Address poisoning is a scam in which an attacker places an address that resembles your recipient's address into your wallet history.
The attacker hopes that you will later copy the familiar-looking string and send funds to the wrong destination.
The incoming transfer itself does not usually give the attacker access to your wallet. The loss occurs if the wallet owner uses the fake address as the destination of a new transaction.
How address poisoning works
Transfer history on a public blockchain can be observed. An attacker finds an address you use and creates another address with some of the same characters at the beginning or end.
The attacker then sends a zero-value or negligible transfer from the lookalike address. The entry appears in your history and starts to look familiar.
During a later transfer, you may copy that address from recent activity. If the wallet shortens long addresses, a difference in the middle can be easy to miss.
MetaMask describes this sequence and recommends checking the middle characters, not only the beginning and end.
Address poisoning does not break wallet cryptography. It exploits the habit of copying from history and treating a repeated entry as trusted.
Address poisoning and spam assets are different threats
An address-poisoning attacker wants a lookalike address to appear in your history. An unexpected token or NFT may be part of a different scam that sends you to a phishing site or asks you to approve a dangerous request.
Receiving an unknown asset does not usually expose wallet secrets by itself. The risk increases when you follow a link, try to redeem or exchange the asset, or approve a request.
Do not follow links in the name or description of an unknown token, and do not interact with it.
MetaMask recommends ignoring unexpected NFTs and their instructions.
How to verify an address before sending
Transaction history proves that an operation occurred. It does not prove that the displayed address belongs to the intended person or service.
Before a transfer:
- Get the address from a trusted source, not from wallet history.
- Compare the entire string, including the middle characters.
- Check the address again after pasting because malware can replace clipboard contents.
- Save a frequent recipient only after completing the first full verification.
- If a hardware wallet shows the destination, compare it with the source address on the device screen.
An address book reduces repeated copying, but it cannot correct an address that was saved incorrectly. A contact name is not a substitute for checking the address itself.
When a test transfer helps
A small test transfer is an additional check, not a way to establish the recipient's identity. Confirm the address through a trusted source first and consider the network fee.
After the test, ask the recipient to confirm receipt through an independent channel. Use the address you already verified for the main transfer instead of copying it again from the test transaction history.
Coinbase also recommends a test transfer, while warning that confirmed blockchain transfers cannot normally be reversed.
What to do after sending to the wrong address
Do not send another transaction to the same address.
Save the destination address, transaction hash, network, asset, amount, and time. You may need these details when contacting a wallet provider, exchange, recipient service, or fraud-reporting channel.
If the address belongs to a known service, contact it only through its official support channel. If the owner is unknown, recovering a confirmed transfer is usually impossible.
How this relates to ElyxS
Start ElyxS actions from the official interface and review the request before confirming it in your connected wallet. Do not replace a destination with an address from history merely because it looks familiar.
ElyxS links to SupraScan open the record of an existing transaction. You can use that record to inspect the network, address, hash, and status, but it does not authenticate the owner of an address for a future transfer.
See How to Read SupraScan for ElyxS for explorer records and Set Up StarKey Wallet for basic wallet safety.
Sources and further reading
- MetaMask: Address poisoning scams — the attack mechanism and destination-address checks.
- MetaMask: Clipboard hacking — checking an address after copying and pasting it.
- MetaMask: NFT airdrop scams — the risks of links and actions attached to unsolicited assets.
- Coinbase: Crypto sent to the wrong address — the finality of confirmed transfers.
- Coinbase: Address Book and whitelisting — reusing previously verified addresses.