Address poisoning is one of the most effective scams on transparent chains. Attackers inject look-alike addresses into your wallet history so you copy-paste the wrong one. Here is exactly how it works on Bitcoin, EVM chains, and Tron — and why Monero is structurally immune.
Address poisoning (also called 'address spoofing' or 'dust poisoning') is a scam where an attacker sends a tiny or zero-value transaction to your wallet from an address that visually matches one you have recently used. When you later copy an address from your transaction history, you grab the attacker's address by mistake — and send your funds to them. Losses crossed nine figures in 2024 and continued through 2026.
Attackers grind vanity addresses that match the first 4-6 and last 4-6 characters of your real counterparties. Most wallet UIs only show those characters, so the spoofed entry is visually identical.
The poisoned transaction is often 0 BTC, 0 ETH, or a few sats/wei. On EVM chains, attackers even use fake ERC-20 'transferFrom' calls so your wallet displays an outgoing transfer that you never authorized.
The exploit targets your habits, not the protocol. If you copy addresses from past transactions instead of from a trusted source, the poisoned entry sits there waiting.
Bots scan the mempool for large transfers, then immediately poison both sides of the trade. Losses of $68M, $1.4M, and $1.8M in single transactions have been publicly documented since 2024.
Originally a Bitcoin and Ethereum problem, the attack now spans Tron (USDT), BNB Chain, Polygon, Base, and Arbitrum. Tron USDT poisoning is especially common because of low fees.
Address poisoning only works on chains where the sender, receiver, and historical addresses are publicly visible and reusable. Monero's stealth-address design removes the attack surface entirely.
| Attack Vector | Bitcoin / EVM / Tron | Monero (XMR) | Exposure |
|---|---|---|---|
| Public addresses in history | Yes | Stealth (one-time only) | Immune |
| Vanity look-alike spoofing | Effective | Impossible | Immune |
| Zero-value dust injection | Yes | Not applicable | Immune |
| Fake transferFrom spoofing | EVM / Tron | Not applicable | Immune |
| Need to copy from history | Common | Never (subaddresses) | Immune |
Bots watch every confirmed transaction in real time. When a large or recurring transfer is detected, both the sender and receiver addresses get queued for poisoning.
GPU clusters generate Bitcoin or EVM addresses that match the first and last characters of the target. A 6+6 character match takes minutes; a 4+4 match takes seconds.
The attacker sends 0 sats (or a fake ERC-20 transferFrom on EVM) from the spoofed address to your wallet. Your wallet UI now shows a transaction that looks like it came from your real counterparty.
Days or weeks later, when you go to send funds, you scroll your history, copy the most recent address — and grab the attacker's spoofed one. The first and last characters look correct.
Bitcoin transactions are irreversible. EVM transactions are mined in seconds. By the time you notice the mismatch in the middle characters, the attacker has already moved the funds through a mixer or off-ramp.
Until you move to a stealth-address chain like Monero, defensive habits are the only protection. Wallet UI improvements help but every major wallet still ships the vulnerable history view.
Always copy from the original source — an address book, the recipient's signed message, or a freshly requested invoice. Treat your wallet history as untrusted input.
Check the middle 8-12 characters, or compare the full string. Vanity grinders match the visible ends; the middle will always differ.
Most modern wallets (Sparrow, Electrum, Rabby, Frame) let you save trusted addresses with labels. Send only from the contacts list, never from history.
For any transfer above a few hundred dollars, send a dust test, confirm receipt with the counterparty out-of-band, then send the rest.
Monero issues a one-time stealth address per transaction. There is no reusable address to spoof, no history view to poison, and no clustering attack surface.
Every incoming XMR transaction lands at a freshly derived address that only you and the sender can compute. There is no public, reusable destination for attackers to spoof.
The protocol enforces uniqueness — your wallet history shows incoming notes, not 'from address' fields you would ever paste back. The poisoning UX simply does not exist.
Even if an attacker tried to inject a fake transaction, ring signatures and RingCT hide who sent what and how much, so no convincing spoof of past activity is possible.
A scam where an attacker sends a small or zero-value transaction from a vanity address that visually matches one of your real counterparties. The fake transaction appears in your wallet history, and when you later copy-paste an address from history, you copy the attacker's instead of the real one.
Yes. Any chain with public, reusable addresses is vulnerable. Bitcoin, Ethereum, Tron (especially USDT-TRC20), BNB Chain, Polygon, Base, and Arbitrum have all seen large-scale poisoning campaigns since 2022.
Public losses include $68M in a single Bitcoin transaction in 2024, multiple seven-figure EVM losses, and millions in recurring Tron USDT thefts. Total losses crossed nine figures by 2025 and continued through 2026.
Generating a fully matching address would require breaking the underlying cryptography. Attackers grind vanity prefixes and suffixes (typically 4-6 characters each) because that is all most wallet UIs display in the truncated form (e.g. 'bc1qxy...j3kf').
Partially. A hardware wallet will show the full destination address on its screen — if you verify every character. Most users do not, and the device cannot tell that the address came from a poisoned history entry rather than your real counterparty.
No. Bitcoin and most EVM-chain transfers are final once confirmed. The only recourse is to contact the receiving exchange (if the attacker cashes out via a KYC venue) and hope for a freeze, which rarely succeeds.
Monero uses one-time stealth addresses derived from the recipient's public viewkey. Each incoming transaction creates a unique on-chain output address that you never reuse and never copy-paste from history. There is no reusable address surface for attackers to spoof.
Why Bitcoin's address-level transparency creates tainted coins, freezes, and attack surfaces that Monero's fungibility eliminates.
→ ReadBitcoin's full transparency model — addresses, clusters, and how it enables both surveillance and scams like address poisoning.
→ ReadCold-storage best practices for Monero — verifying addresses, using subaddresses, and avoiding the wallet hygiene pitfalls that BTC users face.
→ ReadNo public addresses. No poisoned history. No copy-paste attack surface. Non-custodial, no KYC, no logs.
Swap Crypto Privately →