Skip to content
Ghostex.ai
5 AI agents · 24/7 Launch swap
Launch swap
5 AI agents · 24/7 No humans. No KYC. Fully automated.

Security12 min read

Address poisoning: check a crypto address before sending

By the Ghostex team

A look-alike address in your history, a swapped clipboard or a doctored QR code all end the same way: coins sent to someone else, with no way back. Here is how each route works on Ethereum, Tron and Bitcoin, and one check that catches all three.

  • Security
  • Addresses

Short answer: address poisoning is a scam in which an attacker creates an address that starts and ends with the same characters as one you use, then makes it appear in your wallet's transaction history with a zero-value, dust or fake-token transfer. If you later copy that familiar-looking address from your history, the coins go to the attacker, and a blockchain transfer cannot be reversed. The defence is a habit: take every address from its original source, such as the recipient's receive screen, your order page or an address-book entry you verified, and compare the full address, block by block, after you paste it.

Ghostex.ai guide cover: the title “Address poisoning: check a crypto address before sending” on a dark violet card with the Ghostex.ai logo, topic Security, 12 min read

How does address poisoning work?

The attack exploits a display shortcut. Wallets and explorers shorten addresses to something like 0x1a2b…9f3e, so people learn to recognise an address by its ends. An attacker who sees you pay an address on a public chain runs a vanity generator until it produces an address with the same start and end, then puts it in front of you. A Carnegie Mellon study of Ethereum and BNB Smart Chain describes three ways it gets into your history:

  • Tiny transfers. The look-alike sends you a small amount of the real token, so it shows up as a recent counterparty.
  • Zero-value transfers. The transferFrom function of many tokens accepts a transfer of zero tokens without the owner's approval, because nothing moves. The result is an entry showing 0 tokens going from your address to the look-alike, as if you had paid it.
  • Counterfeit tokens. The attacker deploys a token with the same name and symbol as, say, USDT, and makes its contract report transfers between your address and the look-alike.

None of these moves your money; the entry is bait that only costs you if you copy it. The same study counted 270 million attack transfers aimed at 17 million victims between July 2022 and June 2024, and at least 6,633 successful incidents with losses of at least $83.8 million.

Timing is part of the trick. Bots react to your own transfers, so the look-alike often lands minutes after a real payment, right next to it. In December 2025 a user sent a small USDT test transfer, a look-alike appeared in the history, and the main transfer of almost $50 million went to the copied look-alike.

Poisoning, clipboard malware or a swapped QR code?

Poisoning is one of three routes to the wrong address, and each is caught in a different place:

Three ways the wrong address reaches your wallet
RouteHow the wrong address gets inHow close it looksWhat catches it
History poisoningA zero-value, dust or fake-token transfer puts a look-alike in your transaction list, and you copy it laterSame start and end; the most capable group in the Carnegie Mellon data matched 20 charactersNever copying from history; comparing the full address with its source
Clipboard malwareMalware on your device rewrites the clipboard between copy and pasteOften barely: the clipper Microsoft analysed kept only the first two characters of a legacy Bitcoin or Tron addressComparing the pasted address with the source; the screen of a hardware wallet
Swapped QR codeThe code holds an attacker's address: a sticker over a printed code, an edited screenshot, a tampered pageIt need not look close, because you never read it before scanningComparing the address your wallet decoded with the text address from the source

A clipboard swap means an infected device: the Crypto Clipper campaign Microsoft described in June 2026 also steals seed phrases that pass through the clipboard. And the FBI warned in 2022 that criminals tamper with both digital and physical QR codes to redirect payments. A QR code is only as trustworthy as the place you got it from.

What does poisoning look like on Ethereum, Tron and Bitcoin?

The bait, and the clues on an explorer, differ by network.

Ethereum and other EVM chains

Addresses are 0x plus 40 hexadecimal characters. Poisoning shows up as transfers of 0 USDT or USDC, as dust of a real token, or as a token with the right name and the wrong contract. Etherscan hides zero-value transfers and tokens with a poor reputation by default, so your wallet app may list entries the explorer does not. The clues:

  • The sender is not you. If the token line says 0 USDT went from your address to someone, but the transaction's From field, the account that signed it and paid the fee, is a stranger, you did not send it.
  • The contract is wrong. Tether lists USDT on Ethereum at 0xdac17f958d2ee523a2206206994597c13d831ec7. A "USDT" from any other contract is not Tether's.
  • Your wallet warns you. MetaMask shows a blocking warning when an address matches the first and last four characters of one you have used but differs in the middle.

