Address poisoning
Definition
Address poisoning is a scam that plants a lookalike address in your transaction history, hoping you later copy and pay it by mistake.
Address poisoning exploits a habit almost everyone has: checking only the first and last few characters of a long wallet address. An attacker watches your public activity, generates a “vanity” address whose start and end match an address you have used, and sends you a token transfer, often of zero value, from that lookalike. The transfer’s only purpose is to place the deceptive address into your transaction history.
Why it matters
Later, when you want to reuse an address, you may scroll your history and copy the poisoned entry by mistake, because it looks nearly identical to the real one. If you paste it and send, the funds go to the attacker rather than the intended recipient, and the transfer cannot be reversed. The scam costs the attacker very little and relies entirely on a moment of inattention.
Common misunderstanding
Some users believe receiving such a transfer means their wallet was hacked. It does not: anyone can send tokens to a public address without any access to it, so an unexpected entry is not a breach. The defence is procedural, not technical. Verify the full address, not just the ends; use a trusted saved contact or address book rather than copying from history; and send a small test amount for large or new transfers. Some wallets and explorers now flag destinations that closely resemble ones you have used before. Even so, the most reliable protection remains your own careful check of the full address before every send.
Related terms
Frequently asked questions
Does a poisoning transfer mean my wallet is compromised?
How do I avoid falling for it?
Note: CamoCrypt is security & education only — no prices, no predictions, no investment advice. Verify every address and contract yourself; we cannot recover lost funds and neither can anyone who contacts you claiming they can.