TL;DR
- The attacker generates an address whose first and last characters match a counterparty you actually use, plants it in your transaction history with a zero-value event, a counterfeit token or a tiny transfer, and waits for you to copy it from that history. The attack is patient, cheap at scale, and aimed at your habits rather than your keys.
- It removes the need to be in your history at all: malicious software on your device watches the clipboard, recognises copied crypto addresses by their format, and silently replaces yours with the attacker's between copy and paste. The address you verified at the source and the address you paste are different strings.
- Because attackers choose the characters you check. Both attacks are engineered against first-and-last verification, so real verification means comparing the whole string against a destination you saved or obtained independently, doing it at the paste destination, and confirming on a display the compromised machine does not control. Each of these steps reduces a specific risk; none is a guarantee.
In one block
Address poisoning is a payment-redirection attack that plants attacker-controlled lookalike addresses in a victim's transaction history, using zero-value token events, counterfeit tokens or tiny transfers, so that a later copy from that history selects the attacker's address.
How does address poisoning actually work?
Quick answer
The attacker generates an address whose first and last characters match a counterparty you actually use, plants it in your transaction history with a zero-value event, a counterfeit token or a tiny transfer, and waits for you to copy it from that history. The attack is patient, cheap at scale, and aimed at your habits rather than your keys.
The mechanics unfold in three moves. First, surveillance: public ledgers make payment patterns readable to anyone, and campaigns watch for transfers to a repeated counterparty, exchange deposit addresses being the classic case. Second, imitation: vanity-generation tools grind out addresses until one matches the target counterparty's leading and trailing characters. Matching a handful of characters at each end is computationally cheap, which is exactly why those are the characters everyone checks; matching more costs more compute but is not impossible, and one measured campaign group appears to have used GPUs for the job (Tsuchiya, Dong, Soska and Christin, "Blockchain Address Poisoning", USENIX Security 2025). Third, contamination: the attacker places the lookalike in the victim's history, usually within minutes of the genuine transfer so that the plant sits next to the real address in the chronology. The USENIX study's detection method looked for poisoning within the 20 minutes after the original transfer.
What the plant looks like, by chain
The word "dust" is used loosely for all of this, and the loose usage hides a distinction that matters for what you see in your wallet.
On Ethereum, BNB Smart Chain and other EVM chains, the cheapest plant is not a transfer of anything. The ERC-20 token standard says that transfers of zero value "MUST be treated as normal transfers and fire the Transfer event" (EIP-20). Because a zero-value `transferFrom` needs no allowance, an attacker can emit a Transfer event that reads as "from your address to the lookalike" for a token you really hold, paying only gas. Wallets and explorers that render token events as history then show the lookalike as an address you apparently paid. A second EVM variant deploys a counterfeit token with a copied name (a fake "USDT", for example) and sends the victim an amount matching a real recent payment. Real tiny transfers of a genuine token are the third form. Over two years on Ethereum, the USENIX study counted roughly 7.2 million zero-value transfers and 9.9 million counterfeit-token transfers against about 309,000 tiny transfers; of the tiny transfers under 10 dollars, almost 99 percent were under 3 dollars (Tsuchiya et al., 2025). Etherscan's own guidance separates the same three patterns, calling them event spoofing, token spoofing and address spoofing, and its explorer mutes zero-value token transfers and marks them with a warning icon (Etherscan Information Center, 23 February 2023 and 15 January 2024, updated 21 June 2026).
On Bitcoin there are no token contracts and no events, so a poisoning plant has to be a real transaction that sends a tiny amount of bitcoin to the victim, and the attacker pays a fee for each one. Tron's TRC-20 tokens follow the ERC-20 interface, so both real tiny USDT transfers and zero-value token events are possible there; the published measurement work covers Ethereum and BNB Smart Chain only, so this guide does not give Tron figures. The practical point holds on each chain discussed here: an unexplained deposit of nothing, of a token you never asked for, or of a few cents is the attacker's cost of entry, and its purpose is to sit upstream of your next payment.
