Crypto Scams

Address Poisoning Attack: How Scammers Trick You Into Sending Crypto to Their Wallet

You sent the transaction. You watched the confirmation. Then something felt wrong — you checked the destination address and your stomach dropped. The address you pasted wasn’t the one you meant to use. If this happened to you, you may have been the victim of an address poisoning attack crypto scammers have been running since at least 2022. You are not alone, and you are not stupid for falling for it. These attacks are engineered specifically to exploit the way human attention works.

Address poisoning is a particular kind of gut punch because it requires almost no action on your part — you just copied an address from your own transaction history. That’s what you were supposed to do. The scammer counted on it. Before we get into what to do next, let’s walk through exactly how this works, because understanding the mechanics is what keeps it from happening again.

How an Address Poisoning Attack Actually Works

Crypto address poisoning is surprisingly simple in concept. The scammer doesn’t need to hack your wallet or install malware. They just need to manipulate your transaction history. Here’s the step-by-step:

  • The scammer monitors the blockchain. Every transaction on a public blockchain like Ethereum or Bitcoin is visible to anyone. Tools exist to watch for wallets that are actively sending or receiving funds. Your wallet address is not private — it can’t be.
  • They generate a lookalike address. Using address-generation software, the scammer creates a wallet address that shares your destination address’s first 4–6 characters and last 4–6 characters. The middle 30+ characters are completely different, but most people never check the middle. A real address looks something like: 0x7f4a...c9b2. The fake might be: 0x7f4e...c9b2. Without careful inspection, they look identical.
  • They send you a dust transaction. The scammer sends a tiny amount — sometimes fractions of a penny, sometimes exactly $0.00 worth of a low-value token — from their lookalike address to your wallet. This transaction is harmless on its own. Its only purpose is to plant the fake address in your transaction history.
  • They wait for you to copy the wrong one. Next time you go to send crypto to your real destination, you scroll through your transaction history and spot the familiar-looking address. You copy it. You paste it into the send field. You hit confirm. The funds go directly to the scammer.

The whole operation can cost the scammer less than a dollar in gas fees. Against a single successful hit, that’s an extraordinary return.

Clipboard Hijacking Crypto: The Related Attack You Should Know About

There’s a second, related attack worth understanding: clipboard hijacking crypto malware. Unlike address poisoning — which is entirely on-chain and requires no malware — clipboard hijacking requires malicious software on your device.

Here’s how it works: You copy a crypto address normally. The malware, running silently in the background, detects that a crypto address is on your clipboard and automatically replaces it with the scammer’s address. You paste what you think is your intended destination. You’re actually pasting the scammer’s wallet.

Both attacks exploit the same weakness — that crypto addresses are long, opaque, and humans aren’t built to proofread 42-character hex strings. The fix for both is the same: verify the full address every single time before you send.

Red Flags: How to Catch an Address Poisoning Attack Before You Send

Prevention is straightforward once you know the patterns. Build these habits into every transaction:

  1. Verify the full address — every character, not just the first and last few. Most wallets display abbreviated addresses by default (first 6, last 4). Expand the full address before sending. This is where the lookalike address falls apart: the middle is different. Yes, this is tedious. Do it anyway.
  2. Use an address book or saved contacts in your wallet. If you send to the same addresses regularly — an exchange withdrawal address, a friend’s wallet, your hardware wallet — save them as named contacts. Copy from there, not from transaction history.
  3. Send a small test transaction first. For any large transfer — define “large” however you want, but $1–5 is the standard — send a tiny test amount first. Confirm it arrives at the correct destination before sending the full amount. This costs you a couple of dollars in the worst case. A few extra minutes versus potentially losing everything.
  4. After pasting, check your clipboard by pasting into a text editor first. Open Notepad, TextEdit, or any plain text field. Paste the address there and read it character by character against the source. If clipboard hijacking malware is active, this step reveals it.
  5. Watch for lookalike characters. The Latin alphabet contains character pairs that look nearly identical in many fonts: zero (0) versus capital O, lowercase L (l) versus the number 1, capital I versus lowercase l. Scammers use these in human-readable names and sometimes in Ethereum Name Service (ENS) addresses. In raw hex addresses, the risk is positional similarity, not character substitution — but stay alert.
  6. Be suspicious of any transaction you didn’t initiate. If a tiny, unexpected transaction appears in your history from an address you don’t recognize, that’s the poison being planted. Don’t copy that address for any reason. Ignore it entirely.

