Download Trust Wallet
Home  >  Glossary  >  Address Poisoning

Address Poisoning

Share post
In Brief

Address poisoning is a scam where attackers send tiny transactions from an address that looks almost identical to one you use, hoping you'll later copy the fake address from your transaction history and send funds to it.

Address Poisoning

What Is Address Poisoning?

Address poisoning is a scam that exploits a common habit: copying wallet addresses from your transaction history. The attacker generates a vanity address whose first and last characters match an address you regularly interact with, then "poisons" your history by sending you a tiny (or zero-value) transaction from it. Later, when you copy what looks like the familiar address, you may paste the attacker's look-alike instead — and send your funds to them.

Because crypto transactions are irreversible, there is no undo once funds arrive at the attacker's address.

How an Address Poisoning Attack Works

  1. You send funds to an address you use often (an exchange deposit, a friend, your other wallet).

  2. The attacker spots the transaction on-chain and generates a look-alike address matching its first and last 4–6 characters.

  3. They send you a dust transaction (a tiny amount, sometimes zero-value tokens) so the look-alike appears in your history.

  4. Next time you pay that recipient, you copy the address from history — and pick the poisoned entry by mistake.

How to Protect Yourself

Address Poisoning and Trust Wallet

Trust Wallet's Security Scanner flags risky transactions before you sign, and the in-app address book lets you save verified recipients so you never need to copy addresses from history. You control your keys — and with a few habits, the scammers get nothing.

Simple and convenient
to use, seamless to explore

Download Trust Wallet