Crypto Scams

Address Poisoning: How a Fake Address Slips into Your Transaction History

31. August 2026.

Address Poisoning: How a Fake Address Slips into Your Transaction History

Key takeaways:

  • Address poisoning is a technique where an attacker sends a worthless transaction to your address from an address that resembles one you have previously sent funds to.
  • The attacker counts on you copying an address from your transaction history without checking the full string.
  • Checking only the first and last characters of an address is not reliable because the attacker can generate an address with the same characters.
  • Always check the full address, use an address book or notes, and send a small test amount with recipient confirmation before a larger transaction.

Address poisoning is a sneaky technique where an attacker pollutes your transaction history with fake entries. The goal is not to steal funds directly, but to trick you into copying the wrong address next time. This attack exploits the human habit of scrolling through history and trusting what we have already seen.

In this article, I explain how the address poisoning pattern works, why checking only the first and last characters is insufficient, and what practical steps you can take to reduce the risk.

What is address poisoning and what does an attack look like

Address poisoning is a type of attack where the attacker generates an address whose first and last characters match those of someone you have previously sent funds to, such as a supplier or an exchange. From that fake address, they send a worthless transaction to your address. This transaction appears in your history, right next to the legitimate recipient address.

When you next send funds to that recipient, you might think the fake address is correct and copy it from history. Instead of reaching the recipient, the funds go to the attacker. The attacker does not need to breach your security, they just wait for you to make a mistake.

Why checking only the first and last characters is not enough

Many users check an address by comparing the first few and last few characters. This is quick but dangerous. The attacker can generate an address that matches in those parts, while the middle is completely different. This is technically feasible and does not require significant resources.

For example, if the recipient address starts with 0x1234 and ends with abcd, the attacker can generate an address that also starts with 0x1234 and ends with abcd, but the rest is completely different. If you only glance at the first and last characters, you will not notice the difference.

That is why it is crucial to check the entire address, character by character. The most reliable practice is to compare the full address against a source you received directly from the recipient or saved in your address book.

How to spot a poisoned address in your transaction history

Poisoned addresses usually appear as transactions with zero amounts or worthless tokens. They may also contain a message in the transaction data that tries to look legitimate, but the most important thing is to pay attention to the address itself.

  • Check whether the address is exactly the same as the one you used before. If it differs in any character, that is a red flag.
  • Ignore transactions that have no value or come from unknown addresses.
  • Use the address book in your wallet to save addresses you have already used, instead of looking them up in history.

If you notice a suspicious transaction, do not send funds to that address and verify the address directly with the recipient.

Practical steps to protect yourself from address poisoning

Protecting against address poisoning requires a few habits. First, always check the full address before sending. Second, use the address book or notes in your wallet to save addresses you frequently use. Third, send a small test amount and ask the recipient to confirm receipt before the main transaction, especially if you are sending to a new address.

Additionally, you can use a hardware wallet that displays the address on the device screen, which helps if malicious software changes the address in your clipboard. You still need to check the address on the screen, but compare it with the address from your address book or directly with the recipient, not with your transaction history.

For small businesses, it is advisable to establish a procedure for double-checking addresses, especially for larger amounts. One person can prepare the transaction, and another can verify the address before confirmation.

What to do if you suspect you are a victim of address poisoning

If you notice that you have sent funds to the wrong address, immediately stop any further transactions. Unfortunately, blockchain transactions are irreversible, so you cannot recover the funds. Report the case to the Serbian Ministry of the Interior’s Department for High-Tech Crime (vtk@mup.gov.rs, 011/3540-231) and inform your network, but be aware that recovery is unlikely.

Regularly review your transaction history and be suspicious of any address that does not match completely.

The most important thing is to be careful yourself and to apply the address book and test transaction before every send.

Why awareness of this pattern is key for users in Serbia

Address poisoning is especially dangerous because the attacker can generate a fake address that matches in the first and last characters, and victims are often unaware they have been attacked until they lose funds.

Spreading information about this pattern gives users a chance to recognize it before they send funds.

Related articles

Frequently asked questions

How does address poisoning work?

The attacker generates an address that resembles one you have previously sent funds to, and from that address sends a worthless transaction to your address. The fake address thus appears in your history, right next to the legitimate one.

Is it enough to check the first and last characters of an address?

No, because the attacker can generate an address that matches in those parts. Always check the full address character by character.

How can I recognize poisoned addresses in history?

Pay attention to transactions with zero amounts or worthless tokens. If the address is not exactly the same as the one you used before, ignore it.

What should I do if I sent funds to the wrong address?

Transactions are irreversible, so you cannot recover the funds. Report the case to the Serbian Ministry of the Interior’s Department for High-Tech Crime (vtk@mup.gov.rs, 011/3540-231) and stop further transactions, but focus on prevention in the future.

Does a hardware wallet help against address poisoning?

Only partially. The device screen protects you if malicious software changes the address in your clipboard, but if you copy the wrong address from history yourself, the device will display exactly that. Use the screen to compare the address with the one from your address book or directly with the recipient, not with your transaction history.

← Nazad na BlockchainSecurity.rs
Scroll to Top