VEYRNOX · Learn · Address Poisoning

Address Poisoning

Address poisoning is a wallet-address confusion attack in which an attacker sends a zero-value or dust transaction from an address that visually resembles one of the victim’s frequent contacts. The victim later copy-pastes the poisoned address from history and sends real funds to the attacker.

How it works

The attacker generates a vanity address whose first four and last four characters match the victim’s target contact. They send a small dust transaction to the victim, which appears in the transaction history alongside legitimate entries. When the victim later copies an address from history — a common UX shortcut — they may pick the poisoned entry instead of the real one. Because wallets typically display addresses in truncated form ("0x1234…abcd"), the substitution is invisible without a full-character comparison.

Why it matters

This attack has drained millions of dollars from careful users who followed every security best practice except one: they trusted their own transaction history. It exploits a UI convention (truncated address display) rather than a cryptographic weakness. The defence is wallet-level: filter dust from history, warn on near-duplicate addresses, and require full-address confirmation before sending.

Related concepts

Frequently asked questions

How much does address poisoning cost the attacker?

Almost nothing — gas for one dust transaction. That is why the attack is run at scale against every high-balance address.

Can I whitelist my real contacts?

Yes. Veyrnox stores counterparties by full address, so lookalikes fail an exact-match check even if the truncated view matches.

Does verifying the last four characters help?

No. Attackers grind vanity addresses that match both the first and last four characters. Always verify the full address.

In Veyrnox

Veyrnox filters incoming dust from address book views and, on Safety Plus, warns when an outgoing address closely resembles a prior counterparty without exactly matching. The warning is surfaced by the Threat Intelligence Platform rule set.

Learn more →