Crypto Address Poisoning: How to Verify Wallet Addresses Before You Send
Crypto address poisoning plants a lookalike address in your transaction history. Learn how it works and follow a safer verification checklist.
Last updated
Copying a familiar address from recent activity feels efficient. It can also be the exact shortcut an attacker expects. Crypto address poisoning turns public transaction history into a trap by placing a lookalike address beside legitimate activity. This guide extends our crypto wallet security hub with a repeatable way to verify the destination before you send.
Important
This is educational information, not financial advice (NFA). On-chain transfers can be irreversible, and no checklist guarantees safety. Verify current guidance independently, use only funds you can afford to lose, and do your own research (DYOR).
What Is Crypto Address Poisoning?
Address poisoning, sometimes called address spoofing, is a social-engineering attack against copy-and-paste habits. An attacker creates an address that resembles one you use, then causes it to appear in your wallet or block-explorer history. Later, you may copy the imitation instead of retrieving the recipient's verified address.
Think of someone slipping a counterfeit contact card into a stack of real receipts. The receipt proves an event occurred. It does not prove that the printed contact belongs to the person you meant to pay.
The official Ethereum accounts documentation explains that an externally owned account address has 40 hexadecimal characters plus the 0x prefix. Interfaces often shorten that value. A criminal does not need an identical address or your private key; matching a few visible characters may exploit a hurried comparison.
An EIP-55 checksum address can detect many accidental character or capitalization errors, but it cannot authenticate a recipient. An attacker's lookalike address can carry its own valid checksum, so compare the full value from an independent source.
How the Scam Reaches Your History
The usual flow has four stages:
- Observation: The attacker watches public activity and identifies an address you use.
- Imitation: Software generates an address whose beginning, ending, or both resemble the legitimate destination. Its middle remains different.
- Seeding: A tiny transfer, zero-value token event, or another visible interaction places the lookalike in history. The display varies by chain, token, explorer, and wallet.
- Misdirection: You later copy the poisoned entry and authorize a real transfer to the attacker.
Chainalysis's October 23, 2024 analysis documents this lookalike-and-seeding pattern. Trezor's current address poisoning guidance similarly warns users not to copy destinations from transaction history or a block explorer.
The dangerous step is the last one: you sign a valid transaction to the wrong recipient. The network is not confusing two addresses. Ethereum's transaction documentation lists the receiving to address as part of the signed instruction, and the network executes the destination you approved.
Address Poisoning Is Not Key Theft or Dusting
These threats can look similar, but their remedies differ.
| Threat | Attacker's goal | What you see | Primary defense |
|---|---|---|---|
| Address poisoning | Make you pay a lookalike | A misleading history entry | Retrieve and verify the destination independently |
| Seed-phrase phishing | Take account control | A request for recovery words | Never disclose the secret |
| Malicious approval | Gain token-spending authority | An allowance or permission request | Inspect spender, scope, amount, and expiry |
| Dusting or spam token | Track or lure interaction | An unsolicited asset or transfer | Ignore it and do not follow embedded links |
An unexpected incoming transfer does not by itself mean your private key leaked. A public address is designed to receive assets. Coinbase's public-address guidance distinguishes a shareable receiving address from the private key needed to control funds.
Do not send the unwanted amount back to “clean” your wallet, and do not visit a URL embedded in a token name. Treat the entry as untrusted data.
A Safer Address Verification Workflow
1. Start from a trusted source
Retrieve the destination through a channel you already trust: a verified address-book entry, the recipient's authenticated account, or an official deposit page reached through a bookmark. A transaction list records what happened; it is not a trusted contact directory.
For an important payment, confirm the address through a second channel. If it arrives by email, verify it using a known phone number or established encrypted chat—not by replying to the same potentially compromised thread.
2. Compare the complete address
Do not approve based only on the first and last four characters. Expand and compare every character against the trusted source. If the wallet cannot reveal the full destination, pause and use an interface that can.
Verify the network and asset too. The same-looking EVM address may work on several networks, but that does not prove the recipient supports your selected chain or token.
3. Verify on the signing device
If you use a hardware wallet, compare the complete destination shown on that trusted device. Clipboard-replacement malware is different from address poisoning, but the same device check helps catch both.
