Skip to content
← All posts

How Does Address Poisoning Replace a Familiar Address in Wallet History?

Address poisoning inserts a lookalike address into wallet history so the user may copy it later by mistake. An attacker sends a tiny transfer or creates a record whose first and last characters resemble a familiar destination. No private key is broken; the attack exploits abbreviated address displays and the habit of choosing recipients from recent transactions.

A fake lookalike address appears among legitimate wallet transactions

Address poisoning inserts a lookalike address into wallet history so the user may copy it later by mistake. An attacker sends a tiny transfer or creates a record whose first and last characters resemble a familiar destination. No private key is broken; the attack exploits abbreviated address displays and the habit of choosing recipients from recent transactions.

How does the false entry reach transaction history?

An attacker studies public transfers, generates an address with a similar abbreviated appearance, and sends the victim a tiny amount or zero-value token transfer. The blockchain accurately records the operation, so the wallet displays it beside legitimate entries. Later, the user copies that address from history and voluntarily signs a transfer to the attacker.

How common is this pattern?

In June 2026, MetaMask reported that its system flagged 65.4 million attacks from January 2025 through February 2026. The figure reflects detected attempts and one product's methodology, but it demonstrates why an abbreviated address is insufficient for recipient verification.

How should an address be checked before transfer?

Use a preverified address book or a QR code from a trusted channel. Compare the full address on a hardware wallet or another signing display rather than only its beginning and end. For a new recipient, send a small test amount, then retrieve the address again from the original channel instead of transaction history.

What are the limits and risks?

Wallet warnings may miss a new variation or produce a false positive. A test transfer still reaches the attacker when the address is wrong and does not protect the later payment from fresh poisoning. A naming service reduces visual burden but still requires checking the resolved address. Transaction history should not be treated as an address book.

What are the key takeaways?

  • The attack manipulates history rather than the private key.
  • Matching first and last characters does not confirm an address.
  • Recipients should come from a verified address book.
  • Check the full address on a trusted display before signing.
  • A test transfer limits damage but does not replace verification.

Sources

  • MetaMask Jun 2026
  • Address poisoning
  • Wallet history

This article is for information only and is not individual investment advice. Trading crypto carries the risk of losing your funds; results on historical data do not guarantee future results.

Read this next

Why does an exchange hold new customers' crypto withdrawals for 48 hours?

Check the strategy against your own data

ACARO is a terminal that executes a strategy on your own exchange account. Parameter search and backtesting on history are part of the subscription.

See pricing