Address Poisoning: The Silent Threat to Crypto Transactions
Crypto address poisoning is a social-infrastructure attack that uses the way users handle addresses against them. It works by exploiting user habits, particularly the tendency to copy and paste addresses from history or recent activity.
Attackers create vanity addresses that share the same starting and ending characters as a real counterparty, then inject these lookalike addresses into a victim's history with a dust or zero-value transaction. Weeks later, when the user needs to pay the vendor again, they copy the poisoned entry, sending funds to the attacker's address.
The attack is made possible by user shortcuts and UI habits. Wallets show past recipients in a list, explorers abbreviate addresses, and most users rely on copying rather than saving contacts. Attackers know this and design their vanity addresses to exploit these weaknesses.