Address Poisoning Attacks: How They Work and How to Avoid Them
Learn how address poisoning attacks work, why copied wallet addresses can be dangerous, and how to avoid sending crypto to a lookalike address.
Author: Damon Salvatore · Senior Content Marketer Address poisoning is a wallet scam built around a small human shortcut: copying an address from transaction history instead of verifying it from the intended recipient.
The attacker sends a tiny transaction from an address that looks similar to one you have used before. Later, when you check wallet history, the fake address may appear near the real one, hoping you copy the wrong destination.
Use the workflow below whenever you send to a frequent destination, especially if you are copying an address from a wallet, exchange, block explorer, or previous transaction.
Quick Answer: What Is an Address Poisoning Attack?
An address poisoning attack is a scam where an attacker sends a small transaction from a lookalike address so that the fake address appears in your wallet history. The attacker hopes you later copy that poisoned address by mistake and send funds to it.
MetaMask address poisoning guidance and Ledger address poisoning guidance both describe the same core pattern: attackers create lookalike addresses and rely on users copying from recent activity.
Chainalysis analysis of address poisoning is useful for understanding why the scam scales: the attacker can automate small on-chain touches and wait for a rushed transfer.
Key Takeaways
- Do not copy destination addresses from wallet history.
- Verify the full destination from the trusted source, not just the first and last characters.
- Small dust transactions can be bait, not harmless noise.
- A hardware wallet screen helps only if you actually compare the address before signing.
- Saved address books should be created from verified sources, not from random incoming transactions.
How Address Poisoning Works
The attack does not need to break encryption. It tries to make the wrong address feel familiar.
Attackers watch public blockchain activity, identify addresses that send or receive funds, and generate an address with similar visible characters. They then send a tiny token, NFT, or dust transaction to make the fake address appear in the victim's transaction history.
The next step depends on habit. If the victim copies a destination from history, a block explorer, or a wallet activity list without confirming it against the intended recipient, the poisoned address can become the send target.
This is why checking only the first and last few characters is not enough for high-value transfers. Lookalike addresses are designed to survive that weak check.
| Signal | Safer response |
|---|---|
| Tiny unknown incoming transaction | Treat it as noise unless you can verify the sender. |
| Address in recent activity looks familiar | Do not copy it from history; fetch the address from the trusted recipient. |
| First and last characters match | Compare more of the address, or use a verified address book. |
| Large transfer to a reused destination | Generate or confirm the address again before sending. |
How to Avoid Address Poisoning
Use the address from the trusted source, not from a random history entry.
Use the recipient's current receive screen, official payment request, or saved address book entry that you previously verified. If you use an address book, create entries deliberately and label them in a way that helps future review.
For larger transfers, ask the recipient to confirm the address through a second channel. If it is your own cold wallet, compare the address in the wallet app with the address shown on the hardware device.
If a transaction is meaningful, send a small test first. A test transfer cannot prove every future transfer is safe, but it can expose wrong network or wrong address workflows before the main amount moves.
Address Poisoning Prevention Checklist
- Get the destination address from the recipient's current receive screen or official payment request.
- Do not copy a destination from recent wallet activity, dust transactions, or block explorer history.
- Compare more than the first and last characters for meaningful transfers.
- Use a verified address book for repeat recipients and create entries only from trusted sources.
- Send a small test transfer before moving a large amount to a new or rarely used destination.
- If the wallet app and hardware-wallet screen disagree, reject the transaction and start over.
What to Do If You Sent to a Poisoned Address
If funds were already sent to an attacker-controlled address, the transaction is usually irreversible. Record the transaction hash, destination address, time, amount, and any related wallet-history evidence.
Stop using the poisoned address source immediately. Review the wallet for other suspicious transactions, remove untrusted contacts from address books, and switch to a verified receive-address workflow.
If the mistake involved a centralized exchange, report it to the exchange with the transaction hash. If it involved theft or fraud, consider filing a report with the appropriate cybercrime reporting channel in your jurisdiction.
Where UKey Fits
UKey helps when you use the device screen as the final address check.
UKey Core 26 is relevant because the device screen gives users a separate place to review the destination before signing. That protection only works when the user treats the screen as the approval source, not as a formality.
For address poisoning, the habit matters more than the device name: generate the receive address from a trusted wallet, compare it on-device, and do not use unknown history entries as address sources.
Related Resources
Continue with these UKey guides to connect this threat model with safer wallet setup, approvals, and self-custody habits.
- How to Secure Your Crypto Assets
- Why a Hardware Wallet Needs a Screen
- How to Revoke Token Approvals
- DeFi Token Approval Safety
- Crypto Wallet Drainers
- Fake Wallet Apps
- Approval Phishing
This article is for educational purposes only. It is not financial, legal, tax, cybersecurity incident-response, or investment advice. Threats, wallet interfaces, and supported security features can change. Always verify official sources and current wallet instructions before signing transactions or moving funds.