Address poisoning: how the lookalike address scam works
Address poisoning plants a lookalike wallet in your history so you copy it next time. How the attack works, a dated case, and the habits that stop it.
Address poisoning is a scam in which an attacker plants a wallet address that looks like one you use into your transaction history, so that the next time you copy an address from that history, you send the funds to the attacker. It is also called address spoofing. Below: how it works, a dated case, and what changes when you message or pay a wallet by name on Cherry (cherry.fun), the wallet-to-wallet messenger and community app for crypto.
How address poisoning works
The attacker sets up the first three steps, and the victim takes the fourth.
- They watch a wallet that moves money and pick an address it sends to often, such as an exchange deposit address.
- They generate a vanity address whose first and last few characters match that address. Pine Analytics estimated in April 2025 that a Solana address matching three characters at each end costs up to about $30 of compute.
- They send a transfer from the lookalike to your wallet, so it lands in your history. On Ethereum and other EVM chains this is often a zero-value token transfer: Etherscan’s article of 9 March 2026 names dust transfers, spoofed token transfers and zero-value token transfers as the usual tactics. On Solana, Pine Analytics described tiny SOL transfers from the vanity address.
- Next time you pay, you copy the recent entry, glance at both ends, and sign.
The attack needs no access to your wallet. It works only if you send to the planted address yourself, which is why it runs at volume: Etherscan cited research putting the success rate of a single attempt at about 0.01% on Ethereum.
On 3 May 2024, Cointelegraph reported that an unnamed trader lost 1,155 WBTC, worth about $68 million, in a single transaction to an address-poisoning scam first flagged by the on-chain security firm Cyvers. On 10 May 2024 it reported that the attacker had sent back about 22,960 ETH, worth $65.7 million or over 96% of the dollar value taken, after negotiations.
How to avoid it
- Save the addresses you pay often in your wallet’s address book. Etherscan also suggests private name tags.
- Send to a name such as alice.sol or alice.skr. Lookalike names can be registered too, so check that the name resolves to the wallet you expect before a large transfer.
- Never copy an address from transaction history. Trezor’s support guide gives that advice for block explorers as well as its own app.
- Compare every character of the address with the source you trust, the middle included.
- Send a small test amount, confirm it arrived, then send the rest from the same trusted source.
- Ignore transfers you cannot account for. Etherscan said in March 2026 that it hides zero-value transfers by default.
Example on Cherry
On Cherry you can DM a wallet by its .sol, .sns or .skr name, so the address you reach comes from the name. A free first DM from a stranger, lookalike or not, lands in your Requests tab without a notification.
OTC deals in the Cherry mobile app for iOS and Android settle through an on-chain escrow inside the conversation with the other wallet. Each side funds its leg, the program settles when both legs are in, and neither side pastes a payment address.
Cherry shows a wallet that has no name by its short address, the first four and last four characters, and those are the characters an attacker copies. To read a full address, use the copy button on the wallet card, paste the result into an explorer such as Solscan, and compare it with the address you trust.
Related terms
- Is sharing your wallet address safe? : what a public address exposes.
- How to spot a fake airdrop : another scam that arrives as a transfer.
- .sol domain name and .skr domain : names that point at a wallet.
- Crypto escrow : how a program settles both legs of a deal.
FAQ
Can address poisoning take funds without my signature? No. The attacker never gets access to your wallet or your keys: the poisoned transfer only adds an entry to your history. Funds leave only when you sign a transfer to the lookalike address yourself, so checking the full address before you approve stops the attack.
Sources
- Trader loses $68M in address poisoning scam, Cointelegraph, 3 May 2024
- WBTC address poisoner sends nearly all funds back, Cointelegraph, 10 May 2024
- Address Poisoning Attacks Are Rising on Ethereum, Etherscan, 9 March 2026
- Solana Account Dusting and Address Poisoning, Pine Analytics, 24 April 2025
- Why address poisoning works without stealing private keys, Cointelegraph, 19 February 2026
- What are address poisoning attacks and how to avoid them, Trezor
Try Cherry
Sign in with a wallet, DM any address, and join token-gated and paid communities. No phone number, email, or KYC.