Skip to content
Active Currencies: 18,404
Market Cap: $2.272T
Bitcoin Dominance: 56.28%
24h Market Cap Change: $0.06

Crypto address poisoning costs user $100K USDT: How the trap worked

Why 'copy and paste from transaction history' is not recommended when moving funds.

Crypto scams are everywhere. However, this time around, it is the low-tech crypto scammers who are exploiting user interface (UI) habits.

A day after Harmony Protocol was exploited via unauthorized minting of 4 billion ONE tokens, a user has fallen victim to address poisoning.

Inside rising cases of wallet address poisoning

According to Lookonchain, the victim lost more than $100K in USDT after copying an illegitimate wallet address from the transaction history.

Here is the gist.

The attacker initially poisoned the wallet about 66-69 days ago.

Usually, scammers generate lookalike addresses that match the first and last visible characters of a legitimate address the victim has used before. They then send small transfers, commonly known as dust, using the fake address so it appears in the victim’s history.

Address poisoning
Source: Lookonchain

The crypto phishing tactic targets users who copy and paste addresses and send funds without verifying. The latest victim lost funds through this tactic.

Consequently, the attacker swapped the USDT to Ethereum [ETH] 72 seconds after it landed on Uniswap V3 and now holds 52.8 ETH. The purpose was to evade potential freezing, as Tether can do so.

The rate at which address poisoning is rising is alarming. For instance, a routine transfer turned into a multimillion-dollar loss in minutes on the 30th of January. The victim transferred 4,556 ETH valued at $12.40 million to a fake address.

Source: Web3 Antivirus

That is not all.

Another victim lost $649K from a fake address that initially sent $10 in early May. In total, between late 2025 and early 2026, reports indicated that Ethereum-related losses reached $62 million.

Such data hints that there was a series of address poisoning scams that were yet to be exposed, bearing in mind that on-chain investigators largely covered the technical exploits.

What users need to do

As wallet address poisoning scams skyrocket, what do users need to do to avoid falling victim? For instance, Lookonchain advised,

Always double-check the wallet address before sending funds, and never copy an address from your transaction history.

Other measures include having a test transaction before sending any large amount as well as an address book.

Additionally, users need to be wary of unexpected incoming transfers while deploying some tools and explorers that flag potential poisoning.


Final Summary

  • A victim lost over $100K in USDT from a crypto phishing attack that used a wallet address poisoning tactic. 
  • The rising number of address poisoning attacks indicates that those who ‘copy and paste from transaction history’ are the most vulnerable. 
Disclaimer: AMBCrypto's content is meant to be informational in nature and should not be interpreted as investment advice. Trading, buying or selling cryptocurrencies should be considered a high-risk investment and every reader is advised to do their own research before making any decisions.

Lennox Gitonga

Journalist

Lennox Gitonga is a Financial Market and On-Chain Analyst at AMBCrypto with a Bachelor of Commerce in Finance. As a former equities trader, he applies traditional market rigor to crypto, delivering clear technical and on-chain analysis that explains price action, liquidity, and network behavior driving digital asset trends.

AMBCrypto was founded in 2018 with a mission to simplify and bring the latest blockchain and cryptocurrency news to our readers. We have quickly grown into the digital news source for an emerging generation of cryptocurrency enthusiasts, reaching more than a million readers on a monthly basis, across the globe.