Address Poisoning: $2M Lost Over 7 of 40 Characters
On August 21, 2026, a wallet belonging to Bofur Capital lost $2 million in USDC due to an attack known as address poisoning. This technique involves an attacker planting a fake but similar-looking address into the wallet's transaction history.
The attacker needs no access to the wallet, only an entry in its history, which is often used as a convenient source for receiving addresses. There are two common ways to achieve this: dust transfers and fake transfer events.
In this case, both techniques were used side by side. The attacker sent tiny amounts of USDC from their fake address, creating entries in the wallet's history. They also published token contracts that reported fake transfers, making it difficult for users to distinguish between real and fake transactions.
The key to the attack was how little similarity this required: only seven out of forty characters needed to match, including four at the front and three at the back. The remaining thirty-three characters were completely different but not visible in the shortened display used by most wallets and block explorers.