Tron (USDT TRC20)

Tron addresses are 34 characters in Base58 and all start with T, so the first character tells you nothing. Fees are low, so poisoning goes out in bulk: TRM Labs traced one dusting address that made about 920 outgoing transactions of TRX dust, and in the case it described the look-alike shared only the first and last two characters with the intended recipient. The clues: Tether lists USDT on Tron at TR7NHqjeKQxGTCi8q8ZY4pL8otSzgjLj6t, so a "USDT" from any other contract is a different token; and TRONSCAN flags suspicious contracts with badges that the TRON developer documentation tells users to heed.

Bitcoin

Bitcoin has no tokens and no zero-value transfers, so a poisoner must send real bitcoin from the look-alike and pay a fee every time. That makes it rarer, not absent. Jameson Lopp scanned the chain for transactions whose input and output addresses share their first and last four characters, and found nearly 48,000 between July 2023 and January 2025, costing the senders about 0.29 BTC. He confirmed one theft, of 0.1 BTC. The clue is an unexpected tiny payment from an address that shares the start and end of one you use, including your own. Every native SegWit address starts with bc1q (see Bitcoin address types), so a display like bc1qr9…2wua0h shows only eight characters that actually vary. Do not spend the dust: combined with your other coins in one transaction, it links them publicly.

A pre-send check that catches look-alikes

Checksums will not save you. They exist to catch typos: the Bech32 checksum detects any error affecting up to four characters, and the EIP-55 checksum lets a mistyped checksummed Ethereum address pass only 0.0247% of the time. A look-alike is a different, valid address with its own valid checksum, so every format check passes. Protection comes from where you take the address and how you compare it:

  1. Take the address from its source, every time: the recipient's receive screen, an invoice or order page, or an address-book entry you verified when you saved it. Transaction history, explorer lists and forwarded screenshots are not sources.
  2. Paste first, then compare the full address in blocks of four, from the first character to the last. Checking what sits in the send field catches a clipboard swap as well as a wrong copy.
  3. Save verified addresses in an address book, label them, and pick from the book afterwards. Exchanges offer the same idea as withdrawal allowlists.
  4. Read the hardware wallet screen. It shows the address the device will sign for, which defeats malware on your computer, but it cannot tell a look-alike you chose from the real one. Compare it with the source too.

Here is the block check on a real pair from Lopp's scan, where the look-alike imitated the victim's own address:

A look-alike Bitcoin address, block by block
AddressIn blocks of four
Genuinebc1q r9xk xanf stzq pfd5 ce0t 3evw c45p nmsr 2wua 0h
Look-alikebc1q r9wu w4zk jfle t80l r9cr 5ec8 620c 4fg5 2wua 0h
As a wallet shortens bothbc1qr9…2wua0h

The shortened forms are identical. Blocks 2 to 9 all differ, and block 2 gives it away at once: r9xk against r9wu.

Why a small test deposit backfires on a swap

"Send a small test first" is standard advice for wallet-to-wallet transfers. On a swap order it works against you. On Ghostex, every order has its own page with a deposit address and an exact amount. Networks that use a memo or tag get one on the order, and it is mandatory. Everywhere else, the exact amount is what ties a deposit to your order, so the order page asks for exactly that amount in one transaction and states that any other amount is refunded automatically. A test deposit runs into that rule:

  • It does not match the order. It is refunded to your refund address or to the address you paid from, minus the network cost of sending it back. On a memo network it may instead be executed at the market rate, as your order page shows. If you paid from an exchange account, crediting you is up to the exchange. A test worth less than about $10 is also below the minimum.
  • The clock keeps running. A fixed rate holds for 30 minutes from order creation, and the deposit must be sent inside that window. Ghostex waits for 2 confirmations on a Bitcoin deposit, about 20 minutes on average, so waiting for a Bitcoin test to confirm before sending the rest uses up most of it.
  • One deposit per order. Under section 9 of the Terms, additional or partial deposits may fall outside the fixed rate and be refunded instead of exchanged. See why to send the exact quoted amount.
  • It alerts the bots. A small transfer to a new address is exactly what poisoning bots react to.

Treat the order page as the source of truth instead. Copy the deposit address with its copy button or scan its QR code, then compare what your wallet shows with the order page, which prints the address in blocks of four. Check the amount, and the memo if one is shown. On a USDT (TRC20) to BTC swap, that means a T address on the order page, and your own bc1 address checked before you create the order. Never reuse a past order's details from your history. To try the service first, make a separate small order with its own quote, as in our checklist for judging no-KYC exchanges, then a new order for the full amount.