Then the attacker waits. Nothing further is needed from them: the next time the victim pays that counterparty by copying from history, some fraction of victims select the plant. The economics explain the persistence. The USENIX authors measured about 270 million on-chain poisoning attempts against roughly 17 million victim addresses on Ethereum and BNB Smart Chain over two years, with at least 83.8 million dollars in losses across 6,633 incidents; the pipeline tracked stablecoin transfers, so the WBTC case below falls outside that count (Tsuchiya et al., 2025). The reference case is 3 May 2024, when one Ethereum user sent 1,155 WBTC, then worth about 68 million dollars, to a lookalike address that differed from the intended one in the middle characters. According to Chainalysis, the attacker returned the funds on 9 May after being contacted, keeping roughly 3 million dollars of gain from the intervening price move; the same investigation traced the campaign to eight seeder wallets and 82,031 potential seeded addresses, just under one percent of all new Ethereum addresses created in the period, and found that 756 other addresses had sent small amounts of between 1 and 100 dollars to lookalikes, which the authors read as test payments that stopped larger losses (Chainalysis, 23 October 2024). The academy's Crypto Loss Report situates the category among transfer-stage losses; what matters here is that each of the victim's actions felt like established routine.

What does clipboard malware do differently?
Quick answer
It removes the need to be in your history at all: malicious software on your device watches the clipboard, recognises copied crypto addresses by their format, and silently replaces yours with the attacker's between copy and paste. The address you verified at the source and the address you paste are different strings.
Clipboard hijackers, also called clippers, are a long-standing category of crypto-specific malware. They have been found on desktop and on mobile, including an Android clipper that ESET reported finding in Google Play in February 2019, which replaced copied Bitcoin and Ethereum addresses (ESET WeLiveSecurity, 8 February 2019), and they spread through cracked software, fake wallet apps, malicious browser extensions, removable media and the loader families that the academy's drainer coverage describes. Their logic is compact: pattern-match clipboard contents against address formats, swap in an attacker address of the same chain, and pass everything else through untouched so the machine feels healthy. A clipper analysed by Microsoft in June 2026 polled the clipboard about every 500 milliseconds, recognised Bitcoin legacy, P2SH, Bech32 and Taproot formats as well as Tron and Monero addresses, spread through malicious shortcut files on USB drives, and preserved some characters of the original so the substitute looked familiar (Microsoft Security Blog, 17 June 2026).
The distinction from poisoning matters for defence. Poisoning corrupts the place you copy from and is reduced by choosing better sources; a clipper corrupts the copying itself, so even an address copied from a verified official page pastes wrong. That is why the paste-side check, reading the address at the destination field, and on the signing device's display where one exists, is the layer that can catch clippers, and why a mismatch between what you copied and what you pasted is a serious signal: it means the device doing the copying is compromised, and the incident response guide's device-compromise drill applies, starting with the rule that the affected machine signs nothing further.
Why do partial checks fail, and what does real verification look like?
Quick answer
Because attackers choose the characters you check. Both attacks are engineered against first-and-last verification, so real verification means comparing the whole string against a destination you saved or obtained independently, doing it at the paste destination, and confirming on a display the compromised machine does not control. Each of these steps reduces a specific risk; none is a guarantee.
The habit under attack is understandable: addresses are long, unmemorable strings, so people compress verification to the ends and a glance at length. Wallets and explorers encourage the habit by truncating addresses to a few characters at each end; the USENIX detection threshold of three leading and four trailing matching characters was chosen because that is what common displays show (Tsuchiya et al., 2025), and a separate 2025 evaluation of 53 Ethereum wallets found only three that explicitly warned a user about to send to a lookalike, while 16 displayed counterfeit-token transfers as if they were real (Guan and Li, arXiv, August 2025). Vanity generation makes the ends worthless as authentication precisely because they are cheap to reproduce.
It is tempting to conclude that reading more characters solves the problem. It does not, for two reasons. First, "more" is a moving target: a campaign that targets one high-value counterparty can spend the compute to match six, eight or more characters at each end, so a rule of "check six" is a rule the attacker can read too. Second, a longer partial check is still a comparison against your memory of a shape, and memory is exactly what the lookalike is designed to satisfy. MetaMask's own guidance tells users to pay close attention to the middle characters and to avoid copying from history (MetaMask Help Center); both are sound, and neither is the whole answer. The defence that does not depend on how many characters you read is to compare the full string against a destination you hold independently of the thing you are checking: an address book entry saved from a verified source, a QR code from the counterparty's own device, or a deposit page opened fresh from the exchange rather than from history. Some wallets now automate the comparison; MetaMask, for example, announced in June 2026 that it had added a blocking warning for when a pasted address matches the ends of a previously used address but differs in the middle, across EVM networks (MetaMask, 17 June 2026). Such warnings are a useful backstop and cover only the wallets and chains that implement them.
