← Crypto Scam Library · Risk checks · Research
By Verixia Research · reviewed 2026-08-05 · educational — not financial advice
Attackers generate a wallet address whose first and last characters match one you regularly send to, then send you a tiny (often zero-value) transfer so their address appears in your history. Later, when you copy an address from your recent transactions instead of the real source, you paste theirs.
The middle characters differ completely, but almost nobody reads the middle of a 42-character string.
Vanity-address generation makes matching the visible ends cheap. The dust transfer is the delivery mechanism — it puts the poisoned address into the exact place people copy from. Some variants use fake token transfers that mimic a stablecoin you hold, so the poisoned entry looks like a legitimate USDC movement.
An unexpected zero-value or dust transfer from an address that resembles one of yours; a 'stablecoin' transfer you didn't initiate; a recent-history entry that looks familiar but isn't the contact you saved.
Never copy an address from transaction history. Use a saved address book, verify the full string (not just the ends), and send a tiny test amount first for any large or new transfer. Hardware-wallet address confirmation on-device defeats it entirely.