Good day everyone,
I hope you are all well and having a great day, welcome to CryptoGod-1's blog on all things crypto. Today I will be doing a quick roundup on the recent news from MetaMask regarding a poisoning scam, and the response from consumers.
MetaMask Support Announcement
On the 11th of January 2023 MetaMask Support account on Twitter made a post warning its users of the potential of 'Address Poisoning' threats. Basically this happens when a scammer targets a wallet, such a MetaMask. Once a user has sent a transaction on a blockchain, the scammer sends a $0 token txn to that wallet, in essence 'poisoning' the txn history. This is done with an address that makes use of the same first & last few characters as the real transaction which was sent. It is done in the assumption that the wallet user will not check the full address the next time they sent a transaction, and instead will accidentally send future transaction to the malicious txn.
This means that if a user just copies the last txn address from their transactions, they will end up sending the next amount of funds to the scammers, and therefore losing their funds in the process. It is a scam which relies on user carelessness and haste above all else, unlike traditional scams which target users Secret Recovery Phrase.
It also relies on the fact that crypto wallet addresses are long, and therefore a user will only see the first and final few letters/numbers instead of the entire address. Since their fake address will look similar as the one you are used to sending fund into, it is possible that the user will copy the fake address and paste it as the destination for a future transaction. As we are all well aware once you send funds on the blockchain the transaction is immutable, meaning it cannot be reversed once confirmed, the funds will be lost and irretrievable.
Community Response and Solutions
One solution provided by MetaMask was for users to always double check the address before confirming a transaction, which is sound advice at all levels of crypto. However, we are all aware that it can be time consuming to check every digit and letter in the address, and sometimes you are transacting in haste and complacency can creep in when copying an already used address.
They also state that because these are public blockchains we're interacting with, anyone, anywhere can do as they please in terms of sending one of these $0 token txn to a wallet. There is no way of stopping this, as it is the entire point of crypto and being able to transfer funds with ease. However, they do make some recommendations to protect oneself, which are:

Another user gave their opinion, which is that users making use of an ENS (Ethereum Naming Service) would not need to worry about this issue. They argue that if a user is sending funds to an ENS instead of a traditional long copy and paste address, then the likelihood of being scammed like this is removed. While that is true, as an ENS would mean you are sending your funds to a name saved in your address book, such as BOB.eth or 123.eth, there is the issue of not everyone having an ENS. Just because you have the ENS, does not mean the person you are sending funds to has one. Another issue that could arise with using an ENS is, if like the example above of BOB.eth is the address, the bad actors could create an 'Address Poisoning' which makes B0B.eth shown in your wallet instead (Number Zero instead of letter O). It is a solution for sure, but users need to always be vigilant and aware of the threats they face when making transactions.
Another user was quick to point the finger of blame at MetaMask, calling their wallet "pure garbage," however MetaMask made sure to inform the user that it is possible to happen with any wallet on any blockchain. and not just specific to MetaMask.
Not everyone has this level of unhappiness for MetaMask however, with some users even making their own suggestions of how MetaMask could be improved to ensure this is not possible. As shown below, the suggestion of a "simple hash check in the TX" was taken onboard from MetaMask Support, who explained they will consider it as they are looking into the best possible mitigation strategies.
While it is never nice to see these sort of scams, it does seem like the type of one which can be avoided through a user being diligent in their actions before making a transaction. Always check, and double check, the address before signing the transaction. There is no undo button in crypto, but be being informed and aware, there should be no need for one. Stay safe out there.
Have a great day.
Peace. CryptoGod-1.
Referral links:
Publish0x - https://www.publish0x.com/?a=olejZqrzej
Binance - https://accounts.binance.com/en/register?ref=143611368
Medium - https://medium.com/@1r3n9project
NFT Market Sales
OpenSea - https://opensea.io/RNabc
Follow Me :)
Twitter - @RNabc123