Terenval Answers · P1 safety · Русская версия
What Is Address Poisoning and How Can It Trick Crypto Wallet Users?
Address poisoning exploits the habit of copying destinations from transaction history. An attacker creates a lookalike address, places it in your history and waits for you to reuse the wrong one.
Last reviewed: 2026-10-05.
Published by Terenval
Technical review: Terenval Wallet team
Editorial policy
Key takeaways
- The scam does not need to compromise your private key.
- A lookalike address can be engineered to share visible prefix/suffix characters.
- The poisoned transaction itself may be harmless; the loss happens when you later copy the wrong destination.
- Recent transaction history is not an address book.
- A small test transfer helps only if you verify the destination independently.
How the attack works
After observing a public transaction, an attacker generates a vanity address visually similar to the real recipient. Because wallet UIs often shorten addresses to something like 0x1234…ABCD, matching the visible edges can make the attacker address look familiar.
The attacker then sends a tiny/zero-value transaction involving the lookalike address so it appears in your activity. Later, if you copy that address from history instead of obtaining the recipient address from a trusted source, the transfer goes to the attacker.
Why checking only the first and last characters can fail
Shortened address displays are useful for readability but create a recognition shortcut. A targeted vanity address can deliberately match those visible characters while differing in the middle.
For meaningful transfers, expand the address when possible and compare more of it. If the recipient is an exchange, use the current deposit address displayed by the exchange rather than an old transaction. For a personal contact or your own second wallet, use a verified address book/QR workflow.
Safe recipient-verification workflow
- Obtain the address directly from the intended recipient or current receive screen.
- Confirm the network separately.
- Paste the address and compare it against the trusted source.
- Do not choose a destination solely because it appears in recent history.
- For a large transfer, send a small test and verify receipt.
- Re-check the final destination before the larger transfer.
If a wallet warns that an address closely resembles a previous address but differs in the middle, stop and verify instead of dismissing the warning.
Address poisoning vs clipboard hijacking
Address poisoning manipulates your transaction history and your recognition habits. Clipboard hijacking uses malware on the device to replace the address you copied. Both can end with a payment to the attacker, but the attack surfaces differ.
The shared defense is independent destination verification before signing.
Common mistakes
- Copying the most recent address from history.
- Verifying only four characters at each end for a high-value transfer.
- Assuming an incoming tiny transaction identifies a legitimate contact.
- Believing the wallet can infer your intended human recipient with certainty.
- Reusing an exchange deposit address without checking whether it is still current and supported.
How this works in Terenval Wallet
When sending from Terenval Wallet, treat the transaction review screen as the final checkpoint: verify the selected network, recipient and amount against a trusted source. Network safeguards can detect some chain mismatches, but no wallet can reliably know whether a lookalike address is the human recipient you intended.
Do not source a destination from suspicious recent activity. Use the recipient's current receive address and a test transfer for large or unfamiliar routes.
Official pages: Supported networks · Security
Open Terenval WalletFrequently asked questions
Can address poisoning steal my seed phrase?
The basic attack does not need your seed phrase. It tries to make you authorize a valid transfer to the wrong address.
Is a zero-value incoming transaction dangerous by itself?
Usually the danger is social/operational: it pollutes history. Do not interact with unknown tokens or links attached to suspicious activity.
Can I recover crypto sent to a poisoned address?
Confirmed blockchain transfers are generally irreversible without cooperation from the recipient. Prevention and address verification are therefore critical.
Related Terenval Answers
Primary and authoritative sources
- https://support.metamask.io/stay-safe/protect-yourself/wallet-and-hardware/address-poisoning-scams/
- https://support.metamask.io/stay-safe/protect-yourself/wallet-and-hardware/
- https://ethereum.org/developers/docs/accounts
Terenval-specific statements are first-party; general technical claims are checked against primary or authoritative sources.