poisoning?

Address poisoning is a scam that exploits a habit, not a bug. Wallet addresses are long strings of random characters, so almost nobody reads the whole thing. Instead we glance at the first few and last few characters and assume the rest matches. Attackers know this, so they generate a 'vanity' address that begins and ends with the same characters as an address you have used before, then make it appear in your wallet so that the next time you copy an address from your history, you copy theirs.

The most common delivery method is the zero-value transfer. As Ledger Academy explains, attackers monitor blockchain activity to find wallets with regular transaction patterns, then send transactions worth nothing — often $0 token transfers — from a lookalike address into your wallet. These cost almost nothing to send, so they can be automated at enormous scale. The transfer does not take anything; it exists purely to plant the fake address in your transaction list, sitting right next to the real one you actually deal with.

This is a fundamentally different problem from sending crypto on the wrong network or approving a malicious contract. Nothing about your keys is compromised and no malware is involved. The attack targets the moment you select a recipient — it poisons the well you draw addresses from, and then waits for you to draw.

Checklist

  • Attackers create addresses matching your recipient's first and last characters.
  • Zero-value transfers plant that fake address in your history.
  • The attack costs the scammer almost nothing to run at scale.
  • It targets your copy-paste habit, not your private keys.

Why this is worth your attention now

Address poisoning stopped being a rare curiosity and became an industrial-scale nuisance. Security firm Blockaid reported more than 65 million flagged address-poisoning transactions since January 2025, averaging over 160,000 attempts per day, with a sharp spike into early 2026. Because the attack is so cheap — one campaign reportedly sent roughly three million dust transfers to over a million addresses for a total cost of around five thousand dollars — attackers spray it broadly and profit from the small fraction who slip.

That small fraction still produces large losses. Individual incidents have been severe: Blockaid documented a December 2025 case where a victim lost $50 million in a stablecoin transfer to a poisoned address, and a January 2026 case where someone sent 4,556 ETH — about $12.4 million — after an attacker spent two months dusting their wallet to plant a near-perfect lookalike of a regularly used address.

The important nuance for a beginner is that you do not need to move millions to be a target. Automated poisoning does not know or care how much you hold; it plants lookalikes in millions of wallets and lets ordinary copy-paste habits do the rest. The defense is the same whether you are moving fifty dollars or fifty thousand, which is why building the habit early costs you nothing and protects you later.

The habits that defeat it

The core fix is to change where you copy addresses from. Your transaction history is the one surface an attacker can write into, so it is the one place you should never pull a recipient address from. Instead, save the addresses you send to repeatedly in your wallet's address book (also called a contacts or allowlist feature) and select the recipient from there. For a new recipient, get the address directly from the person or platform through a channel you trust — a QR code you scan in person, or a copy from their official account — not from a prior transaction line.

Second, verify the whole address, not just the ends. The entire poisoning technique relies on you checking only the first and last characters. When it matters, compare the full string, or at minimum several characters from the middle as well. A hardware wallet helps here because it displays the destination address on its own screen for you to confirm before you approve, giving you a deliberate, malware-resistant checkpoint that a rushed copy-paste on a phone does not.

Third, send a small test transaction before any large transfer to a new or infrequent address, and confirm with the recipient through a separate channel that it arrived at the right place. Finally, treat any unexpected token or zero-value transfer that appears in your wallet as noise to ignore, never as a contact to reuse — interacting with poisoned entries is exactly the reaction the attacker wants.

Checklist

  • Copy recipient addresses from a saved address book, never from history.
  • Verify the full address, including the middle, not just the ends.
  • Use a hardware wallet's on-device screen to confirm the destination.
  • Send a small test amount first for new or large transfers.
  • Ignore surprise zero-value or unknown-token entries — never reuse them.

What to do if you already sent to a poisoned address

If you copied a lookalike address and the transaction has confirmed, the funds are gone in the same way any mistaken crypto transfer is gone: blockchain transactions are final, and the FTC notes that a defining feature of crypto is that transfers cannot be reversed the way a card charge can. There is no support line that can pull the money back, and no legitimate service can guarantee its return.

What you can still do is contain the damage and stop the pattern. Check whether the poisoned address planted more than one lookalike in your history and remove or clearly label the real addresses in your address book so the correct one is unmistakable going forward. If the loss is significant, report it to the FBI's IC3 and the FTC; these reports feed the threat intelligence that wallet providers and analytics firms use to flag poisoned addresses for everyone else.

