You open your wallet and prepare to transfer money. Recent transactions seem to be okay, so you copy the last address you sent and paste it. A few minutes later, the token enters an address that looks similar but does not actually belong to you. No one has "hacked" you, your historical record has deceived you.
This is address poisoning. It is silent, inexpensive, and specialized in people's daily habits. The attacker will not forcibly invade, but will plant traps in your path and wait for you to step on them step by step.
Today, such attacks can be seen everywhere in chain history, especially on chains where gas bills are low and people trade frequently.
Address poisoning is the norm
Address poisoning is a social engineering attack that exploits the way we handle addresses.
The wallet will display a list of past collection addresses. Blockchain browsers usually only display the first and last characters of an address. Most people are accustomed to copying and pasting rather than saving contacts. The attacker knows this well.
They created a "vanity address" with the same characters as the real payee address. Then inject this address into your history with an airdrop or zero-value transaction. A few weeks later, when you needed to pay the merchant again, you copied the address that "looked like". The funds disappeared.
When user interface habits solidify into shortcut operations, they become attack surfaces. Address poisoning takes advantage of this shortcut, not the encryption technology itself.
Where did address poisoning come from?
This has its own development context. Early "dust attacks" spread extremely small amounts of tokens to track user identities. Garbage transactions probe memory pools for arbitrage. As the cost of block space on L2 decreases and user behavior becomes more standardized, attackers have shifted from making noise to inducing fraud.
From dust to fraud: Dust was once the ultimate goal, but now it has become a means of transmission. The real "payload" is the "look-alike" address that appears in your recent activity record. The goal is not to affect the market or clog the memory pool, but to tamper with your memory by tampering with the user interface.
Why users are fooled: Most interfaces shorten the address to 0x12ab... Format like 9881. Humans recognize patterns through marginal features. If the first four and last four characters match, it "feels" correct. Coupled with time pressure, mobile phone screen limitations and operating habits, the consequences can be imagined.
How false history records are constructed
Let's take a look at a typical address poisoning operation flow. It is low-cost, repeatable, and optimized for the way wallet displays information.
Attacker Toolkit: Two elements are indispensable: a vanity address with the same visible edge characters as the target address, and a way to implant it into the victim's history. The attacker generates a "look-alike" address that matches the beginning and end characters of the target address, and then makes the address appear in the victim's history by sending dust or zero-value transactions.
Poisoning process: In the investigation stage, the attacker finds a target wallet that has recently paid to a payee address; in the forgery stage, a vanity address with the same visible edge characters as the real address is generated; in the implantation stage, a micro transfer is sent from the vanity address to the target wallet, or a zero-value transaction is made to appear in the target's activity record; In the waiting phase, days or weeks later, the target opens the wallet, scrolls through history, and copies the most familiar collection address; in the capture phase, funds flow into the attacker's "likely-looking" address. No private key was leaked, just a perfect copy-and-paste trap.
What is a stateful spam transaction: A study measured nearly 1.4 billion such transactions on the Ethereum main network and the main L2 network and found that address poisoning accounted for 53% of stateful transactions on Ethereum that were not rolled back.
What we are currently seeing on the chain
The data confirms what many people see in their wallets: more and more zeroes and dust transactions, with the purpose of influencing what we copy later. The research shows that address poisoning dominates certain ineffectual transactions on Ethereum. L2 networks such as Optimism and Base also show large amounts of state-of-state activity, consistent with the fact that low gas fees make spam experiments cheap.
Why Ethereum is so obvious: The main network has a broader address set and a longer history, making the habit of "copying from last record" more common. Attackers are selective, and a few high-value targets are enough to cover gas costs. Cheap block space fueled experiments: On L2, the cost of planting dozens of bait addresses was extremely low. Even if the success rate is small, it can be profitable after scale. This is typical spam economics.
Information such as the Internet, spam cost characteristics, common poisoning signals, relevant research findings and sources were recorded in detail during the study. Due to its high gas fees, Ethereum's attack targets are mostly high-value wallets with a long history;Optimism and Base often have a large number of vanity addresses and zero-value transfers in their activity records due to their low gas fees.
The opportunity created by user habits
Address poisoning was successful because it took advantage of our shortcut. Most of the mistakes I hear about stem from daily habits.
Copy from history by default: People don't save contacts, but scroll through and reuse them, which keeps the poisoned address in a prominent position. Character matching at the edge of trust: Many user interfaces only display the first and last 4 digits of the address, and if both ends look correct, people don't carefully check the middle part. The vanity addresses designed by attackers take advantage of this. Quick operation on your mobile phone: The mobile application interface has a small amount of information, and when you are eager to complete a transfer, it is easy to ignore a label or a tiny "zero value" mark. Trouble with switching between clipboard and apps: Any extra steps increase the likelihood that you will paste the wrong content or copy information from the wrong screen. The poisoner took advantage of this "path of least resistance".
