Recognising Address Poisoning Tactics and Counteracting Transaction History Manipulation
Fraudsters frequently broadcast negligible transfers from custom addresses resembling familiar contacts to trick users into copying false recipient details. Verifying complete destination characters prevents capital misdirection.
- Always verify every character of a recipient address rather than relying on the first and last few alphanumeric digits, as attackers generate vanity strings designed to mimic genuine counterparties.
- Avoid copying transfer destinations directly from recent inbound transaction feeds or public ledgers, as malicious actors intentionally populate account histories with nominal transfers to facilitate human error.
- Maintain a verified address book within your software or hardware interface for recurring transfers to ensure outbound transactions route exclusively to authenticated destinations.
- Notify Action Fraud and the receiving platform promptly if assets are directed to an illicit address, supplying exact transaction hashes to assist onchain tracking efforts.
Written by the Wallsec investigations team. General information only, not legal or financial advice.
Need a case reviewed?
Tell us what happened and we will say honestly whether the onchain data supports a trace.