What Is Address Poisoning?
Address poisoning is a patience scam. An attacker generates an address whose first and last characters match one you actually use, sends you a dust transaction from it, and waits. Weeks later you copy "your" address from transaction history, check the ends like everyone does, and send funds to the impostor.
How It Actually Works
- Crypto addresses are long, so humans verify the first four and last four characters. Attackers exploit exactly that habit.
- Vanity-address tools can brute-force matching ends for any target address in minutes.
- The attacker sends zero-value or dust transfers so their lookalike embeds in your history, sometimes spoofing token transfers so it appears you interacted before.
- The payout is your next big transfer, self-inflicted and irreversible.
Risks and Common Mistakes
- Copying addresses from transaction history at all. History is attacker-writable; your address book is not.
- Verifying only the ends of an address. Middles are where impostors live.
- Rushing large transfers. The scam monetizes hurry.
The Habits That Stop It
- Maintain a saved address book in your wallet and send only to saved entries.
- For meaningful amounts: send a small test first, confirm receipt out-of-band, then send the rest.
- On hardware wallets, verify the full address on the device screen, which malware on the computer cannot rewrite.
When It Matters
Every transfer, and acutely for self-custody users moving between their own wallets. It pairs with the broader hygiene on my Security page, and with the rule from contract addresses: in crypto, identity is the full string or it is nothing.
Related Terms
Glossary · Learn · Resource Library · Return to Official Home Page
Copyright © 2026 Crypto Guidance Inc.