Independent explainers · No ads · No affiliate links

Money, fintech & crypto, explained from primary sources

RiskCrypto-assets are high-risk and can lose all their value. We explain; we do not advise. Read the risk disclosure.
Security & Privacy · Intermediate

Phishing and address poisoning in crypto

Phishing fakes the website. Address poisoning fakes your own transaction history. Both count on you checking only the first and last few characters.

A blue fishing lure shaped like a fish, resting on a rock
Photo: “Bluefox Vibrotail jig fishing lure 29 gr” by R. Henrik Nilsson, CC BY 4.0, via commons.wikimedia.org. Converted to black and white.
On this page
  1. What is crypto phishing?
  2. How does address poisoning work?
  3. Why does checking the first and last characters fail?
  4. How do phishing, address poisoning and fake airdrops differ?
  5. How can you protect yourself from address poisoning?
  6. What mistakes make address poisoning succeed?
  7. Questions readers ask
  8. Sources
The short version
  • Crypto phishing imitates a trusted site, app or person to get your seed phrase, your password or a wallet signature.
  • Address poisoning plants a lookalike address in your transaction history, hoping you copy it next time you send funds.
  • The trick works because wallets often shorten 40-character addresses to the first and last few characters.
  • Ethereum transactions are irreversible, so the only real defence is checking the full address before you send.
  • Use a saved address book instead of copying from your history, and ignore tokens you did not expect.

Address poisoning is a crypto scam in which an attacker creates an address that starts and ends like one you use, then sends you a zero-value or tiny transfer so it appears in your history. Copy it by mistake later and your funds go to the attacker, irreversibly.

What is crypto phishing?

Phishing is any attempt to get you to hand over something valuable by pretending to be someone you trust. In crypto, the valuable thing is usually one of three: your seed phrase, the password and code for an exchange account, or a wallet signature that grants spending rights.

CISA's warning signs apply directly: urgent or emotional language, requests for personal or financial information, shortened links and web addresses that are one letter off, like CISA's example "amazan.com". Ethereum.org adds crypto-specific versions: clone sites with identical layouts, fake airdrops that link to scam pages, and spoofed link previews in social media ads. Its advice is to check that you are on the right domain, especially after clicking a link.

The scale is large. The FBI's IC3 logged 191,561 phishing and spoofing complaints in 2025 across all sectors, not only crypto.

How does address poisoning work?

An Ethereum address is 40 hexadecimal characters after the 0x prefix, derived from a public key, according to ethereum.org. Nobody memorizes that, so people copy addresses from their own transaction history. Address poisoning exploits that habit.

Researchers at Carnegie Mellon, in a peer-reviewed USENIX Security 2025 paper, describe the attack in three steps. The attacker watches who you transact with, generates a new address whose first and last characters match that counterparty's, and then sends you a transaction from it so it appears in your history. The paper identifies three kinds of poisoning transfer: zero-value transfers, tiny transfers and fake token transfers.

Two features of the ERC-20 token standard make this possible. It states that transfers of 0 values must be treated as normal transfers and must emit a transfer event, so a worthless transaction still shows up in explorers and wallets. And, as ethereum.org notes, anyone can deploy a token contract with the same name and symbol as a real one, and the contract itself writes the transfer events, so a fake token can produce convincing-looking entries.

A box of metal fishing spoons and hooks
Photo: “ABU Fishing Lures” by Podknox, CC BY 2.0, via flickr.com. Converted to black and white.

Why does checking the first and last characters fail?

Each hexadecimal character has 16 possible values. If you only check the first four and last four characters after 0x, the attacker needs an address matching just 8 characters.

This is why ethereum.org's instruction is to make sure the address you are sending to exactly matches the recipient's, not that it looks similar. Once sent, an Ethereum transaction is irreversible: unless you know the owner and they agree to return the funds, they are gone.

How do phishing, address poisoning and fake airdrops differ?

