Address Poisoning
Address poisoning is a scam that plants lookalike addresses in your transaction history, hoping you will copy one of them the next time you send funds. The attacker generates a vanity address whose first and last characters match an address you genuinely use, then sends your wallet a tiny or zero-value transfer so the fake address appears in your history alongside real ones.
The scam exploits a common habit: because crypto addresses are long strings, many people verify only the first and last few characters, and reuse addresses by copying them from a previous transaction in their wallet or block explorer history. For example, a user who regularly sends USDT to an exchange deposit address starting with 0x9a3 and ending in f41 might see a poisoned entry with those same visible characters, copy it, and send a large transfer straight to the attacker. Blockchain transactions are irreversible, so the funds are gone the moment it confirms.
Losses from this technique have been substantial precisely because it requires no hacking and no signature tricks, only inattention. Defenses are simple: never copy addresses from transaction history, use an address book or saved contacts for recurring recipients, verify more than the ends of an address before sending, and send a small test amount first for large transfers. A common misconception is that receiving the poisoned dust transfer is itself dangerous; it is harmless until you copy the wrong address.