[{"data":1,"prerenderedAt":19},["ShallowReactive",2],{"blog-content-en-address-poisoning-attacks-explained":3},{"slug":4,"title":5,"excerpt":6,"description":7,"bodyHtml":8,"faqItems":9},"address-poisoning-attacks-explained","Address Poisoning Attacks: How They Work and How to Stay Safe","Address poisoning plants lookalike addresses in your transaction history and waits for you to copy one. Here is exactly how the scam works, why truncated addresses make it possible, and the habits that make you immune.","Address poisoning explained: how attackers generate lookalike addresses, seed them into your history with dust and zero-value transfers, and how to protect yourself — verification habits, address books and test sends.","\u003Ch2>The scam that exploits copy-paste\u003C\u002Fh2>\n\u003Cp>Most crypto scams attack your keys or your signatures. \u003Cstrong>Address poisoning\u003C\u002Fstrong> attacks something softer: your habits. The attacker never touches your wallet and never asks you to sign anything. They simply arrange for a lookalike address to appear in your transaction history — and wait for the day you copy it instead of the real one. One inattentive paste, and a transfer meant for your own address or a regular counterparty goes to the attacker, irreversibly.\u003C\u002Fp>\n\n\u003Ch2>How the poisoning actually works\u003C\u002Fh2>\n\u003Cp>The attack starts with generation. Crypto addresses are long enough that attackers can cheaply grind out \u003Cem>vanity addresses\u003C\u002Fem> matching the first and last few characters of yours or of someone you transact with — the exact characters wallet UIs display. Next comes the seeding: the attacker sends a transaction that plants the lookalike in your history. Sometimes it is a tiny \"dust\" transfer of a few cents to your address; on many chains it can even be a \u003Cem>zero-value\u003C\u002Fem> token transfer, which costs the attacker only gas and can be crafted so that your history shows an entry involving the fake address. Your explorer page and wallet activity list now contain a convincing decoy, patiently waiting.\u003C\u002Fp>\n\n\u003Ch2>Why it works: truncation and trust in history\u003C\u002Fh2>\n\u003Cp>Two UX conventions make the trap effective. First, interfaces almost universally truncate addresses to something like 0x1a2b…9f8e — so a lookalike engineered to match those visible characters is \u003Cem>indistinguishable at a glance\u003C\u002Fem>. Second, people treat their own transaction history as a trusted address book: \"the address I sent to last week\" feels safe to copy. Poisoning weaponizes exactly that trust. Nothing about the fake entry looks anomalous; it sits beside your legitimate transactions, formatted identically, often mirroring a real counterparty's truncated form.\u003C\u002Fp>\n\n\u003Ch2>What poisoning can and cannot do\u003C\u002Fh2>\n\u003Cp>Worth stating plainly: a poisoning transaction, by itself, takes nothing. Receiving dust does not compromise your keys; a zero-value transfer does not grant any approval; the attacker gains no power over your wallet. The entire attack is a bet on a \u003Cem>future mistake by you\u003C\u002Fem>. That is good news — it means the defense is entirely behavioral, and unlike a key compromise, there is nothing to remediate. Ignore the dust (interacting with unknown \"gift\" tokens is a separate scam family), and the decoy stays harmless forever.\u003C\u002Fp>\n\n\u003Ch2>The habits that make you immune\u003C\u002Fh2>\n\u003Cp>Four habits close the door. \u003Cem>Never copy addresses from transaction history\u003C\u002Fem> — take them from the destination's own interface, an official page, or a saved contact. \u003Cem>Verify more than the ends:\u003C\u002Fem> before signing, check a mid-section of the address too, since lookalikes are ground to match the ends that UIs display. \u003Cem>Use your wallet's address book\u003C\u002Fem> for recurring counterparties, so routine sends never involve copying at all. And for large or first-time transfers, \u003Cem>send a small test amount\u003C\u002Fem> and confirm arrival before committing the rest. Combine these with the broader hygiene in \u003Ca href=\"\u002Fblog\u002Fcrypto-wallet-security-best-practices\">our wallet security best practices\u003C\u002Fa> — and remember the moment of signing is always the last line of defense, as we stress in \u003Ca href=\"\u002Fblog\u002Fhow-to-connect-wallet-to-dapp\">connecting your wallet to a dApp safely\u003C\u002Fa>.\u003C\u002Fp>\n\n\u003Ch2>How WATS fits in\u003C\u002Fh2>\n\u003Cp>Self-custody puts the signing decision — and therefore this defense — entirely in your hands, and \u003Ca href=\"\u002Fhot-wallet\">WATS\u003C\u002Fa> is built to keep it there: fully non-custodial across EVM, Solana and TON, where you hold your keys and WATS never holds one, with saved contacts so routine transfers never depend on copying from history. What WATS removes is the friction that tempts people to rush: every action, on every chain, is charged in one token, \u003Cstrong>ATS\u003C\u002Fstrong>, instead of the chain's native gas — via an \u003Cstrong>ERC-4337 paymaster\u003C\u002Fstrong> on EVM and an equivalent fee-payer\u002Frelayer on Solana and TON — so a careful test send never stalls because you lack a gas token on that network. ATS is a LayerZero OFT with one balance across all three ecosystems, and collected ATS is burned from a 100M supply toward a 30M floor; WATS is the first and only wallet to combine ERC-4337 and OFT single-token fees with that burn. Details live on the \u003Ca href=\"\u002Fats-fee\">ATS fee page\u003C\u002Fa>.\u003C\u002Fp>",[10,13,16],{"q":11,"a":12},"What is an address poisoning attack?","It is a scam in which an attacker generates a lookalike address matching the visible first and last characters of one you use, then plants it in your transaction history via a dust or zero-value transfer. The attack takes nothing by itself — it waits for you to later copy the fake address from your history and send funds to it. The defense is behavioral: never source addresses from history, and verify beyond the truncated ends.",{"q":14,"a":15},"I received dust or a strange token from an unknown address — am I compromised?","No. Incoming transfers cannot steal keys, create approvals or control your wallet — anyone can send anything to a public address. The risk arises only if you later copy the attacker's address by mistake, or if you interact with an unknown token's contract (a separate scam pattern — simply do not touch it). Ignore the dust and your funds remain exactly as safe as before.",{"q":17,"a":18},"How should I verify an address before sending?","Check more than the ends: lookalikes are generated specifically to match the first and last characters that interfaces display, so compare a middle section as well. Better still, avoid manual comparison for routine payments by using saved contacts in your wallet, and for large or first-time transfers send a small test amount and confirm it arrived before sending the remainder.",1784634268771]