Definition
Address poisoning is a deception aimed at how people copy payment destinations. An attacker tries to make a controlled address appear familiar, often by resembling the beginning or end of an address the victim already uses. The objective is a later mistaken transfer; it does not require obtaining the victim’s private key.
How It Works
Small transfers, zero-value activity or misleading token records can place an unfamiliar address in a wallet’s visible history. If the user copies a destination from that history and checks only a few characters, the planted address may be mistaken for the intended one. The exact display depends on the wallet and network, so an entry appearing in history is not evidence that the user previously approved or trusted it.
Key Considerations
Copy receiving details from a verified source or an independently maintained address book rather than recent activity alone. Check the complete address and network, especially before a large transfer. A small test can help confirm a destination, but it does not remove the need to verify subsequent transaction details. Receiving an unsolicited token does not automatically compromise a wallet. Avoid interacting with suspicious claims, and remember that a confirmed transfer to the wrong address is generally not reversible through the wallet interface.