Gold 24K AED 478.82/gUSD/AED 3.6725USDT/AED 3.6698AED/INR 26.31All live rates →

Address Poisoning Explained: The Copy-Paste Crypto Scam

Address poisoning is one of the sneakiest crypto scams because it weaponizes a habit almost everyone has: copying a wallet address instead of typing it. One careless paste can send your funds straight to an attacker. Here is exactly how it works and how to never fall for it.

Table of contents

What is address poisoning?

Crypto addresses are long, alphanumeric strings no one reads in full. Address poisoning exploits that. An attacker gets a lookalike address — one whose first and last few characters match an address you have used — into your transaction history, betting that next time you will copy the wrong one from your own history.

How the scam works

The attacker monitors blockchain activity and identifies addresses you transact with. They generate a vanity address that mimics the start and end of a familiar one, then send you a tiny (often zero-value) transaction so it appears in your history. Later, when you copy an address from your history to repeat a payment, you may grab the poisoned lookalike instead of the real one — and send your funds to the scammer.

How to protect yourself

Never copy addresses from transaction history. Use a saved, verified address book or the recipient’s freshly provided address. Verify the full string, not just the first and last four characters — that shortcut is exactly what the scam defeats. Send a small test transaction first for large transfers. Use wallets with address-book and warning features, and treat any unexpected tiny incoming transaction as a red flag, not free money.

Frequently asked questions

What is address poisoning?
A scam where an attacker plants a lookalike address in your history so you copy it by mistake and send funds to them.

How do I avoid it?
Never copy addresses from history; verify the full address; use a saved address book; send a test transaction for large amounts.

Why did I get a tiny unknown deposit?
It may be a poisoning attempt to get a lookalike address into your history. Do not reuse it.

Is checking the first and last characters enough?
No. Attackers match exactly those characters. Verify the entire address.


Sources: Cryptonite security reporting. Educational overview, updated for 2026. See also our fake USDT scams guide.

Disclaimer: General information, not financial advice.

📧 The Gulf reads Cryptonite first
Get MENA regulation moves, RWA deals and AI-money trends in one weekly brief — plus instant alerts when the MENA Regulation Tracker changes. Free, no spam.
Was this briefing useful?Thanks for the feedback!
Vaibhavv Ali
Vaibhavv Ali

Vaibhav Ali is the founder and editor of Cryptonite (cryptonite.ae), an independent digital-asset news and analysis publication with a UAE focus. He covers virtual-asset regulation — VARA, ADGM and the UAE Central Bank — alongside real-world-asset tokenization, stablecoins and agentic AI in finance. Every Cryptonite article is human-edited and its sources are linked.

More articles by Vaibhavv Ali →

Leave a Comment

About  ·  Contact  ·  Privacy Policy  ·  Editorial Policy  ·  Advertise  ·  Newsletter
Follow: X  ·  LinkedIn  ·  Instagram  ·  Binance Square  ·  CoinMarketCap  ·  Gate