BTC ETH SOL BNB XRP Fear & Greed
AltcoinGordon
News

Address Poisoning Scam Drains $100,000 in USDT From Crypto User

A lookalike wallet address tricked a victim into sending stablecoins to an attacker instead of their intended recipient

Original AltcoinGordon illustration for: Address Poisoning Scam Drains $100,000 in USDT From Crypto User
Original illustration, drawn for this story by AltcoinGordon.

A cryptocurrency user lost approximately $100,000 worth of USDT in an address poisoning attack, according to reports from crypto.news and AMBCrypto. The incident follows a pattern that has become familiar across blockchain networks over the past few years.

Address poisoning does not require hacking a wallet or exploiting a smart contract bug. Instead, attackers study a target's transaction history on a public blockchain. They then generate a new wallet address that shares the same first and last few characters as an address the victim has previously interacted with.

The attacker sends a small, often worthless transaction from this lookalike address to the victim's wallet. That transaction then appears in the victim's transaction history, sitting alongside genuine past transfers. If the victim later copies an address from their history without checking it in full, they risk sending funds to the attacker's address instead of the intended recipient.

In this case, reports indicate the trap succeeded, and the victim's USDT was diverted to the attacker's wallet. Once stablecoins move to an external address, recovery becomes difficult. Blockchain transactions are irreversible by design, and there is no central authority that can claw back the funds automatically.

Address poisoning has drained victims of varying sums since it first drew wider attention, with past incidents ranging from modest amounts to losses in the tens of millions of dollars. The technique persists because it exploits human behavior rather than a technical flaw. Many wallet interfaces still display truncated addresses, showing only the first and last several characters. That design choice, intended to improve readability, makes it easier for a poisoned address to pass as legitimate at a glance.

Security researchers have repeatedly urged users to verify full addresses before sending transactions, rather than relying on shortened displays or transaction history alone. Some wallet providers have introduced address-book features and whitelisting tools meant to reduce this risk, but adoption of these protections remains uneven across the ecosystem.

The $100,000 loss reported here is smaller than some previous address poisoning incidents but still represents a meaningful sum for an individual holder. It also reinforces a broader point: even as institutional custody solutions and regulatory frameworks mature, retail users interacting directly with self-custodied wallets remain exposed to social engineering tactics that require no exploitation of underlying blockchain code.

Market Impact

This incident is unlikely to move broader crypto markets, given its scale relative to daily trading volumes in USDT and other stablecoins. However, it adds to a running tally of address poisoning losses that has drawn attention from wallet developers and blockchain security firms.

Repeated incidents of this kind may accelerate adoption of protective features such as address whitelisting, transaction simulation, and clearer address verification prompts within wallet software. They also serve as a reminder to exchanges and stablecoin issuers about the reputational stakes tied to user losses, even when the platforms themselves are not directly responsible for the theft.

As address poisoning attacks continue to surface, the incident underscores the importance of manually verifying wallet addresses before transferring funds, regardless of how established a user's transaction history may appear.

Frequently Asked Questions

What is an address poisoning attack?

It is a scam where an attacker creates a wallet address that closely resembles one a victim has used before. The attacker sends a small transaction to plant the lookalike address in the victim's transaction history, hoping the victim later copies it by mistake.

How did the victim lose $100,000 in USDT?

According to reports from crypto.news and AMBCrypto, the victim appears to have copied a poisoned address resembling a trusted contact and sent USDT to the attacker instead of the intended recipient.

Can stolen funds from an address poisoning attack be recovered?

Recovery is difficult because blockchain transactions are irreversible. Once funds reach an attacker's wallet, there is no automatic mechanism to reverse the transfer.

How can users protect themselves from address poisoning scams?

Security researchers recommend verifying a full wallet address before sending funds, avoiding reliance on truncated displays, and using wallet features like address whitelisting or saved contact lists where available.