← Crypto Scam Library · Risk checks · Research

Address Poisoning: The Copycat-Address Scam

By Verixia Research · reviewed 2026-08-05 · educational — not financial advice

What address poisoning is

Attackers generate a wallet address whose first and last characters match one you regularly send to, then send you a tiny (often zero-value) transfer so their address appears in your history. Later, when you copy an address from your recent transactions instead of the real source, you paste theirs.

The middle characters differ completely, but almost nobody reads the middle of a 42-character string.

How it works

Vanity-address generation makes matching the visible ends cheap. The dust transfer is the delivery mechanism — it puts the poisoned address into the exact place people copy from. Some variants use fake token transfers that mimic a stablecoin you hold, so the poisoned entry looks like a legitimate USDC movement.

The tells

An unexpected zero-value or dust transfer from an address that resembles one of yours; a 'stablecoin' transfer you didn't initiate; a recent-history entry that looks familiar but isn't the contact you saved.

How to avoid it

Never copy an address from transaction history. Use a saved address book, verify the full string (not just the ends), and send a tiny test amount first for any large or new transfer. Hardware-wallet address confirmation on-device defeats it entirely.

Other scam patterns