Crypto Address Poisoning Scam Costs User $100K in USDT

iconAMBCrypto
Share
AI summary iconSummary
A user lost over $100K in USDT after falling for a wallet address poisoning scam. The attacker used a fake address that matched part of a legitimate one, sending small amounts to mimic real transactions. Funds were later drained and swapped to ETH to avoid Tether’s freezing. As the crypto market remains a target for such tactics, traders are advised to double-check addresses. Among altcoins to watch, security risks continue to shape investor caution.

Crypto scams are everywhere. However, this time around, it is the low-tech crypto scammers who are exploiting user interface (UI) habits.

A day after Harmony Protocol was exploited via unauthorized minting of 4 billion ONE tokens, a user has fallen victim to address poisoning.

Inside rising cases of wallet address poisoning

According to Lookonchain, the victim lost more than $100K in USDT after copying an illegitimate wallet address from the transaction history.

AD

Here is the gist.

The attacker initially poisoned the wallet about 66-69 days ago.

Usually, scammers generate lookalike addresses that match the first and last visible characters of a legitimate address the victim has used before. They then send small transfers, commonly known as dust, using the fake address so it appears in the victim’s history.

Address poisoning
Source: Lookonchain

The crypto phishing tactic targets users who copy and paste addresses and send funds without verifying. The latest victim lost funds through this tactic.

Consequently, the attacker swapped the USDT to Ethereum [ETH] 72 seconds after it landed on Uniswap V3 and now holds 52.8 ETH. The purpose was to evade potential freezing, as Tether can do so.

The rate at which address poisoning is rising is alarming. For instance, a routine transfer turned into a multimillion-dollar loss in minutes on the 30th of January. The victim transferred 4,556 ETH valued at $12.40 million to a fake address.

Source: Web3 Antivirus

That is not all.

Another victim lost $649K from a fake address that initially sent $10 in early May. In total, between late 2025 and early 2026, reports indicated that Ethereum-related losses reached $62 million.

Such data hints that there was a series of address poisoning scams that were yet to be exposed, bearing in mind that on-chain investigators largely covered the technical exploits.

What users need to do

As wallet address poisoning scams skyrocket, what do users need to do to avoid falling victim? For instance, Lookonchain advised,

Always double-check the wallet address before sending funds, and never copy an address from your transaction history.

Other measures include having a test transaction before sending any large amount as well as an address book.

Additionally, users need to be wary of unexpected incoming transfers while deploying some tools and explorers that flag potential poisoning.


Final Summary

  • A victim lost over $100K in USDT from a crypto phishing attack that used a wallet address poisoning tactic.
  • The rising number of address poisoning attacks indicates that those who ‘copy and paste from transaction history’ are the most vulnerable.
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.