Address poisoning on Ethereum: $76 million stolen in a year
Scammers fill Ethereum wallet histories with fake addresses and wait for someone to copy one. We went through a year of transfers to see how often it works and where the stolen money ends up.
- $76.1M
- $50M
- 342
- 80%
- 4.5 days
- 28.3%
01 · The long waitEleven months, one mistake
Sometime in late 2020, one Ethereum wallet started paying another. Over the following year 0xd674…a7da sent 48,235 ether across thirteen transactions, always to the same destination, 0x6d90cc8c…2e48. Then the ether payments stopped. The two kept dealing in dollar tokens, but no ether passed between them for four years.
On 3 October 2025, a stranger sent that first wallet one ten-millionth of an ether. Not enough to buy anything. Not enough to notice.
The stranger's address was 0x6d9052b2…2e48. It started 0x6d90 and finished 2e48.
So did the address of the business partner. Everything in between was different.
Seven weeks later the stranger sent another sliver of a coin, a billionth this time. Then again the day before the theft. On the afternoon of 30 January 2026, the owner of the first wallet paid its partner in ether for the first time since 2021. The 4,556 ether went to the stranger instead. At that day's price it was worth $12,445,768.
The ether dust was only the last part of the setup. Since February 2025 the same stranger had been planting fake dollar transfers in the wallet's history, made to look as if the wallet had sent them. Thirty-three minutes after the theft the money moved to a fresh wallet, and the next day all of it went into Tornado Cash, a mixer that hides where coins go.
That scam has a name: address poisoning. The January theft was the second largest we found in a year of Ethereum. The largest came six weeks earlier, when a trader lost $50 million in one payment.
Bitquery indexes every transaction on Ethereum, so we went looking for the rest. In the twelve months we checked, 1,635 people sent real money to a fake address and lost $76.1 million between them. Most lost a few hundred dollars. Four lost more than a million each.
We got this count wrong twice before we got it right. Our first pass missed every victim who paid in ether. The version we published in August missed the largest theft of the year, because we asked the fake to match too many characters.
Correction, 11 October 2026: the first version of this article counted a fake only if it matched four characters at each end of the real address. That missed hundreds of thefts, including the largest of the year, which went to a fake that matched only the first three characters. Every figure here now includes them. The first version also made three smaller errors. It counted some fake addresses more than once. It said the January victim and its partner stopped dealing for four years, when only the ether payments stopped. And it said the January thief swapped its ether for DAI, when it put the ether into Tornado Cash.
02 · The trickWhat is address poisoning?
An Ethereum address is a long string of letters and numbers, like 0x6d90cc8ce83b6d0acf634ed45d4bcc37eddd2e48. Nobody reads all of it. Wallet apps show the first few characters and the last few, and people check those.
Address poisoning is a scam built on that habit. The scammer makes an address with the same ends as one you use, gets it into your wallet history, and waits for you to copy it by mistake.
Making the fake is cheap. Scammers run a vanity address generator, which tries random keys until one gives the right ends. Four characters at each end takes about 43 seconds on one gaming graphics card. Three at the front and four at the back takes about three seconds.
Getting it into your history is just as easy, because anyone can add a line to it. There are two ways. The scammer can send you dust, a tiny amount of a real coin. Or a scam token contract can report a transfer you never made, so your history shows you "sending" money to the fake. That second trick is often a zero-value transfer: a transfer of zero tokens that costs nothing but still shows up.
03 · The scaleHow many Ethereum wallets get poisoned?
We went through every token and ether transfer on Ethereum in the year to 31 July 2026, about 1.28 billion of them. We looked for one pattern: a fake address showing up in a wallet's history, matching an address that wallet had really paid before.
The match has to happen inside one wallet's own history. Across all of Ethereum, two addresses that share a few characters at each end are common. Inside a list of the few dozen addresses a person pays, a stranger matching one of them by luck is rare.
| Twelve months to 31 July 2026 | |
|---|---|
| Wallets targeted | 7,997,367 |
| Times a fake was aimed at a wallet | 66,966,004 |
| Fake addresses used | about 47.1 million, estimated from a sample |
| People who sent real money to a fake | 1,635 |
| Measured stolen | $76,139,215, a floor, not a total |
| Success rate | 0.020%, one wallet in 4,891 |
One targeted wallet in 4,891 paid a fake. That looks like a failing scam, but the costs say otherwise.
An attempt costs the scammer about $1.86 in network fees, and one transaction can plant hundreds of fake transfers at once. Over the year scammers spent about $19.2 million in fees and took a measured $76.1 million, about four times as much. Our theft figure is a floor and their cost figure is not, so the real margin is wider still. The same scam runs on Solana, where we found 4.5 million poisoned wallets in eleven months.
04 · DeliveryHow does an address poisoning attack reach you?
The fake send. On 9 August 2026, wallet 0xb83f1c98…f50e sent a test payment of about 115 USDT to check an address. Twelve seconds later a scam token reported a transfer of exactly the same amount from the victim to a fake. Thirteen minutes after that, the victim sent $39,889 to the fake.
The test payment is what made the bait. A scammer cannot copy a payment that was never made.
The safety ritual is what creates the bait. You cannot mirror a payment that was never made.
9 August 2026: twelve seconds between the real transfer and its forgery
The largest theft of the year followed the same script. Since December 2023, wallet 0xcb80784e…0819 had paid 0xbaf4b1af…f8b5 the same way every time: a 50 USDT test, then the real sum. It did that fourteen times and moved about $400 million. On 19 December it took the money out of Binance and sent the usual test.