Where the comparison happens matters as much as what it is compared against. Source-side checks validate where you copied from; the theft happens by paste time, so the binding check is at the destination field, immediately before signing, and, for hardware users, on the device display, which is designed to be outside a compromised computer's control, the same principle the blind signing guide builds on. Trezor's guidance, for example, is to check every character of the destination on the device screen before confirming, and never to take an address from Suite's history or a block explorer (Trezor support). The display check is only as trustworthy as the device showing it: it assumes genuine hardware and sound firmware, and hardware wallets have had their own flaws, which the wallet vulnerability ledger records. For meaningful transfers, the test-transaction habit from the sending guide adds a further layer: a small amount first, confirmed received by the counterparty out-of-band, can expose a wrong address or network while the amount at stake is small, which is what those 756 small payments in the May 2024 campaign did for the people who made them. Its protection is limited to the exact string and route it tested. Because plants often arrive within minutes of a genuine transfer, the test payment can itself prompt a lookalike in your history, so an address copied from history for the main transfer can be poisoned after the test succeeded; a clipper can swap the second paste as easily as the first; and a test amount says nothing about a malicious approval or signature request, which moves no test funds at all and is covered in the blind signing guide. The main transfer therefore needs the same full-string check as the test.
Two hygiene habits shrink the attack surface before verification is even needed. Maintain an address book: verified counterparties saved once, under names, inside the wallet, so that routine payments do not start from raw strings or history. That reduces exposure to poisoned history specifically. It does not protect against an entry saved wrongly in the first place, against malware on the device that is signing, or against a malicious approval request, and an allowlist of approved destinations, where a wallet or platform offers one, works on the same principle with the same limits: it restricts where funds can go, and it is only as good as the entries on it. Verify at save time, from an independent source, because a book populated by copying from history inherits the poison. And treat unexpected zero-value events, unknown tokens and tiny deposits as contamination markers: do not interact with them, and let their arrival prompt extra care on the next transfer, since their purpose is to sit upstream of exactly that transfer.

Frequently asked questions
Is a zero-value token transfer or tiny deposit from an unknown address dangerous?
Sitting in your history it steals nothing; its danger activates only if you later copy it. A zero-value event on an EVM chain moved nothing at all and needed no permission from you (EIP-20). Do not interact with unknown tokens, since some contracts are built to misbehave on interaction, regard the deposit as a marker that your address is in a campaign's dataset, and be deliberate about the source of the next address you pay.
Can address poisoning affect you if you always use an address book?
An address book populated from verified, independent sources and used consistently closes poisoning's usual entry point, copying from history, which is the reason this guide describes it as the primary defence against this attack. It reduces that specific risk and does not make transfers safe in general. The residual risks are the book's own hygiene, verify at save time and never save from history; clipboard malware wherever an address is still pasted, which the paste-side and display checks reduce; a compromised signing device; and malicious approval requests, which an address book does not address at all.
Does ENS or another name service protect against address poisoning?
They shorten what you must verify from a long string to a human-readable name, which helps, and they move the verification target: names have their own lookalikes (character substitutions, similar spellings), and the name must still be checked carefully at the paste destination. A verified name in an address book reduces the risk further; a name glanced at in a hurry is the old problem in new clothing.
Can you get crypto back after sending it to a poisoned address?
The transfer is as final as any other on-chain payment, and a report does not guarantee that anything is recovered. The reporting routes are set out in the guide to responding after a theft: in the United States, the FBI's IC3 at ic3.gov; in England, Wales and Northern Ireland, Report Fraud (formerly Action Fraud) at reportfraud.police.uk or on 0300 123 2040; in Scotland, Police Scotland on 101 (City of London Police, December 2025). Funds are occasionally frozen when they reach an exchange or a token issuer that acts on a report. The May 2024 return of most of the 1,155 WBTC followed contact with the attacker, according to Chainalysis, and that outcome cannot be expected in the general case (Chainalysis, 23 October 2024). Anyone who then offers to recover crypto for an upfront fee fits a known follow-on scam: the FBI warns that such fraudsters take the fee and either vanish or ask for more (FBI IC3 PSA, 11 August 2023).
