Address Poisoning: How to Avoid Sending Crypto to a Lookalike Address
A practical explanation of address poisoning and a safer process for checking wallet recipients.
Address poisoning is an attack where a malicious address is placed into a wallet’s transaction history so the user may copy it during a future transfer. The defense is simple but discipline-based: do not use history as an address book, re-check the trusted source, and verify more than the first and last characters.
How does address poisoning work?
An attacker sends a tiny transaction or creates a record with an address that visually resembles one you have used before. A familiar-looking line appears in wallet history, and the user may accidentally copy it.
MetaMask explains this pattern in its guide to address poisoning scams. The problem is that crypto addresses are long, while people often check only the beginning and end.
Why are first and last characters not enough?
An attacker may generate a lookalike address with a similar prefix and suffix. For a small transfer this is already painful; for a large transfer it can be critical. Interfaces often shorten addresses and hide the middle, where the difference sits.
The practical minimum is to verify the address from the original source, check the network, compare several address segments, and avoid autofill from history.
How can funds be sent more safely?
Use an address book only if you added the address yourself and know where it came from. For a new address, reopen the official source: a website, a secure message, a hardware-wallet display, or a previously verified document.
For a large amount, a test transfer can help. But it helps only if the second transfer goes to the same verified address, not to a newly copied line from history.
Which habits reduce risk?
Do not copy an address from a block explorer just because it resembles the one you need. Do not use random history entries as an address book. Hide spam tokens if your wallet allows it. Separate wallets used for frequent transactions from wallets used for storage.
Ledger also explains the pattern in its article on the address poisoning scam, noting that the attack targets the habit of copying shortened addresses.
What limits and risks remain?
No interface removes responsibility completely. Wrong networks, missing memo or tag fields, malicious websites, clipboard replacement, and phishing can cause losses even without address poisoning.
The core rule is that a recipient address is not a technical detail; it is a financial instruction. Before sending, verify the source, network, address, and transaction context, especially when the transfer cannot be reversed.
Sources
- MetaMask safety
- Ledger academy
This article is for information only and is not individual investment advice. Trading crypto carries the risk of losing your funds; results on historical data do not guarantee future results.
Check the strategy against your own data
ACARO is a terminal that executes a strategy on your own exchange account. Parameter search and backtesting on history are part of the subscription.
See pricing