Identifying Address Poisoning Tactics and Lookalike Destinations in Onchain Transactions
Address poisoning involves attackers sending negligible token transfers from lookalike addresses to mimic regular counterparties in wallet histories. Verifying full destination addresses before transferring funds prevents misdirection to fraudulent accounts.
- Attackers routinely generate custom vanity addresses sharing identical beginning and ending characters with your regular counterparties, hoping you will blindly copy the address from your recent onchain transaction history.
- Avoid copying public recipient addresses directly from past activity logs or explorer lists, opting instead to verify each alphanumeric character manually against a securely stored, pre-confirmed address book.
- If an unrequested token or micro-transfer appears in your digital wallet, avoid interacting with the transaction, associated links, or counterparty address, as these transfers are deployed purely to contaminate your account interface.
- Individuals who misdirect assets to a spoofed address should report the theft promptly to Action Fraud and notify the receiving custodial service alongside relevant transaction hashes to aid tracing.
Written by the Wallsec investigations team. General information only, not legal or financial advice.
Need a case reviewed?
Tell us what happened and we will say honestly whether the onchain data supports a trace.