How can you tell if your computer or phone has clipboard malware?
The tell is the mismatch: what you paste differs from what you copied. Test deliberately: copy a known address, paste it into a text editor, compare in full. Any mismatch means the machine is compromised and signs nothing further until rebuilt; the drainer and response guides carry the drill from there. A clean test is weaker evidence than a mismatch, because a clipper may target only certain address formats, as the family Microsoft analysed did (Microsoft Security Blog, 17 June 2026).
Sources and further reading
- Blockchain Address Poisoning (Tsuchiya, Dong, Soska, Christin; Proceedings of the 34th USENIX Security Symposium). arXiv, 28 January 2025, revised 2 July 2025. https://arxiv.org/abs/2501.16681 (accessed 23 September 2026)
- Ethereum Crypto Wallets under Address Poisoning: How Usable and Secure Are They? (Guan and Li). arXiv, 16 August 2025. https://arxiv.org/abs/2508.12107 (accessed 23 September 2026)
- Address Poisoning Scam: How It Works and the $68 Million WBTC Case (investigator's account of the May 2024 case and campaign scale). Chainalysis, 23 October 2024. https://www.chainalysis.com/blog/address-poisoning-scam/ (accessed 23 September 2026)
- EIP-20: Token Standard (zero-value transfers must fire the Transfer event). Ethereum Improvement Proposals, 19 November 2015. https://eips.ethereum.org/EIPS/eip-20 (accessed 23 September 2026)
- Address Poisoning Attacks (token, address and event spoofing). Etherscan Information Center, 15 January 2024, updated 21 June 2026. https://info.etherscan.com/what-is-address-poisoning/ (accessed 23 September 2026)
- Zero-Value Token Transfer Attack. Etherscan Information Center, 23 February 2023. https://info.etherscan.com/zero-value-token-transfer-attack/ (accessed 23 September 2026)
- Address poisoning scams (wallet vendor guidance). MetaMask Help Center, undated. https://support.metamask.io/stay-safe/protect-yourself/wallet-and-hardware/address-poisoning-scams/ (accessed 23 September 2026)
- Address poisoning detection now live in MetaMask (vendor announcement). MetaMask, 17 June 2026. https://metamask.io/news/address-poisoning-detection (accessed 23 September 2026)
- What are address poisoning attacks and how to avoid them (wallet vendor guidance). Trezor support, undated. https://trezor.io/support/troubleshooting/coins-tokens/what-are-address-poisoning-attacks-and-how-to-avoid-them (accessed 23 September 2026)
- First clipper malware discovered on Google Play (Android/Clipper.C). ESET WeLiveSecurity, 8 February 2019. https://www.welivesecurity.com/2019/02/08/first-clipper-malware-google-play/ (accessed 24 September 2026)
- Increase in Companies Falsely Claiming an Ability to Recover Funds Lost in Cryptocurrency Investment Scams (PSA230811). FBI Internet Crime Complaint Center, 11 August 2023. https://www.ic3.gov/PSA/2023/psa230811 (accessed 24 September 2026)
- Report Fraud service goes live with full public launch in January 2026. City of London Police, December 2025. https://www.cityoflondon.police.uk/news/city-of-london/news/2025/december/report-fraud-service-goes-live-with-full-public-launch-in-january-2026/ (accessed 24 September 2026)
- Crypto Clipper uses Tor and worm-like propagation for persistence and control. Microsoft Security Blog, 17 June 2026. https://www.microsoft.com/en-us/security/blog/2026/06/17/crypto-clipper-uses-tor-worm-like-propagation-for-persistence-control/ (accessed 23 September 2026)
Quick quiz: did it stick?
A few questions to check the fundamentals landed. Answers with explanations follow, and nobody is grading you except your future portfolio.
You have completed a quiz on “Address Poisoning and Clipboard Attacks Explained”! Share your achievement on social media.




