Skip to content
Wallets & SecurityBeginner

What is address poisoning in crypto?

Address poisoning is a crypto scam that sends tiny transactions from lookalike addresses. Attackers hope you copy the fake address and send funds to it.

Vahe HakobyanVahe HakobyanEditor-in-chief Updated Oct 5, 20264 min readFact-checked
A dark navy desk with blank address book pages and a thin glowing red line.
Illustration: World-Crypt
On this page
Key takeaways
  • Attackers match the first and last characters of a real address.
  • Checking only the ends of an address is not enough.
  • A confirmed transfer to a poisoned address is final.
  • Address poisoning does not ask for your private keys.

Short answer

Address poisoning is a scam in crypto. Attackers send tiny transactions from addresses that look like ones you have used or plan to send to. They hope you copy the fake address from your history and send funds to it.

The fake address usually sits quietly in your activity list. You may see it when you open your wallet to send a payment. The attack works if you choose that entry instead of the real one.

How do I avoid address poisoning?

Verify the full recipient address before you send funds. Checking only the first and last characters is not enough, because a fake address copies both. Get the address from the recipient through a channel you trust, then compare every character. Do this on the screen where you confirm the transfer.

Before you send

  • Get the address from the recipient directly.
  • Compare every character with the address you received.
  • Check that the full address matches on the confirmation screen.
  • Use a saved contact when you have one.

What if you send to a poisoned address?

If you send funds to a poisoned address, the transaction is irreversible. Once the network confirms it, the transfer is final. A wallet provider or exchange cannot reverse it for you.

How does address poisoning work?

Attackers send a tiny transaction from an address they control. That address is crafted to look like one you have used or plan to send to. The fake entry then appears in your transaction history. Later, you may copy the wrong address by mistake.

  • The first characters match a real address.
  • The last characters match the same address.
  • The middle characters are different.
  • The fake entry looks familiar in your history.

How is it different from phishing?

Phishing tries to get you to give up a password, a seed phrase, or a private key. Address poisoning does not ask for your private keys or any secret. It depends on you copying the wrong address from your history.

Address poisoning compared with phishing
Question Address poisoning Phishing
What the attacker wants You send funds to a lookalike address You share a secret or click a harmful link
What the attacker uses A similar address in your history A message, site, or app that asks you to act
What stops it Checking the full address Checking the sender and the web address

Frequently asked questions

No. The attacker does not get your private keys or move funds on their own. The scam depends on you copying the fake address and sending funds to it.

They are different. A dusting attack sends tiny amounts to many wallets to trace activity or link them. Address poisoning uses a lookalike address to trick one person into sending funds to it.

The transfer is irreversible. Report it to your wallet provider and the exchange you used. Keep the records, because they may flag the address on their platform, but they cannot reverse the transfer.

No. A hardware wallet protects your private keys and can show the address on its screen. You still need to verify the full address yourself before you send.

Was this guide helpful?
Written byVahe HakobyanVahe Hakobyan is the editor-in-chief of World-Crypt. He covers bitcoin, markets and regulation, and leads the newsroom that fact-checks every story before it goes live.