Key points
Blockchain address poisoning is a cryptocurrency scam where attackers exploit the similarities between wallet addresses to trick users into mistakenly transferring funds to the wrong address.
Scammers create counterfeit addresses that are highly similar to commonly used addresses of users and actively send small transactions to these addresses to 'pollute' the user's transaction history.
The irreversibility of blockchain transactions increases the risks and potential losses of address poisoning scams.
To effectively curb such attacks, improvements need to be made at the protocol design, wallet functionality, and user education levels, combined with blockchain data analysis and real-time transaction monitoring.
Introduction
With the popularity of blockchain technology and cryptocurrencies, the methods of attack by cybercriminals are constantly evolving. Among them, blockchain address poisoning has become a prevalent and highly vigilant scam technique. This type of scam induces users to transfer funds to counterfeit addresses that closely resemble their commonly used wallet addresses. Due to the irreversible nature of blockchain transactions, once deceived, users may suffer significant losses.
This article will delve into the operational mechanisms of blockchain address poisoning attacks and the techniques commonly used by scammers, illustrating their dangers with real cases and introducing corresponding preventive measures.
What is cryptocurrency address poisoning attack?
This scam refers to criminals creating counterfeit addresses that are extremely similar to the user's commonly used real wallet address, and using these 'spoofed' addresses to send seemingly harmless small transfers to the victims. The purpose is to fill the victim's recent transaction records or address book with these 'fake' addresses, thereby increasing the likelihood of mistakenly selecting a malicious address during the next transaction.
Blockchain wallet addresses typically consist of a long string of hexadecimal characters, making them hard to remember. Therefore, users tend to directly copy and paste addresses or select from the recent address list displayed in their wallets, which provides a prime opportunity for scammers to implant malicious addresses.
How do attackers generate similar addresses?
Scammers use computer programs to continuously generate wallet addresses in bulk until they find an address that matches the target user's commonly used address in both the beginning and end characters. Since wallet apps usually only display the beginning and end parts of the address, this visual similarity can easily mislead users into thinking the spoofed address is real.
Typical address poisoning attack process
Research the victim: Scammers analyze the victim's transaction patterns to identify their commonly used wallet addresses.
Generate spoofed addresses: Attackers use automated tools to generate addresses that are highly similar to the victim's commonly used addresses.
Pollute transaction records: Attackers initiate very small transfers to the victim's wallet using these spoofed addresses, making the address appear in the history.
Deceive the victim: When the victim sends cryptocurrency again and selects an address from recent records, they may inadvertently choose the spoofed address, resulting in funds being transferred to the scammer.
Real case: 2024 cryptocurrency whale falls victim to poisoning attack
In May 2024, a highly publicized case occurred where a cryptocurrency whale mistakenly transferred nearly $68 million worth of Wrapped Bitcoin (WBTC) to the scammer's Ethereum address. The attacker forged a fake address that completely matched the first six characters of the victim's real address, making it almost indistinguishable. After receiving the funds, the scammer transferred the assets through multiple cryptocurrency wallets.
After several rounds of negotiation, the scammer returned the initial $68 million days later, but due to the increase in token prices during that time, they still made a profit of about $3 million. This attack involved tens of thousands of fake addresses and primarily targeted users holding large amounts of cryptocurrency assets in their wallets and with considerable experience, reflecting the sophistication of such scams and the large scale of the attack.
Who are the target victims?
The main target of address poisoning attacks is usually active users who hold a large amount of cryptocurrency.
Although most spoofed addresses ultimately fail to deceive users, the overall losses from such attacks have accumulated to hundreds of millions of dollars.
Many users will first conduct small 'test' transfers to reduce the risk of large transactions.
How to prevent address poisoning attacks?
Protocol-level optimizations
More user-friendly human-readable addresses: Systems like the Blockchain Naming System (BNS) and Ethereum Name Service (ENS) allow the use of easy-to-remember names instead of lengthy hexadecimal addresses, helping to reduce the likelihood of user errors.
Increase the cost of address creation: By delaying address generation speed or expanding the character set, increase the difficulty and cost of forging similar addresses.
Wallet and interface upgrades
Enhance address visibility: Wallets can display more complete address characters or issue warnings when detecting users attempting to transfer to addresses similar to known spoofed addresses.
Intercept suspicious transfers: Wallets and blockchain explorers can hide or mark suspicious zero-value transfers and fake token transfers used for such scams.
User awareness and best practices
Test before transferring: Always conduct a test with a small transfer before making a large transfer.
Maintain a trusted address list: Use a personal address whitelist to avoid mistakenly selecting fraudulent addresses.
Utilize security tools: Consider installing browser plugins or apps that can detect phishing and address poisoning attacks.
Real-time blockchain monitoring
Real-time monitoring tools can identify anomalous behavior patterns related to address poisoning and promptly alert users, trading platforms, or security teams, thus preventing scams before significant losses occur.
Conclusion
Blockchain address poisoning is an increasingly rampant scam that can lead to significant losses, exploiting the complexity of wallet addresses and users' reliance on operational convenience. Since cryptocurrency transactions are irreversible, even minor mistakes can result in substantial financial losses.
To effectively prevent such scams, collaborative efforts are needed, including optimizing blockchain protocols, designing smarter wallets, enhancing user education, and deploying advanced monitoring systems. Understanding the mechanisms of such attacks and following security practices can help the entire cryptocurrency community reduce risks and improve overall security.
Further reading
Disclaimer: The content of this article is provided 'as is' for general informational and educational purposes only and does not constitute any representation or warranty. This article should not be construed as financial, legal, or other professional advice, and does not recommend you purchase any specific products or services. You should seek advice from appropriate professional advisors. The products mentioned in this article may not be available in your region. If this article is submitted by a third party, please note that the views expressed belong to the third-party submitter and may not reflect the views of Binance Academy. For details, please read the full disclaimer. Digital asset prices may be volatile. The value of your investments may decrease or increase, and the principal invested may not be recoverable. You are fully responsible for your investment decisions, and Binance Academy is not responsible for any losses you may incur. For details, please refer to our terms of use and risk disclaimer.