This is one application of clear signing: confirm the recipient, asset, amount, network, and action you authorize. A readable prompt helps but does not replace independent comparison.
4. Use a verified address book or allowlist
For recurring recipients, save and label an address only after an out-of-band check. Where an exchange offers withdrawal allowlisting and a delay for additions, consider enabling it and protect changes with strong authentication. Treat any unexpected request to replace a known address as high risk.
5. Test carefully, then re-verify
A small test can confirm that the recipient controls an address and that the route works. It does not make a later copy from history safe. Reuse the originally verified destination, compare it again, and ask the recipient to confirm arrival before the main transfer. Trezor recommends a small test for large transfers while noting the extra fee.
What Wallet Warnings Can and Cannot Do
Wallets increasingly flag suspicious addresses or history entries. MetaMask announced address-poisoning detection on June 17, 2026, while Trezor documents filtering that can blur suspicious activity. These controls can remove noise and surface risk.
They are not proof of safety. Coverage varies by wallet, network, transaction type, and threat data. A new attacker address may have no reputation. MetaMask's security-alert documentation describes trust signals as informational rather than guarantees. Treat an alert as a reason to stop; treat no alert as a reason to perform your normal checks.
Common Mistakes and Remaining Risks
- Checking only shortened characters: Attackers optimize the characters interfaces show.
- Losing continuity after a test: A test proves one destination, not the next history entry.
- Assuming a hardware wallet knows the payee: It protects keys and displays data; you must verify identity.
- Trying to remove unsolicited activity: Public chains allow strangers to create visible records. Interaction may add risk.
- Relying on simulation alone: Transaction simulation may show a normal transfer to the wrong address. It previews execution, not human identity.
- Ignoring channel compromise: A verified address can be replaced in a hacked email, invoice, website, exchange account, or clipboard.
Quick Pre-Send Checklist
- Did I obtain the destination from a trusted source rather than history?
- Did I compare every character, not only the shortened prefix and suffix?
- Did I verify the network, asset, amount, and destination on the signing device?
- For a new or changed recipient, did I confirm through a second trusted channel?
- If I sent a test, did the recipient confirm it, and am I reusing the same address?
- Am I calm enough to review the request without deadline pressure?
If any answer is no, do not sign yet.
Frequently Asked Questions
Can a poisoning transfer drain my wallet by itself?
Usually, no. The core attack depends on you later copying the lookalike and sending funds. Do not interact with unsolicited tokens or links, because they may belong to a different phishing or approval attack.
Has my wallet been hacked if I see a strange transfer?
Not necessarily. Anyone can send activity to a public address. Check for outgoing transactions or approvals you did not authorize, but an unsolicited incoming entry alone does not prove key compromise.
Does a small test prevent address poisoning?
It reduces the impact of an initial mistake only if you preserve and re-verify the tested destination. Copying a fresh history entry for the main payment reintroduces the attack.
Can a wallet warning guarantee an address is safe?
No. Warnings and verified labels are useful signals, not guarantees. New threats, incomplete coverage, and compromised legitimate channels remain possible.
Make Destination Verification a Habit
Address poisoning succeeds by making a fraudulent address feel familiar. The durable defense is procedural: source the destination independently, compare the full value, verify it on the signing device, and use a second channel for important changes. Slow down even when the transfer looks routine.
This guide is not financial advice. Crypto transfers and markets carry substantial risk; verify current wallet guidance, use only funds you can afford to lose, and DYOR before acting.
Keep learning

Crypto Scam Prevention Guide 2026: How to Spot, Avoid, and Respond
Crypto scams drain billions every year — and most victims thought they were careful. This how-to guide covers 10 scam types, step-by-step prevention rules, a security checklist, and what to do if you get hit.

Clear Signing vs Blind Signing: How to Read Crypto Wallet Prompts
Clear signing makes wallet prompts readable. Learn how blind signing differs, what EIP-712 and draft ERC-7730 do, and what to verify.

Crypto Transaction Simulation: Read the Result Before You Sign
Crypto transaction simulation previews likely wallet balance, approval, and contract changes before signing. Learn what to check and where it can fail.
Explore related topics

Solidity abi.encode vs abi.encodePacked: Differences and Collision Risks
Compare Solidity abi.encode and abi.encodePacked, see why packed dynamic values can collide, and choose safer encoding for hashes and contract calls.
Ethereum Proxy Contracts Explained: Delegatecall, UUPS, and Upgrade Risks
Learn how Ethereum proxy contracts use delegatecall, how transparent, UUPS, and beacon proxies differ, and how to verify upgrade authority safely.