Key takeaways
- Address poisoning tricks you into copying a scammer's address from your own transaction history.
- It is one of the most common attacks on stablecoin users: about 160,000 poisoning transactions a day, according to Blockaid.
- Single mistakes have cost people $12 million and $50 million in USDT.
- Three habits stop it: never copy addresses from history, check the full address, and send a small test first.
A $50 Million Copy-Paste Mistake
In December 2025, a crypto user lost about $50 million in USDT in a single transaction. They did not click a phishing link or share their seed phrase. They copied what looked like a familiar address from their own transaction history and pasted it into the send screen. The address belonged to a scammer. In January 2026, another user lost about $12.25 million the same way.
This attack is called address poisoning, and it targets exactly the kind of everyday transfers people make with stablecoins.
How Address Poisoning Works
Crypto addresses are long strings like 0x8f3a…9c21. Most wallets shorten them, showing only the first and last few characters, and most people only check those.
- The scammer watches the blockchain. They see you send money to an address you use often, for example a friend or an exchange deposit address.
- They generate a look-alike address. Using software, they create an address whose first and last characters match the one you use.
- They poison your history. They send you a tiny or zero-value transfer from the look-alike address, so it appears in your transaction list right next to the real one.
- You copy the wrong one. Next time you send money, you copy the address from your history. The fake looks identical at a glance, and the funds go to the scammer.
Because blockchain transactions are final, there is usually no way to reverse the payment once it is sent.
How Common Is It?
Security firm Blockaid has counted about 65.4 million address poisoning transactions since January 2025, roughly 160,000 every day. Most fail, but the attack is cheap enough to run at scale, so scammers only need a few people to make a mistake. It is most common on networks with low fees, where sending millions of fake transfers costs very little.
Seven Habits That Protect You
- Never copy an address from your transaction history. Always get it from the original source: the recipient themselves, or your exchange's deposit page.
- Check the whole address, not just the ends. Compare a few characters in the middle too. Look-alike addresses match the beginning and end, not the middle.
- Save trusted addresses. Use your wallet's address book or contacts, and send to the saved entry each time.
- Send a small test first. For large amounts, send a few dollars, confirm the recipient got it, then send the rest.
- Ignore unexpected tiny transfers. A zero-value or dust transfer from an unknown address is a warning sign, not a gift.
- Use readable names where possible. Name services like ENS, or sending to a contact's username, remove the need to compare long strings.
- Slow down for big sends. Most losses happen when someone is in a hurry. Treat any large transfer as a two-step process.
Sending to a contact by their chat username, which some Telegram-based wallets support, avoids the copy-paste step entirely. Our article on sending crypto through Telegram explains how that works.
Other Threats to Know in 2026
- Physical "wrench attacks": criminals targeting known crypto holders in person stole more than $30 million in the first half of 2026, according to Chainalysis. Don't share your holdings publicly.
- Leaked customer data: in August 2026, data breaches at hardware wallet sellers exposed the shipping details of more than 250,000 customers. If you bought a hardware wallet, be wary of letters, emails, or calls asking you to "verify" your device or seed phrase.
- Classic scams still work: fake support agents, investment "opportunities", and phishing sites remain the most common way people lose money. Our guide to avoiding crypto scams covers them all.
What to Do If You Sent Funds to a Poisoned Address
- Stop and don't send anything else from that wallet until you've checked what happened.
- If the stablecoin issuer can freeze funds (as Tether and Circle can in some cases), contact them immediately with the transaction details.
- Report it to your local police and to any exchange the funds were sent to. Fast reports occasionally lead to freezes.
- Beware of "recovery services" that contact you: they are almost always a second scam.
For a broader look at keeping your money secure, see how to keep your money safe online and our guide to crypto wallets.
Frequently asked questions
What is address poisoning?
A scam where an attacker sends you a tiny transfer from an address that looks like one you use, hoping you later copy it from your transaction history and send funds to them.
Can I get my crypto back after sending it to a poisoned address?
Usually not, because blockchain transactions are final. Contact the stablecoin issuer and report it quickly, since some issuers can freeze funds in certain cases, and ignore "recovery services".
How do I avoid address poisoning?
Never copy addresses from your history, check the full address including the middle characters, use saved contacts, and send a small test before large transfers.
Why did someone send me a zero-value transaction?
It is often an address poisoning attempt. Treat unexpected tiny or zero-value transfers from unknown addresses as a warning sign.
This article is for educational purposes only. Figures are based on public reports.