Ethereum Users Lose Millions to Sophisticated Address Poisoning Scams
Address poisoning is a scam where attackers send a nearly worthless transaction from an address that looks almost identical to one you've used before. This allows them to trick victims into sending their funds to the attacker's address instead of the intended recipient.
Two recent cases illustrate how costly this mistake can be: in December 2025, an Ethereum user sent $50 million worth of USDT to a poisoned address, while another user lost 4,556 ETH (worth about $12.25 million) making the same error.
The scam works by exploiting human habit: most people glance at the first and last few characters of an address and assume the middle matches, allowing attackers to generate lookalike addresses with GPU-powered tools.
Once a poisoned address is planted in your transaction history, it's easy to mistake for a legitimate one. Attackers then send small 'dust' transfers from these fake addresses, hoping you'll copy them by mistake when sending funds later on.