00:00
Money for You
Money for You
USD/RUB
EUR/RUB
Cryptocurrency

Crypto User Loses $100,000 in Address Poisoning Scam

A crypto user lost 100,000 USDT after falling victim to an address poisoning attack, a sophisticated deception where scammers plant lookalike wallet addresses in a user's transaction history. The incident highlights the persistent danger of relying on partial address strings when executing high-value blockchain transfers.

Crypto User Loses $100,000 in Address Poisoning Scam

The victim unknowingly sent the funds to an attacker-controlled wallet that had been planted in their transaction history 66 days earlier. According to security firm Cyvers, the malicious address was designed to mimic a legitimate recipient, appearing nearly identical when viewed in standard wallet interfaces that truncate character strings. Once the transfer was complete, the attacker promptly converted the USDT into approximately 52.8 ETH, a move likely intended to bypass Tether’s ability to freeze stablecoin assets.

This method of theft does not require compromising private keys or exploiting smart contract vulnerabilities. Instead, attackers use automated scripts to generate addresses that share the same first and last characters as the victim's frequent contacts, then perform low-value or zero-value transactions to populate the target's history. Security experts now warn that transaction logs should never be treated as a trusted address book. To mitigate risk, users are urged to verify the full character string of every destination address and, in the case of significant transfers, confirm recipient details through an out-of-band communication channel before finalizing any payment.

Share

Comments (0)

Leave a comment

No comments yet. Be the first!