Skip to content

Address Poisoning Scams

Intermediate
7 min

You must be logged in for this lesson to count towards your Learn & Earn reward. Please log in to continue.

Address Poisoning Scams

Operating Web3 wallets has long been considered a barrier to entry for beginners to the blockchain world. Before spot ETFs, these digital wallets were mostly essential to buy and hold crypto, and remain vital to interact with DeFi tools.

Understanding the complexities, many in the industry have prioritised simplifying wallet interfaces. Now, most people can send and receive crypto by copy-and-pasting an address into an app – visually as complex as sending an email, or transferring money via a bank.

However, these advancements, paired with growing adoption, have opened the door to a form of crypto scam known as address poisoning.

Address poisoning

Address poisoning leverages the relative complexity of crypto wallet addresses to trick people into sending money to the wrong account. 

Typically, a crypto wallet public key comprises 26 to 63 alphanumeric characters. As this ends up looking like a random assortment of numbers and letters, it’s quite a mouthful – and most don’t have the patience to double-check every single character.

This is what address poisoning scams take advantage of. Scammers create an address that mimics a real, trusted address, but make minor changes in the hope you won’t notice. For example, they might generate a wallet address with the same first and final four numbers/letters as the real address, but alter characters in the middle. 

The scammers then send a ‘dust’ amount of cryptocurrency to put the fake address at the top of the target’s recent transactions list. Without proper attention, the victim may unwittingly send crypto to this address, thus losing their funds.

Data sourced from Chainalysis

Who can be targeted by address poisoning?

Address poisoning attacks typically target those who are active within the DeFi space. 

The permissionless nature of the blockchain means transactions – and public addresses – are visible across most networks.

In theory, this means that anybody who has ever sent crypto on a public blockchain is susceptible to address poisoning scams. However, the risk is greater for those who are deeply engaged in DeFi ecosystems. High-frequency traders, for example, often manage funds across multiple wallets. They rely on copying and pasting addresses due to the sheer volume of transactions they execute each day, which could increase the likelihood of sending funds to a poisoned address.

Case study: Address poisoning

There are several ways address poisoning scams can play out, but perhaps the most common example follows:

Sending ETH to a ‘friend’

  1. You send ETH from your wallet to a friend’s address: 0xA1B2...1234

  2. A scammer monitors the blockchain and sees your transaction.

  3. They send a tiny amount of ETH (e.g., 0.000001 ETH) from a malicious address to your wallet, but they craft their sending address to look very similar to your friend’s:

    • Real friend: 0xA1B2...1234

    • Scammer: 0xA1B2...12F4

  4. In your wallet’s transaction history, you see something like:

    • “Received 0.000001 ETH from 0xA1B2...12F4

  5. At a glance, the address strings appear the same. So later, when you want to send more ETH to your friend, you open your history and pick the ‘recent address’ that looks like your friend’s, without checking carefully.

  6. You paste/use the scam address and send a large amount. 

  7. Result: the funds go to the scammer’s address and are likely unrecoverable.

How a typical address poisoning scam may play out

This example isn’t just limited to sending crypto to your friends and family – address poisoning can happen when using exchange wallets, DeFi protocols and NFT marketplaces.

How to protect against address poisoning

One of the more effective ways to reduce the risk of address poisoning is to double-check the addresses you’re sending crypto to and from. While this can be a little time-consuming and inconvenient, it is also one of the more reliable ways to reduce the risk.

Other, practical methods include:

  • If you do lack the time to check a full public address, at least cross-reference more than just the first and last four characters. Break the address up into sections, and compare 3-4 strings of characters to verify the recipient.

  • Use saved contacts / address books in your wallet instead of copying from transactions.

  • For large transfers, do a small test transaction first, then confirm receipt before sending the full amount.

  • Treat unexpected small deposits (especially in obscure tokens) as suspicious, not as a gift.

Did You Know?

In March 2026, a crypto ‘whale’ using the Ton ecosystem fell victim to an address poisoning scam, transacting 126k TON (worth approx. $229k AUD) to someone else’s wallet. In a stunning turn of events, the scammer, in a moment of (relative) benevolence, returned 116k TON, stating in the transfer memo: I’m sorry, but this is far too much. Please take it back — I know it’s a serious amount of money. Peace.

More information

Address poisoning has arisen as an awkward issue within the crypto space. Simplifying the process of sending/receiving digital currencies is a key goal of modern industry players – but mitigating the risk of people exploiting this streamlined approach is of equal importance. Luckily, there are a few potential safeguards you can employ while navigating the engrossing Web3 ecosystem to tackle the dangers of address poisoning. 

Educating yourself and those in your community can be a useful preventative measure against scams like address poisoning. Global blockchain analytic firms like Chainalysis work to provide vital data, return stolen funds to victims and collaborate with law enforcement to dismantle the systems used by these bad actors. To learn more, consider some of the additional reading below.

Additional reading:

‘Swyftx’ is a brand of Swyftx Pty Ltd (ABN 72 623 556 730, AFSL 568543). Swyftx’s spot cryptocurrency exchange services are not provided under Swyftx’s AFSL and are not issued, arranged, distributed or authorised by Eightcap Pty Ltd (ABN 73 139 495 944, AFSL 391441) (Eightcap), Web3 Loans Pty Ltd (ABN 48 668 516 952) or Web3 Ventures Pty Ltd trading as Block Earner (ABN 63 655 090 869, ACL 551024) (Block Earner). Derivative products are issued by Eightcap and distributed by Swyftx. Credit products are provided by Block Earner. Swyftx is an authorised credit representative of Block Earner (Credit Representative No 579667). 

The information on this website is general in nature and does not consider your objectives, financial situation or needs. You should consider whether this is suitable for you and your personal circumstances. Any statistics, price references, graphics or information on this page related to the performance of any asset, market or trading account are not indicative of current performance and should not be relied upon when making a decision to invest. This website is not targeted at the public, nor residents, of any specific country and is not intended for distribution to residents in any jurisdiction where that distribution would be unlawful. Digital assets are volatile and carry high levels of risk, you may lose some or all of your investment. Derivative products are highly speculative and carry significant risk. Credit products are subject to lending criteria. Before making any decision about whether to acquire a product, you should read the applicable Terms of Service and, where relevant, the PDS, FSG, Credit Guide and TMD available on Swyftx’s website, as well as the respective product issuer’s website (if applicable).