A trader copied his destination wallet address from his clipboard as usual. The address looked right — he verified the first four characters. He sent $150,000. The last six characters were different. The funds were gone in seconds.
This is not a hypothetical. Attacks like this happen every day across Bitcoin, Ethereum, and other networks. And the terrifying part? The victim did everything they thought was right. They copied the address carefully. They glanced at it. It looked fine.
Understanding two specific attacks — clipboard hijacking and address poisoning — can be the difference between keeping your crypto safe and watching it vanish into a stranger’s wallet with no recourse.
Why Wallet Addresses Are a Security Problem
Ethereum addresses are 42 characters long. Bitcoin addresses can be even longer. They look something like this:
0x3fC91A3afd70395Cd496C647d5a6CC9D4B2b7FAD
No human being reads all 42 characters every time. Our brains are wired for shortcuts. Most people glance at the first four characters and maybe the last four. That is the vulnerability that both clipboard hijackers and address poisoners exploit.
Crypto transactions are also irreversible. There is no customer support line, no chargeback, no fraud department. Once confirmed on the blockchain, the funds are gone. Attackers know this, which is exactly why they target the address entry step.
Clipboard Hijacking: The Silent Swap
Clipboard hijacking is a type of malware attack. The malware lives quietly on your computer or phone, watching your clipboard — the temporary storage your device uses when you copy something.
The moment you copy a crypto wallet address, the malware detects it, swaps it out for the attacker’s address, and sits back silently. You paste what you think is your address. It isn’t. You are now sending funds directly to the attacker.
How does the malware get onto your device? Common entry points include:
- Downloading cracked or pirated software
- Installing fake versions of crypto wallets or trading tools from unofficial sources
- Clicking links in phishing emails or fake ads (see our guide on phishing attacks in crypto, Post 61 in our Wallet Security series)
- Browser extensions that request broad permissions
- Unofficial app stores or torrented files
The malware is often sophisticated enough to generate a replacement address with matching first and last characters — so even a quick glance will not save you.
How to protect yourself from clipboard hijacking:
- Only download wallet software and crypto apps from official websites. Bookmark them. Never search for them through ads.
- After pasting any wallet address, verify the full address character by character against the original source. Not just the first four. All of them.
- Keep your operating system and antivirus software up to date.
- Be suspicious of any software that requests access to your clipboard.
- Consider a hardware wallet, which displays the destination address on a separate physical screen (more on this below).
Address Poisoning: The Look-Alike Trap
Address poisoning is different from clipboard hijacking — it does not require malware on your device. Instead, it poisons your transaction history.
Here is how it works. Attackers use tools called vanity address generators to create wallet addresses that closely resemble a target address. They can generate an address with matching first six characters and matching last six characters, with random characters in the middle.
Once they have a convincing lookalike address, they send a tiny “dust” transaction — often worth fractions of a cent — from that fake address to your wallet. The goal is to get that fake address into your transaction history.
Later, when you need to send funds to a familiar address, you scroll through your transaction history looking for it. You see what appears to be the right address. You copy it. You send your funds to the attacker.
Why truncated display makes this dangerous: Most wallet interfaces do not show full addresses. They show something like 0x3fC9...7FAD — the first four and last four characters. The fake address generated by the attacker can match both ends exactly. In a truncated display, there is no visible difference.
Real-world examples of address poisoning attacks have resulted in losses ranging from tens of thousands to millions of dollars. In 2023, one victim lost $20 million in stablecoins to a near-identical address that appeared in their transaction history just hours before a large planned transfer.
How to Protect Yourself from Address Poisoning
The good news is that address poisoning is entirely avoidable with a few disciplined habits.
- Never copy a recipient address from your transaction history. This is the single most important rule. Transaction history is exactly where the poisoned address sits waiting for you.
- Use your wallet’s address book. Most wallets allow you to save verified addresses with labels. Save addresses once, verify them fully at setup, and reuse from the address book — not from history.
- Verify the full address before every send. Every single character. Not just the ends. Copy the address, paste it into a text editor, and compare it against the source you trust.
- Use a hardware wallet. Hardware wallets like those covered in our hardware wallet guide (Post 34) display the full destination address on a physical screen that is completely separate from your computer. Even if your computer is compromised, you can verify the true destination on a trusted display before approving.
- Send a test transaction first. For any transfer above a few hundred dollars, send a small test amount first. Confirm it arrives at the correct destination before sending the full amount. Yes, this costs a small fee. It is worth it.
The Combined Defense: Full Address Verification
Notice that the same defense defeats both clipboard hijacking and address poisoning: verifying the complete address, character by character, against a trusted source.
A clipboard hijacker can match the first and last characters. An address poisoner can match the first and last characters. Neither can match every single character in a 42-character address without it being the correct address.
Hardware wallets strengthen this defense significantly. When you initiate a transaction on a hardware wallet, the device shows the full destination address on its own screen — a screen that your computer cannot alter. You physically verify on the device before approving. This is why security experts consistently recommend hardware wallets for holding meaningful amounts of crypto. If you have not yet set one up, our guide to seed phrase storage (Post 33) covers the secure backup practices that go alongside hardware wallet use.
Other Address Scams to Know
Clipboard hijacking and address poisoning are the most common address-based attacks, but a few others are worth knowing:
- QR code tampering: Attackers replace QR codes on physical flyers, in PDFs, or on websites with codes that encode their own addresses. Always verify the address a QR code resolves to before sending.
- Typosquatting: Fake websites with URLs similar to legitimate exchanges or wallets (e.g., “bìnance.com” or “coinbáse.com”) display attacker-controlled deposit addresses. Always type URLs directly or use bookmarks.
- Wallet fat finger warnings: Some modern wallets now flag addresses that look similar to recently used addresses — take these warnings seriously. They exist precisely because address confusion attacks are common.
Before Every Crypto Send: Your Checklist
Make this checklist a habit. Every time. No exceptions for “small” amounts.
- Copy the recipient address only from a trusted, verified source — not from transaction history, not from a message, not from an ad.
- After pasting, verify the full address — every character — against the original source.
- For large transfers, send a small test amount first and confirm it arrives correctly.
- If using a hardware wallet, verify the displayed address on the hardware device’s screen before approving.
- Confirm the send only after every character matches.
It takes thirty extra seconds. It can save you everything.
Stay Sharp in Crypto
Address attacks work because they exploit human habits — our tendency to scan rather than scrutinize, to trust familiar patterns, to assume our tools are safe. The antidote is simple but requires consistency: verify fully, every time.
The trader who lost $150,000 was not careless by the standards most people use. He was careless by the standards crypto requires. That gap — between normal caution and crypto-grade caution — is what these guides exist to close.
Subscribe to Crypto Clarified — our free weekly newsletter on staying safe in crypto. Every issue covers one real threat, explained plainly, with concrete steps you can act on.