Address poisoning: How a scammer "slips in" someone else's address and what to do if the transfer has already gone through
A scammer adds a similar address to the history and counts on the user copying it instead of the real one.
Imagine: a scammer adds a similar address to the history and counts on the user copying it instead of the real one. On screen, everything may look familiar, so the dangerous moment is easy to miss.
The main thing to know right away: The main thing is not to panic and not to try to "fix" the situation with random transfers. First, stop the repeat risk, save the original data, and only then sort out what happened.
How the scheme works
The scheme uses public transfer history. The attacker creates an address visually similar to your usual recipient's address and makes a small or zero transaction so that this twin appears in the history. The key moment comes later: the user copies the details from the history and signs a transfer to someone else's address themselves.
In this situation, it is important to separate two things: the attack mechanism itself and what has already happened to the assets. A scammer adds a similar address to the history and counts on the user copying it instead of the real one. After an incident, the technical review begins not with guesses, but with a specific transaction and its continuation on the blockchain.
What to do if this has already happened
Compare the mistaken address with the real recipient in full, not just by the first and last characters. This helps record the substitution itself and avoid confusing it with key compromise.
- Stop repeating the action that led to the incident: do not sign new requests and do not send additional payments.
- Save the tx hash, full addresses, network, asset, amount, and time of the transaction.
- Record the correspondence, domain, profile, app, or signing screen — everything that explains the context of the transaction.
- If there is a risk of wallet compromise, move the remaining assets to a new safe wallet without using the exposed seed phrase.
- If the amount is substantial, it makes sense to trace the further route of the funds and identify service points along the way.
What to save for the review
For this specific topic, it is especially useful to save: the full address that should have been the recipient, and the source from which you usually obtain it.
For an initial review, prepare the data in one message or file — this reduces the risk of losing an important detail:
- tx hash / txid
- full sender and recipient addresses
- network, asset, amount, and time
- screenshots and correspondence
- domain, profile, or app, if they are related to the incident
What is better not to do
- Do not share the seed phrase and private keys with "helpers" or a "recovery service".
- Do not pay an unknown intermediary a "tax", "insurance", or "unlock fee".
- Do not delete correspondence and transaction history before everything is saved.
Important: the transaction and address are verifiable on-chain facts. The owner's identity, motive, and legal status should not be automatically inferred from a single graph.
When it makes sense to involve a specialist
If the amount is substantial, the route has already branched, or exchanges, swap services, bridges, and other services have appeared along it, a manual review helps separate available actions from useless ones. To start, public data is usually enough — private keys are not needed.
Frequently asked questions
Does the appearance of a similar address mean the wallet has been hacked?
No. By itself, a "twin" in the history does not give the scammer access to the keys. Loss occurs if the user selects this address as the recipient and confirms the transfer.
Can a confirmed transaction be canceled?
As a rule, no. Further actions depend on the route of the funds and whether services have appeared along it that can restrict the movement of assets.
Can the scammer be identified immediately by the address?
No. The blockchain shows addresses and transactions. Identity requires additional data: service KYC, public sources, case materials, or other confirmations.
In short
A scammer adds a similar address to the history and counts on the user copying it instead of the real one. If this has already happened, first stop the repeat risk and save the original data. Then you can review the route and the real points for further action.
Need to understand what happened and where the funds went?
Send the tx hash, network, and a short description of the situation. A seed phrase and private keys are not needed for an initial assessment.
Submit data for assessment