Attackers Use Sophisticated Technique to Steal 2 Million USDC
The attack, known as address poisoning, occurred on August 21, 2026, when a wallet transferred 2 million USDC to an address that matched the original in exactly seven of forty characters. The attackers used a technique called dust transfer, where they sent a small amount from their fake address to the victim's account, and then replicated the transaction multiple times.
The attack was not detected until it was too late, and the funds were transferred out of the wallet through a series of complex transactions. The attackers used homoglyphs, characters that look similar to others but are technically different, to make their fake addresses appear legitimate in blockchain explorers.
The technique is particularly effective because most users rely on shortened forms of addresses when copying and pasting, which can lead them to inadvertently send funds to the wrong recipient. The attackers also used a technique called fake transfer events, where they created external token contracts that reported fictional transactions to the victim's wallet.