Checking your payout and refund addresses

A payout is final once broadcast: under section 11 of the Terms, neither Ghostex nor anyone else can cancel, recall or redirect it. So the address you receive to needs the same care:

  • Copy it from the receive screen of the wallet that will hold the coins, not from an old transaction. Poisoners imitate your own addresses too, as in Lopp's example.
  • Know what the form checks. The Ghostex form accepts every standard address format of the coin you receive, checks the format and, where the address has one, the checksum, and flags an address that looks like another network's. That catches typos, not look-alikes: as section 10 of the Terms puts it, a valid format does not prove the address is yours.
  • Add a memo or tag only when the destination needs one, typically an exchange account that shows one on its deposit page. See how memos and destination tags work. When receiving to an exchange, take the address and memo from its deposit page each time; for the reverse trip, see withdrawing from an exchange to your wallet.
  • A refund address must be yours and on the same network as your deposit. Ghostex requires one only for coins that hide the sender (Monero, Lightning, shielded Zcash). Those are receive-only today, so it is optional on every current pair, and strongly recommended when you pay from an exchange account.

Already sent to a poisoned address?

The transfer is final: the look-alike's key belongs to the attacker, and no wallet or swap service can pull the coins back. What you can still do:

  1. Collect the evidence: the transaction hash, the address you meant to use, the look-alike, and the poisoning transfer that planted it.
  2. If it was a stablecoin, report it to the police at once. Issuers can freeze tokens held at an address, and Tether describes freezing stolen USDT in cooperation with law enforcement. That only helps while the tokens are still there; in the December 2025 case they were swapped for ether.
  3. If a clipboard swap caused it, stop using that device for crypto and, from a clean device, move what is left to a new wallet with a new seed phrase.
  4. Do not count on the attacker. A victim who lost 1,155 WBTC, about $68 million, in May 2024 got most of it back by negotiating, which is remembered because it is the exception.

If the coins were meant for a Ghostex order, a deposit sent to a look-alike never reaches it: the order expires and nothing is charged, but Ghostex cannot retrieve coins from an address it does not control. If you are unsure what happened, write to support@ghostex.ai with your order ID.

How to spot a recovery scam

A public post about a loss attracts fake recovery services: the FBI reported over $9.9 million lost to fictitious law firms offering recovery between February 2023 and February 2024. Stop if someone:

  • contacts you first, or answers your public post within minutes;
  • promises to reverse, trace and recover, or hack back a confirmed transaction;
  • wants a fee, tax or "unlock deposit" up front (law enforcement does not charge victims to investigate);
  • asks for your seed phrase or private key, or to connect your wallet to a site (Ghostex will never ask for your seed phrase, private keys or passwords);
  • claims to work with the FBI or another government agency.

The same signs apply to other lost-funds cases, such as USDT sent on the wrong network.

This guide is general information about checking crypto addresses, not financial or legal advice. Product facts follow the Terms and the Privacy policy.

FAQ

Address safety questions

Can address poisoning take funds from my wallet?

No. A poisoning transfer cannot move your funds, not even the zero-value kind that appears to come from you. It only adds an entry to your history. The loss happens when you copy that entry and send to it. Ignore the entry, and do not interact with unknown tokens that arrive with it.

Is it enough to check the first and last characters?

No. Look-alikes are generated to match exactly those characters, and the most capable group in a Carnegie Mellon study matched 20 of them. Compare the full address, block by block, with its source.

Should I send a small test transaction first?

Between your own wallets it can confirm a route, but copy the address for the main transfer from its source again, not from the test in your history. On a swap order, do not send a test to the deposit address: it will not match the order’s exact amount and is refunded, minus network costs (on a memo network it may instead be executed at the market rate, as your order page shows). Make a separate small order instead.

Does a hardware wallet protect against address poisoning?

Partly. Its screen shows the address it will actually sign for, which defeats malware that swaps the address on your computer. It cannot know that you chose a look-alike, so compare the device screen with the original source.

Does Ghostex check that my payout address is mine?

No. The form checks the address format and checksum for the coin you receive, which catches typos. A valid format does not prove ownership, and a payout is final once broadcast, so compare the full address with your wallet’s receive screen before you create the order.

Five AI agents24/7

Check every block, then swap

Paste your payout address from your wallet's receive screen, then copy the deposit address and exact amount from your order page and compare both in full before you send. The flat 0.48% fee is already in the quote, and Ghostex covers the network fee on the payout.