Detecting Address Poisoning Tactics and Deceptive Transfer Histories Onchain
Deceptive actors frequently generate spoofed wallet addresses to mimic legitimate counterparties and manipulate transaction records. Checking every character of a recipient address before signing prevents misdirected transfers to fraudulent destinations.
- Fraudsters use automated scripts to send negligible or zero-value transactions from vanity addresses designed to share the initial and trailing characters of your frequent transfer destinations.
- Copying recipient addresses directly from recent transaction history exposes users to deceptive addresses placed deliberately within account activity logs to intercept routine digital asset transfers.
- Wallet users should maintain a pre-verified address book within their application or verify the entire alphanumeric sequence against an independent record before broadcasting any transaction.
- If assets are mistakenly sent to a spoofed address, compile the complete transaction hash and notify Action Fraud alongside the compliance team of the destination exchange service.
Written by the Wallsec investigations team. General information only, not legal or financial advice.
Need a case reviewed?
Tell us what happened and we will say honestly whether the onchain data supports a trace.