Address poisoning
Addresses are long and most people only check the first and last few characters. Attackers exploit that. Address poisoning sends a tiny amount of value from an address that starts and ends like one you already use, so it appears in your history as a familiar-looking entry.
The trap
Later, when you copy an address from your history to send funds, you paste the attacker’s lookalike instead of your real recipient. The transfer goes to them.
How to avoid it
- Verify the entire address, or at least a middle chunk, not just the ends.
- Use saved contacts or address books in your wallet instead of copying from history.
- Do a small test transfer before a large one.
- Treat unexpected tiny inbound transfers as a warning sign.
Why monitoring helps
Address poisoning is quiet by design — the dust is small and easy to miss. An agent that watches your outflows and flags unusual recipients gives you a second set of eyes before a large transfer leaves.
