Guide
What is address poisoning
2 min read · September 2026
A plain explainer of address poisoning, how the lookalike-address trick works, and what to check before you copy an address from your history.
Address poisoning is a technique where an attacker generates a wallet address that shares the same first and last few characters as an address you already use. They then send you a transaction, often worth zero or a fraction of a cent, from that lookalike address. The goal is simply to get it to appear in your transaction history.
The trap works because most people, and most interfaces, don't display the full address by default. If you're used to sending funds to a counterparty by copying their address from a past transaction, and you glance only at the opening and closing characters, the poisoned entry looks identical to the real one. Copy it, and the funds go to the attacker instead.
Why this matters for anyone reviewing wallet activity
For a compliance analyst or investigator, address poisoning changes what a clean-looking transaction history actually tells you. A wallet's send history is no longer reliable proof that a given address belongs to a known counterparty. It may simply be an address that was engineered to resemble one.
- A 0-value or negligible-value transfer in a wallet's history is not evidence of a real relationship between the sender and receiver.
- Matching first and last characters is not sufficient to confirm two addresses are the same.
- Poisoning attempts can sit in a wallet's history for a long time before anyone acts on them, which means they can show up in historical reviews as well as live monitoring.
What to actually do about it
The defence is mechanical, not clever: compare the full address string, not just the bookends, before treating any address as verified or before relying on copy-paste from history. This applies whether you're advising a client on an outgoing transfer or reviewing a chain of transactions for a report.
- Verify the complete address character by character, or use a tool that does the comparison for you, rather than eyeballing the start and end.
- Treat 0-value or dust-value incoming transactions as a signal to check the sender address carefully, not as noise to ignore.
- When documenting a wallet's counterparties for a case file, note which addresses were confirmed by full-string comparison and which were assumed from history.
The whole attack depends on you trusting the first and last few characters instead of the full string. Checking the full address defeats it every time.
WalletDNA's glossary keeps a plain-language definition of address poisoning and related terms at walletdna.com/glossary for quick reference during a review.
Sources
Check a wallet yourself
Risk analysis and entity attribution across 18 chains, free to start.
Analyze a wallet