Deep Tide TechFlow news: On October 04, according to monitoring by GoPlus Security, a user suffered losses of about 305,000 USD in DAI due to an “address poisoning” attack.
The attacker generated a fake address whose prefix and suffix matched what the victim was expected to transfer to, then sent the victim small amounts of “dust” funds to lure them into incorrectly copying the fake address from historical transaction records during subsequent transfers.
GoPlus Security reminds that such attacks have been automated, covering the entire process from target discovery and address spoofing to money laundering via mixers. Users should avoid directly copying addresses from historical transaction records, verify the full address before transferring, and perform a small test transfer before making any large transfer.
The attacker generated a fake address whose prefix and suffix matched what the victim was expected to transfer to, then sent the victim small amounts of “dust” funds to lure them into incorrectly copying the fake address from historical transaction records during subsequent transfers.
GoPlus Security reminds that such attacks have been automated, covering the entire process from target discovery and address spoofing to money laundering via mixers. Users should avoid directly copying addresses from historical transaction records, verify the full address before transferring, and perform a small test transfer before making any large transfer.
