Address poisoning is a scam that plants an address resembling one you already use into your transaction history, betting that next time you send funds you will copy it from that history instead of from the real source. Attackers generate vanity addresses matching the first and last few characters of a genuine address, send a zero-value or dust transaction to insert it into your feed, and wait. It requires no exploit, no signature and no access to your wallet — only the very common habit of copying an address from a recent transaction. Two individuals lost $12.25 million and $50 million to exactly this in December 2025 and January 2026.
Key Facts
- Attackers brute-force vanity addresses matching the first and last 4-6 characters of a target address.
- The middle of the address is completely different — and it is the part nobody reads.
- Delivery is a dust or zero-value transfer, purely to appear in your transaction history.
- No signature, approval or wallet access is needed at any point.
- Scam Sniffer recorded individual losses of $12.25M in January 2026 and $50M in December 2025 from copied wrong addresses.
- Solana addresses are base58 and 32-44 characters, which makes visual comparison unreliable.
- Transfers are irreversible — there is no recovery once sent.
The Mechanics
Step one: the attacker watches the chain for wallets that transfer meaningful sums to the same destination repeatedly — an exchange deposit address, a second wallet you own, a business counterparty. Step two: they run a vanity generator until they produce a keypair whose address starts and ends with the same characters as that destination. Generating a match on the first four and last four characters takes minutes of ordinary compute.
Step three: they send you a tiny transfer from that lookalike address, or a zero-value transaction, purely so it appears in your history. Step four: they wait. The next time you go to send funds and copy the address from your recent activity — because it is right there and it looks correct — you paste theirs. Nothing about the attack touches your keys, which is why keypair security is irrelevant to it and why hardware wallets offer no protection at all.
Why Truncated Addresses Are the Problem
| What you see | What it hides | Risk |
|---|---|---|
| 4YK1…98P5Z in a wallet UI | Roughly 30 middle characters | High — the matched part is all you check |
| First 6 and last 6 | Still 20+ characters | Slightly better, still exploitable |
| Full address, read carefully | Nothing | Low, but nobody does it every time |
| Saved address book entry | Nothing — you verified it once | Very low |
| Copied from transaction history | Whether the entry is genuine | The attack surface itself |
Every wallet interface truncates addresses, because a 44-character base58 string is unreadable in a list. That design necessity is precisely what the attack exploits: the visible characters are the ones the attacker matched, and the hidden middle is where the difference lives.
What Actually Prevents It
One habit closes almost the entire attack: never copy an address from transaction history. Use a saved address book entry that you verified once when you created it, or copy from the original source — the exchange’s deposit page, the counterparty’s message, your own wallet’s receive screen. Interfaces including Gem Wallet, Phantom and Solflare support address books, and the two minutes spent adding entries is the whole defence.
Beyond that: send a small test transaction before anything large, verify the middle characters rather than the ends, and treat any unexplained tiny incoming transfer as a warning that you are being targeted — which is the same signal discussed in dust attacks, since the delivery mechanism is identical. Check unfamiliar entries on Solscan before assuming an address in your history is one you have used before.
Why the Losses Are So Large
The scale of individual losses — $50 million in one case — reflects who the attack selects for. Poisoning targets wallets that already move large sums repeatedly, because the attacker needs a pattern to imitate. Retail traders sending small amounts occasionally are poor targets; treasuries, funds and high-volume individuals are ideal ones. The technique also scales cheaply, so an attacker can poison thousands of wallets simultaneously and wait for any of them to slip once. One success pays for everything.
Verifying Addresses in Practice
DOLAN Duck ($DOLAN) lives at 4YK1njyeCkBuXG6phNtidJWKCbBhB659iwGkUJx98P5Z, and that string illustrates the problem neatly: almost everyone who has read it remembers “4YK1” and “98P5Z”, which is exactly the amount an attacker needs to reproduce. The same logic applies to token contract addresses as to wallet addresses — verifying a contract address means comparing the whole string against a source the project controls, not recognising the ends. Whether you are sending SOL to a friend or pasting a mint into a swap interface, the rule is identical: the characters you can see are the ones an attacker matched on purpose. Check DEXScreener or an explorer against the official source, every time, and never trust your own memory of an address.
Address poisoning plants a lookalike address into your transaction history, matching the first and last characters of one you already use, hoping you copy it from there when sending funds.
By brute-forcing vanity addresses until one matches the visible characters of the target. Matching the first and last four takes only minutes of ordinary computing power.
No. The attack never touches your keys or requires a signature — it relies entirely on you copying the wrong address. Hardware wallets provide no protection against it.
Nothing. Transfers on Solana are irreversible, and the funds are in an address the attacker controls. Prevention is the only defence available.
Never copy addresses from transaction history. Use a verified address book entry or copy from the original source, and send a small test transaction before anything large.
Scam Sniffer reported individual losses of $12.25 million in January 2026 and $50 million in December 2025 from users copying the wrong address out of their transaction history.
Possibly. Unexplained tiny incoming transfers are the standard delivery mechanism for both dusting and address poisoning, so treat them as a signal to check any address before your next send.