Crypto address poisoning is a scam that exploits a common habit: copying a wallet address from recent transaction history. An attacker sends a tiny amount from an address that looks similar to one you have used before. If you later copy that fake address by mistake, your funds may go to the scammer.
How the scam works
Blockchain addresses are long strings, so many people check only the first and last few characters. A scammer can create an address with matching beginnings and endings, then send a dust transaction to your wallet. The fake transfer appears beside a legitimate exchange or personal address in your history.
The attacker does not need access to your wallet. The danger comes from a rushed copy-and-paste action. Because blockchain transfers are generally irreversible, a mistake can be expensive.
Simple habits that protect you
- Never copy an address from transaction history. Use a trusted address-book entry or copy it directly from the recipient.
- Check the complete address. Compare characters at the beginning, middle, and end.
- Send a small test first. Confirm it arrived before sending the remainder.
- Slow down for important transfers. Treat every address as new unless verified independently.
What to do about suspicious dust
Do not interact with links or tokens attached to an unexpected transfer, and do not use the sender address as a contact. Hide or ignore it where your wallet allows. If you already sent funds to a wrong address, record the transaction ID and contact the recipient platform quickly, although recovery is not guaranteed.
Before every crypto transfer, verify the full destination address outside transaction history.
Address poisoning is a social-engineering trick aimed at hurried copying. A careful verification routine is one of the cheapest security tools available to every crypto user.