Address Poisoning: The Quiet Threat to Crypto Wallet Security
Address poisoning is a type of social-infrastructure attack that exploits how people handle addresses in their wallets. Attackers create vanity addresses that match the visible edges of legitimate recipient addresses, then inject these lookalikes into the victim's history with tiny or zero-value transactions.
This allows them to trick users into copying the poisoned address when sending funds again, effectively stealing tokens without compromising private keys. The attack relies on routine user behavior, such as relying on wallet histories and trusting edge matches, rather than exploiting cryptography weaknesses.
A recent study found that nearly 53% of non-reverted state-invariant transactions on Ethereum are linked to poisoning campaigns, with large volumes also observed on L2s like Optimism and Base. The low cost of planting dozens of decoys makes the attack profitable at scale.