A simple way to prevent crypto address poisoning attacks

A simple way to prevent crypto address poisoning attacks


A crypto address poisoning attack is a malicious method to steal crypto currencies by changing the original destination address, entered by a sender, with a modified address to which attackers want to send crypto.

Security infrastructure providers like Blockaid record an average of over 160,000 on-chain address poisoning attempts per day, translating to roughly 4.8 million attack attempts per month.

Security researchers estimate that more than 225 million to 270 million total poisoning events have been deployed on-chain targeting millions of individual wallets.

Address poisoning attacks have resulted in over $83 million in confirmed baseline losses across thousands of tracked on-chain incidents, with individual catastrophic thefts adding tens of millions more per single event.

Bybit lost about $1.5 bln. on February 21, 2025. This attack was not a simple address poisoning attack, but a multi-level sophisticated attack, which included a phishing technique, malware infection, user interfaces and smart contracts manipulations. According to Bybit disclosures and security analyses, attackers infiltrated internal networks, infected employee devices with malware, and manipulated the transaction-signing interface. The interface displayed a legitimate address to the engineers approving the transfer while secretly altering the underlying smart contract logic to route funds to the hackers.

Notable Address Poisoning Attacks:

May 3, 2024 – ~$68 Million to $70 Million (WBTC/BTC)

A prominent crypto trader accidentally sent roughly 1,155 Wrapped Bitcoin (WBTC) to a spoofed address that mirrored the first and last characters of their intended destination.

December 20, 2025 – $50 Million (USDT)

A high-net-worth trader attempting to transfer funds from Binance first sent a 50 USDT test transaction. An automated scam script immediately generated a matching lookalike address, prompting a fatal copy-paste error for the remaining $50 million.

January 30, 2026 – ~$12.4 Million (4,556 ETH)

An investor fell victim after their wallet was "dusted" with micro-transactions for over two months, eventually copy-pasting a poisoned vanity address while making a routine OTC deposit.

March 5, 2026 – ~$24 Million (aEthUSDC)

Well-known crypto influencer "sillytuna" lost a massive position in aEthUSDC after selecting a poisoned lookalike address from their recent transaction history.

A simple way to prevent address poisoning attacks is to perform these steps:

Step 1. Go to this tool: https://www.dynpass.online/tools/cmp/cmp.html

Step 2. Before pasting a destination address into an interface of a crypto wallet, paste it into the first field of the tool. Then, paste the destination address into a destination field of the crypto wallet.

Step 3. Wait some time, for example, one minute. If you are under an address poisoning attack then the destination address will be changed by attackers.

Step 4. Copy the destination address from the destination field of your crypto wallet and paste it into the second field of the tool. If attackers modified the destination address then the addresses in both fields of the tool will be different.

Step 5. Click on the “Compare” button.

Here are some examples.

Example 1.

p1

p2

Find a difference.

1BoatSLRHtKNngkdJKzobR76LKB3QNdVDC

1BoatSLRHtKNngkdJKzoBR76LKB3QNdVDC

 

Example 2.

p3

p4

Find a difference.

1A1zP1eP5QGefi2DMPTfTL5SLmv7DivfNa

1A1zP1eP5QGefi2DMPPfTL5SLmv7DivfNa

 

Example 3

p5

p6

 

 

 

 

 

 

How do you rate this article?

6


I_g_o_r
I_g_o_r

I am curious about science, technologies and their applications to solving real problems.


Simple solutions to complex problems
Simple solutions to complex problems

Each post is devoted to a simple solution to a complex problem.

Publish0x

Send a $0.01 microtip in crypto to the author, and earn yourself as you read!

20% to author / 80% to me.
We pay the tips from our rewards pool.

Page not displaying correctly?