If You Already Sent Crypto to the Wrong Address: Immediate Steps

If you think you’ve been hit by a crypto address poisoning attack and may have sent crypto to wrong address, move through these steps now:

  1. Confirm the transaction on a blockchain explorer. Go to Etherscan (for Ethereum/ERC-20 tokens), Blockchain.com (for Bitcoin), or the appropriate explorer for your network. Enter your transaction hash (the unique ID of your transaction — your wallet will show it). You’ll see exactly where the funds went. This confirms whether the attack happened and gives you the documentation you need.
  2. Document everything immediately. Write down: the transaction hash, the amount sent, the destination address (the fake one), the intended destination address (your real one), the exact timestamp, and the dollar value at the time of the transaction. Screenshot everything. You will need this for every report you file.
  3. Report to the FBI’s Internet Crime Complaint Center (IC3). Go to ic3.gov and file a complaint. Include all the documentation from step 2. IC3 aggregates crypto fraud reports and shares intelligence with federal law enforcement. They cannot recover your funds, but your report contributes to pattern detection that leads to prosecutions.
  4. Report to the FTC. File at reportfraud.ftc.gov. Same documentation applies. The FTC tracks consumer fraud patterns and publishes alerts that warn others.
  5. Report the scammer’s address to your exchange. If you use Coinbase, Kraken, Binance, or any centralized exchange, contact their fraud/security team and provide the scammer’s wallet address. Exchanges can flag addresses and, in some cases, freeze funds if the scammer attempts to cash out through their platform. This is a long shot, but it costs nothing.
  6. If clipboard hijacking is suspected: run a full malware scan immediately. Use a reputable antivirus tool — Malwarebytes is a reasonable free option for a one-time scan. Check your browser extensions: remove any you don’t recognize or haven’t intentionally installed. Consider whether you recently downloaded software from an unfamiliar source, which is the most common infection vector.

Honest Recovery Expectations

This part is hard to read, but you deserve honesty: blockchain transactions are final.

There is no bank to call. There is no fraud department that will reverse the charge. There is no technical mechanism to pull funds back from a confirmed transaction. The scammer knows this — it’s the entire reason they operate in crypto. The finality of blockchain transactions is by design, a feature that also makes this fraud so painful.

Recovery does happen occasionally — when the scammer tries to cash out through an exchange that can freeze the funds, or in rare cases where law enforcement identifies and prosecutes the operator. These cases exist. They are not common. Expect the funds to be gone, and let the reporting process serve two purposes: it validates your experience officially, and it contributes to the data that may protect someone else.

If someone contacts you after you file reports and offers to recover your crypto — for a fee, for a percentage, for any reason — they are a scammer running a recovery fraud on top of the original crime. This is extremely common. Do not engage.

How to Protect Yourself Going Forward

The good news: address poisoning attacks are almost entirely preventable once you know how they work. Three habit changes eliminate most of the risk.

Use a hardware wallet for anything significant. Hardware wallets (Ledger, Trezor, Coldcard) display the full destination address on the device screen and require physical confirmation before sending. This creates an out-of-band verification step that is much harder for malware to subvert. If you’re holding meaningful value in crypto, a $60–150 hardware wallet is cheap insurance.

Maintain an address book. Every major wallet and exchange lets you save frequently used addresses with human-readable labels. “My Coinbase deposit address,” “Cold storage,” “Partner’s wallet.” Label them, save them, copy from there. Never copy from transaction history.

Make full-address verification non-negotiable. Every time. For any amount. This is the single highest-leverage habit in crypto security. Addresses are long on purpose — they’re designed to be unique and unguessable. That length is a security feature. Use it.

If you want a complete framework for securing your wallet from the ground up — address book setup, hardware wallet configuration, seed phrase storage, and the habits that prevent exactly this kind of attack — the full guide covers all of it.


Fell victim to an address poisoning attack? Report it to IC3 and your exchange — then read our full guide to crypto wallet security.

Want the full DeFi research every Friday? Wednesday scam alerts + Friday deep dives — premium newsletter, $9/month.
Upgrade to Premium →