Phishing site or messageAddress poisoningFake token airdrop
What you seeA familiar brand, a login page or a support agentA familiar-looking address in your own historyUnknown tokens that appear in your wallet
What it wantsSeed phrase, password, 2FA code or a signatureYour next transferA visit to a site that asks you to sign
When it hitsImmediately, if you complyDays or weeks later, when you copy the addressWhen you try to sell or claim the token
Main defenceGo to sites directly; never share secretsAddress book and full-address checksIgnore it; do not interact

How can you protect yourself from address poisoning?

  1. Save trusted addresses. Use your wallet's address book or allowlist feature, if it has one, for people and services you pay regularly. The CMU researchers recommend allowlisting trusted addresses.

  2. Never copy from your history. Get the address from the source each time: the recipient, your saved contact or the exchange's deposit page.

  3. Check every character, or at least far more than the ends. Read it in chunks and compare against a copy you trust.

  4. Treat unexpected transfers as warnings. A zero-value or tiny incoming transaction from a near-copy of a known address is a sign someone is targeting you.

  5. Ignore unknown tokens. Ethereum.org warns that scam airdrops lead to sites that ask for signatures; see token approvals and wallet drainers.

For exchange accounts, add phishing-resistant login protection with two-factor authentication.

A small fishing lure with a sharp treble hook
Photo: “Horisontally balanced ice fishing lure made in Finland 5 gr body 4 1 5 cm” by R. Henrik Nilsson, CC BY 4.0, via commons.wikimedia.org. Converted to black and white.

What mistakes make address poisoning succeed?

  • Trusting your own history. Anyone can place an entry in it. A row in your transaction list says nothing about who controls that address.
  • Checking only the ends. The attack is designed around exactly that shortcut.
  • Assuming a hardware wallet will catch it. The device signs what you ask. If you paste the wrong address, it signs the wrong address; see hardware vs software wallets.
  • Hurrying. CISA lists urgent, pressured language as a classic phishing marker. A transfer that "must" go out in the next few minutes deserves the slowest check of all.
  • Searching for a recovery service. Ethereum.org says no one can reverse blockchain transactions; paid recovery offers are a second scam.

Questions readers ask

Has my wallet been hacked if I see a strange zero-value transfer?

Not necessarily. A zero-value or fake-token transfer can appear without access to your keys. Treat it as a warning, avoid that address, and use your saved contacts for future transfers.

Does address poisoning only affect Ethereum?

The CMU study measured it on Ethereum and BNB Smart Chain, and the same copy-from-history habit exists on other networks. Check the full address on any network.

Should I send the scam token back or try to sell it?

No. Interacting with unknown tokens can lead you to sites that ask for signatures. Leave them alone and never visit links attached to them.

Can I get funds back after sending to a poisoned address?

Only if the recipient chooses to return them, which in a scam will not happen. Report it to ic3.gov and your exchange, and ignore paid recovery offers.

Bottom line

Phishing and address poisoning both exploit shortcuts: trusting a familiar look instead of a verified source. Go to websites directly, keep a saved address book, never copy from your history, and check addresses in full before every send. Those habits cost seconds; a mistake on-chain is permanent.

Sources

  1. Tsuchiya, Dong, Soska and Christin, Carnegie Mellon University, Blockchain Address Poisoning (USENIX Security Symposium 2025) (2025)
  2. Ethereum Improvement Proposals, ERC-20 Token Standard (EIP-20) (2015)Primary source
  3. ethereum.org, Ethereum accounts (2026)Primary source
  4. ethereum.org, How to identify scam tokens (2026)Primary source
  5. ethereum.org, Ethereum security and scam prevention (2026)Primary source
  6. ethereum.org, Scam help & reporting (2026)Primary source
  7. Cybersecurity and Infrastructure Security Agency, Recognize and Report PhishingPrimary source
  8. FBI Internet Crime Complaint Center, 2025 IC3 Annual Report (Internet Crime Report) (2026)Primary source

Educational content only — not financial, investment, legal or tax advice. Crypto-assets are high-risk and you could lose all the money you put in. Rules differ by country; check with your national regulator. See our risk disclosure and editorial policy.