Phishing and address poisoning in crypto
Phishing fakes the website. Address poisoning fakes your own transaction history. Both count on you checking only the first and last few characters.

On this page
- Crypto phishing imitates a trusted site, app or person to get your seed phrase, your password or a wallet signature.
- Address poisoning plants a lookalike address in your transaction history, hoping you copy it next time you send funds.
- The trick works because wallets often shorten 40-character addresses to the first and last few characters.
- Ethereum transactions are irreversible, so the only real defence is checking the full address before you send.
- Use a saved address book instead of copying from your history, and ignore tokens you did not expect.
Address poisoning is a crypto scam in which an attacker creates an address that starts and ends like one you use, then sends you a zero-value or tiny transfer so it appears in your history. Copy it by mistake later and your funds go to the attacker, irreversibly.
What is crypto phishing?
Phishing is any attempt to get you to hand over something valuable by pretending to be someone you trust. In crypto, the valuable thing is usually one of three: your seed phrase, the password and code for an exchange account, or a wallet signature that grants spending rights.
CISA's warning signs apply directly: urgent or emotional language, requests for personal or financial information, shortened links and web addresses that are one letter off, like CISA's example "amazan.com". Ethereum.org adds crypto-specific versions: clone sites with identical layouts, fake airdrops that link to scam pages, and spoofed link previews in social media ads. Its advice is to check that you are on the right domain, especially after clicking a link.
The scale is large. The FBI's IC3 logged 191,561 phishing and spoofing complaints in 2025 across all sectors, not only crypto.
How does address poisoning work?
An Ethereum address is 40 hexadecimal characters after the 0x prefix, derived from a public key, according to ethereum.org. Nobody memorizes that, so people copy addresses from their own transaction history. Address poisoning exploits that habit.
Researchers at Carnegie Mellon, in a peer-reviewed USENIX Security 2025 paper, describe the attack in three steps. The attacker watches who you transact with, generates a new address whose first and last characters match that counterparty's, and then sends you a transaction from it so it appears in your history. The paper identifies three kinds of poisoning transfer: zero-value transfers, tiny transfers and fake token transfers.
Two features of the ERC-20 token standard make this possible. It states that transfers of 0 values must be treated as normal transfers and must emit a transfer event, so a worthless transaction still shows up in explorers and wallets. And, as ethereum.org notes, anyone can deploy a token contract with the same name and symbol as a real one, and the contract itself writes the transfer events, so a fake token can produce convincing-looking entries.

Why does checking the first and last characters fail?
Each hexadecimal character has 16 possible values. If you only check the first four and last four characters after 0x, the attacker needs an address matching just 8 characters.
This is why ethereum.org's instruction is to make sure the address you are sending to exactly matches the recipient's, not that it looks similar. Once sent, an Ethereum transaction is irreversible: unless you know the owner and they agree to return the funds, they are gone.
How do phishing, address poisoning and fake airdrops differ?
| Phishing site or message | Address poisoning | Fake token airdrop | |
|---|---|---|---|
| What you see | A familiar brand, a login page or a support agent | A familiar-looking address in your own history | Unknown tokens that appear in your wallet |
| What it wants | Seed phrase, password, 2FA code or a signature | Your next transfer | A visit to a site that asks you to sign |
| When it hits | Immediately, if you comply | Days or weeks later, when you copy the address | When you try to sell or claim the token |
| Main defence | Go to sites directly; never share secrets | Address book and full-address checks | Ignore it; do not interact |
How can you protect yourself from address poisoning?
Save trusted addresses. Use your wallet's address book or allowlist feature, if it has one, for people and services you pay regularly. The CMU researchers recommend allowlisting trusted addresses.
Never copy from your history. Get the address from the source each time: the recipient, your saved contact or the exchange's deposit page.
Check every character, or at least far more than the ends. Read it in chunks and compare against a copy you trust.
Treat unexpected transfers as warnings. A zero-value or tiny incoming transaction from a near-copy of a known address is a sign someone is targeting you.
Ignore unknown tokens. Ethereum.org warns that scam airdrops lead to sites that ask for signatures; see token approvals and wallet drainers.
For exchange accounts, add phishing-resistant login protection with two-factor authentication.

What mistakes make address poisoning succeed?
- Trusting your own history. Anyone can place an entry in it. A row in your transaction list says nothing about who controls that address.
- Checking only the ends. The attack is designed around exactly that shortcut.
- Assuming a hardware wallet will catch it. The device signs what you ask. If you paste the wrong address, it signs the wrong address; see hardware vs software wallets.
- Hurrying. CISA lists urgent, pressured language as a classic phishing marker. A transfer that "must" go out in the next few minutes deserves the slowest check of all.
- Searching for a recovery service. Ethereum.org says no one can reverse blockchain transactions; paid recovery offers are a second scam.
Questions readers ask
Has my wallet been hacked if I see a strange zero-value transfer?
Not necessarily. A zero-value or fake-token transfer can appear without access to your keys. Treat it as a warning, avoid that address, and use your saved contacts for future transfers.
Does address poisoning only affect Ethereum?
The CMU study measured it on Ethereum and BNB Smart Chain, and the same copy-from-history habit exists on other networks. Check the full address on any network.
Should I send the scam token back or try to sell it?
No. Interacting with unknown tokens can lead you to sites that ask for signatures. Leave them alone and never visit links attached to them.
Can I get funds back after sending to a poisoned address?
Only if the recipient chooses to return them, which in a scam will not happen. Report it to ic3.gov and your exchange, and ignore paid recovery offers.
Phishing and address poisoning both exploit shortcuts: trusting a familiar look instead of a verified source. Go to websites directly, keep a saved address book, never copy from your history, and check addresses in full before every send. Those habits cost seconds; a mistake on-chain is permanent.
Sources
- Tsuchiya, Dong, Soska and Christin, Carnegie Mellon University, Blockchain Address Poisoning (USENIX Security Symposium 2025) (2025)
- Ethereum Improvement Proposals, ERC-20 Token Standard (EIP-20) (2015)Primary source
- ethereum.org, Ethereum accounts (2026)Primary source
- ethereum.org, How to identify scam tokens (2026)Primary source
- ethereum.org, Ethereum security and scam prevention (2026)Primary source
- ethereum.org, Scam help & reporting (2026)Primary source
- Cybersecurity and Infrastructure Security Agency, Recognize and Report PhishingPrimary source
- FBI Internet Crime Complaint Center, 2025 IC3 Annual Report (Internet Crime Report) (2026)Primary source
Educational content only — not financial, investment, legal or tax advice. Crypto-assets are high-risk and you could lose all the money you put in. Rules differ by country; check with your national regulator. See our risk disclosure and editorial policy.