Really effective protective measures
Although there is no panacea, some habits and product features can significantly change the risk landscape. The key is not to use historical records as your true source of information.
Create an address book: Save known payee addresses and use them permanently. This can form muscle memory and is an effective way to defend against address poisoning. Double check names and notes: Use human-readable tags such as "Payroll Overpayment Account" or "Cold Wallet No. 1". If the wallet supports it, require a name match before sending. Verify before sending: Send a small test transaction first, confirm receipt with the payee through other channels, and then make a large transfer. Although it is troublesome, it is still less costly than transferring a wrong account. Don't get addresses from history: Treat the Recent Activities Panel as read-only information. If you need an address, you should get it from a saved contact, a message signed by the recipient, or verified data under your control. Use interface settings: Some wallets and browsers allow you to hide zero-value transactions or fold spam. Please turn on these features. Force the full address to be displayed on the confirmation screen. If the tool supports transaction simulation, run it and check the "recipient" address character by character. Follow current guidelines: An attacker uses dust or zero-value transactions to implant a "look-alike" address that matches your visible characters. The solution is not complicated, just save contacts and check them carefully.
None of the above is financial advice, but basic safety habits to prevent you from losing assets due to interface traps.
A screenshot of a wallet interface shows the poisoned incoming transaction, including an address that "looks like it", demonstrating how the poisoned address appears in the wallet and why users can be deceived into copying it.
Future direction
Wallet interactive design is moving towards address books, verified recipients, richer warnings and better previews. Make the safe path the easiest path. Protocol and blockchain browser role: The browser is expected to flag clusters of known poisoning addresses, allow users to block zero-value spam, and display the recipient name when available. Protocol-level fixes are more complex and cannot simply ban zero-value transactions, but fee mechanisms and memory pool policies can make certain spam patterns unattractive. Education is leverage: Training teams to abandon the habit of "copying from history" is more effective than chasing every new variant of spam. Within the company, encrypted address books should be regarded as vendor master data in financial software to reduce temporary copy-and-paste behaviors and reduce accidents.
Risks and possible places to go wrong
Create false trust in people's names: Human-readable names may be typed incorrectly or deceived by similar-looking domain names or information. clipboard hijacking: Malware can still replace copied addresses. Address books are helpful, but device security is equally important. Invalid label: If the recipient changes wallets and you don't update your contacts, you will still make an error. Multi-sign confusion: Many organizations use multi-sign wallets or signers with similar names, and their purpose may not be clear based on the label alone. Interface bypass: In a hurry, users may disable simulation, skip confirmation pages, or paste addresses directly from chat logs. Attacker adaptation: If a wallet hides zero-value spam, an attacker may escalate to sending small non-zero transactions to bypass the filter. Address poisoning uses shortcuts. Any control that relies on a user's perfect attention sometimes fails.
FAQs
Are address poisoning and dust attacks the same thing?
They are related but have different intentions. The historical goal of dust attacks has been to track or tag wallet addresses by sending extremely small amounts of tokens. Address poisoning, on the other hand, uses very small or zero-value transactions as a carrier to implant an address that "looks like" in your history and induce you to copy it later.
How to identify poisoned entries in history?
Red flags include: zero-value transactions from a known recipient's address that "almost" matches; unexpected token spam; or clusters of extremely small transactions around the time you last paid someone. Be sure to cross-check the full address using saved contact information before sending.
What if I have sent funds to the poisoned address?
On-chain transactions are irreversible. Please notify exchanges or service providers that may prevent further transfer of funds as soon as possible, but the possibility of recovery is low. The best practice is to record the incident, rotate all operating addresses if necessary, and strengthen your operating procedures to prevent recurrence.
Can ENS name or address tags completely solve this problem?
They are very helpful, but they do not completely eliminate the risk. The name may have been entered incorrectly, and some interfaces are not clearly displayed on the confirmation screen. It is recommended to use a combination of names, saved contacts, and verify them through small test transactions before transferring large amounts.
Which wallets provide features to reduce the risk of poisoning?
Some wallets support contact lists or address books. If your wallet lacks this feature, consider replacing it or using external address book workflows.
Why does the Internet not directly ban zero-value spam transactions?
Zero-value transactions may have legitimate uses, and forced bans may cause new problems. So, researchers analyze patterns, and tools add filters or tags. Research has shown that address poisoning dominates transactions on Ethereum that have remained unchanged and not rolled back, which is driving better interactive defense measures.
Disclaimer: This article is for reference only and does not constitute legal, tax, investment, financial or other advice.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following