And guard against the follow-on scam. As with other crypto losses, 'recovery experts' who promise to retrieve funds for an upfront fee are a predictable second wave and are themselves fraudulent. The honest outcome here is prevention: this is a scam you defeat almost entirely by changing one habit — where you copy addresses from — before it ever costs you anything.

Authority sources used

Outbound links are included for verification and entity authority, not decoration.

FAQ

If a zero-value transfer appears in my wallet, has my wallet been hacked?

No. A zero-value transfer or a surprise token showing up in your history does not mean anyone has access to your wallet, your private keys, or your seed phrase. Anyone can send a transaction to a public address without permission, exactly as anyone can mail a letter to your address without being able to enter your house. Address-poisoning attackers exploit this by sending worthless transactions from a lookalike address purely so that it appears in your transaction list, hoping you will later copy it by mistake. The transfer itself takes nothing and grants no access — it is bait, not a breach. The correct response is to leave it alone: do not click it, do not send anything to it, and do not treat it as a contact. Simply be aware that your history now contains a decoy, and make sure you copy future recipient addresses from a saved address book or a trusted source rather than from your history, where the decoy lives.

Isn't checking the first and last four characters of an address enough?

Not against address poisoning — that habit is the exact weakness the attack is built to exploit. Attackers generate a 'vanity' address engineered to match the first few and last few characters of an address you already use, precisely because they know most people verify only the ends, especially since many wallet interfaces abbreviate addresses as something like '0x1a2b...9f8e.' Matching ends are cheap to produce; matching the full string is not. So checking only the ends gives you false confidence while leaving the middle — where the fake diverges — unverified. When a transfer matters, compare the entire address or at least several middle characters as well, ideally against a saved address-book entry rather than a history line. Better still, use a wallet's address book so you select a verified contact instead of re-checking characters at all, and confirm the destination on a hardware wallet's own screen before approving. The reliable rule is to verify the whole address, or select from a trusted source, rather than trusting the ends.

How is address poisoning different from sending crypto to the wrong network?

They are two separate mistakes with different causes. Sending to the wrong network means you used a correct address but selected an incompatible blockchain — for example, sending tokens over a network the receiving wallet or exchange does not credit — which is about chain selection, not deception. Address poisoning is an active scam: an attacker deliberately plants a lookalike address in your transaction history through zero-value or dust transfers, hoping you copy their address instead of your intended recipient's. In the wrong-network case, the address you meant to use was right; in address poisoning, the address itself is the trap. The defenses also differ. Wrong-network errors are avoided by carefully matching the network on both ends and sending a test amount first. Address poisoning is avoided by controlling where you copy the address from — using a saved address book instead of your history — and verifying the full string. Both share one habit worth keeping: always send a small test transaction before a large or unfamiliar transfer.

Does using a hardware wallet stop address poisoning?

It helps meaningfully but does not remove the need for good habits. A hardware wallet's real advantage against this scam is that it displays the destination address on its own trusted screen and asks you to confirm before signing, which creates a deliberate checkpoint that a fast copy-paste on a phone skips. If you actually read and verify the full address on that screen against your intended recipient, you can catch a poisoned lookalike before approving. But the device cannot know your intent — if you copied the wrong address and approve it after only a glance at the ends, the hardware wallet will faithfully sign the transaction to the attacker, because from its perspective you authorized it. So a hardware wallet is a strong layer that gives you a clear moment to verify, not an autopilot that judges correctness for you. Pair it with the habits that prevent the mistake upstream: copy addresses from a saved address book rather than history, verify the full string, and send a test amount first for anything large or new.

Why would an attacker send me a transaction that gives them nothing?

Because the transaction is not the payoff — it is the setup. A zero-value or tiny 'dust' transfer costs the attacker almost nothing to send, and its only purpose is to place a lookalike address into your transaction history so it sits next to an address you genuinely use. The attacker is playing a numbers game: automated tools blast these decoy transfers to millions of wallets for a few thousand dollars total, then wait for the small fraction of people who later copy the wrong address from their history when sending real funds. Blockaid has tracked tens of millions of these poisoning transactions, averaging well over a hundred thousand attempts per day, precisely because the economics work at scale even if only a tiny percentage succeed. When one does succeed, it can be enormous — documented single incidents have run into the tens of millions of dollars. So the 'pointless' transaction is a cheap, patient trap, and understanding that its whole job is to poison your history is what lets you defuse it by simply never copying addresses from there.