Illustration of a lookalike wallet address hooked into a legitimate transaction history

One of the more deceptive crypto theft techniques in circulation doesn't involve a fake website, a phishing email, or malware at all. It targets something users trust without thinking about it: their own wallet transaction history. Security researchers refer to it as address poisoning, or a contaminated transfer history attack, and it works by planting a look-alike address in a victim's history until it starts to look like a legitimate, familiar recipient.

How the Attack Actually Works

An attacker generates a wallet address that visually resembles one a target has used before, matching the first and last several characters, which is often all a person checks. They send a tiny 'dust' transaction, sometimes for a fraction of a cent, from that address into the victim's wallet. That transaction now sits in the victim's history, indistinguishable at a glance from a real prior contact.

Why It Works So Well

  • Most wallet interfaces prioritize and surface recent transaction history as a shortcut for repeat transfers.
  • Mobile screens routinely truncate full addresses to the first and last few characters.
  • People recognize patterns rather than verify full strings, the brain fills in the middle instead of checking it.
  • Users who send crypto frequently are the most likely to copy an address from history instead of retyping it.

The Attack Sequence

  • The attacker sends a dust transaction to the target wallet from a look-alike address.
  • The wallet records that address in the transaction history, alongside genuine past recipients.
  • The victim later goes to send funds and selects what looks like a familiar recent address.
  • They select the attacker's address instead of the real one.
  • Funds move on-chain to the attacker and cannot be reversed.

No link is clicked, no software is installed, and no credentials are stolen. The entire attack takes place inside behavior the victim already trusts, their own transaction log.

Key Point

This attack is most effective against people who send crypto often and treat their wallet's recent-activity list as an informal address book. The fix isn't more vigilance in general, it's a specific habit change around where addresses come from.

Who's Most Exposed

Risk rises for anyone who regularly sends funds to exchanges, business partners, or recurring contacts, especially on a mobile wallet where addresses are visually truncated by default. High transaction volume compounds the risk further, since a poisoned entry has more opportunities to get mistaken for a real one in a busy history.

How to Defend Against It

  • Never treat transaction history as an address book, it isn't one, and nothing prevents an attacker from writing to it.
  • Verify the full address character by character before sending anything meaningful, not just the first and last few digits.
  • Use a wallet's saved or whitelisted address feature for recurring recipients instead of copying from recent activity.
  • Avoid copy-pasting addresses out of a recent transactions list altogether, retrieve them from a verified source each time.
  • Double-check the destination address on a second screen or device for any transfer above a threshold you'd regret losing.

What makes this attack dangerous isn't sophistication, it's how ordinary it looks. There's no scam moment to catch, no suspicious link, no urgent message. Just a quiet substitution that depends entirely on a user not looking closely at something they had no reason to distrust.

address poisoningwallet securityphishing

Related reading

How to Read Etherscan Like a Pro: Tracking Stolen Funds After a Phishing AttackCrypto Customer Support Scams: Why That 'Binance Agent' on Social Media Is After Your Seed PhraseThe Five-Minute Habit That Closes Off a Common DeFi Attack Path