Three minutes after the test, a transfer of zero USDT to the fake 0xbaff2f13…f8b5 appeared in the victim's history. The victim had not sent it: the scammer's contract set it off. Ten minutes later the fake sent the victim half a cent of real Tether. Then the victim sent the whole 49,999,950 USDT to the fake.
The December fake matched only the first three characters. Our August count asked for four at each end, so it never saw the theft.
The dust send. This one is cruder, and it took the January $12.4 million. The fake sends the victim a worthless sliver of a coin, which lands in the history as an incoming payment and waits. More than half of all thefts, 908 of 1,697, came through incoming dust or tokens alone. A study that looks only at what victims seem to have sent misses half the crime.
05 · Fake tokensWhat are fake tokens and zero-value transfers?
Fake sends need tokens that look real, and there is now a steady supply of them. We found 38,691 scam token contracts copying the names of major coins, behind more than a hundred million transfers in the year.
The busiest is 0x647a139b…acb8, a fake Tether whose name reads USDT on any screen. Three of its four letters are not plain English letters: an accented U, a Cyrillic S and a Cyrillic T. It reached more than a million addresses in under two months.
Others are quieter. 0xe75ae445…e377 spells USDT correctly and simply is not Tether. Some hide invisible characters inside the name. In a wallet's history they look exactly like the real coin.
Add zero-value transfers to the fake tokens and 15.45 percent of all token transfers on Ethereum in the year carried the marks of poisoning. Some of that is innocent, because some apps send zero-value transfers for their own reasons. Still, more than one token transfer in seven now exists to mislead somebody.
06 · The missWhat did our August count miss?
Our first pass filtered to token transfers, since fake tokens are the signature trick. That cut out every victim who paid in plain ether. Ether is the one asset on Ethereum nobody can fake, so it was the safest thing to count, and it was the only thing we were not counting. Adding it took the count from 792 thefts to 1,355.
The August version still had a blind spot, and the news would have shown it to us. A trader lost 49,999,950 USDT to a fake on 19 December (UTC), a theft widely reported at the time, and it was not in our total. We had asked a fake to match four characters at each end, because most fakes do. The December fake matched three at the front and four at the back.
So we ran the whole count again, this time testing for a three-character match at each end. That found 342 more thefts worth $53.9 million. Almost all the new ones match exactly three at the front, and most match four, five or six at the back.
Three characters is a weaker test, so we checked it against luck. We ran the same count on characters from the middle of each address. Scammers have no reason to copy those, so any match there is chance. In wallets that had paid 1,000 different addresses or fewer, the middle test found no thefts at all. In bigger wallets, such as exchanges and big contracts, it found nearly as many as the real test, so for those we kept the four-character rule. One $16 million "theft" the looser rule would have counted was a Sky (formerly MakerDAO) reserve contract paying a swap router 854 times.
With the December theft counted, ether's share of the money falls from well over half in the August count to a fifth, because that theft was paid in Tether.
07 · The lossesWho loses money, and how much?
The median theft is $300, the one in the middle when you line them all up. Sixty-five percent of thefts were under $1,000.
The two largest thefts, December and January, are 82 percent of all the money stolen. Take them out and the other 1,695 add up to $13.7 million. This is a crime against ordinary wallets with two huge outliers on top.
08 · The clockHow long does the bait wait?
The cases that make the news are fast. The $39,889 loss took thirteen minutes, and the $50 million one took twenty-three. Most thefts are slow.
This decides which defence works. Most wallets bet on a warning when you sign, a pop-up that interrupts the payment. That catches about one theft in six. The fake usually sits in the victim's history for days before anyone copies it, so cleaning up the history protects more people than interrupting the moment.
The fakes themselves often arrive fast. In a quarter of thefts the fake appeared within ten minutes of the victim's first real payment to the address it copies. Bots watch the chain and make a matching fake on the spot.
09 · The exitWhere does the stolen money go?
The two largest thefts ended up in the same place: Tornado Cash, within a day. About $61 million went in, 80 percent of all the money stolen in the year.
The December thief started by getting out of Tether. Tether can freeze USDT at any address. DAI is a stablecoin nobody can freeze. Twenty-eight minutes after the theft the thief swapped all 49,999,950 USDT for DAI through MetaMask's swap service. A second wallet then sold the DAI for ether in pieces of one million, and that evening two wallets on the path put 16,470 ether into the mixer. Other poisoners even forged copies of the thief's DAI transfer, aimed at lookalikes of the second wallet. The thief was now a target too.
The January thief skipped the swap. All 4,556 ether went into the mixer in 56 deposits the day after the theft. If you have lost money this way, Bitquery's investigation services can trace it for you.
Smaller thefts leave a messier trail. We followed the money three steps out from every thief wallet, stopping at any address that takes money from more than a hundred others, which is a service rather than a person. Most of it went into swaps. Some reached exchange accounts we can name, through our address labels. Each figure below is a floor of money sent on from thief wallets. It says nothing about how the exchanges behaved.
| Exchange | At least |
|---|---|
| Bybit | $304,892 |
| OKX | $259,570 |
| HitBTC | $139,320 |
| Binance | $119,304 |
| Kraken | $73,001 |
| Revolut | $57,269 |
| FixedFloat | $29,196 |
| KuCoin | $15,403 |
Trace a poisoning wallet in plain English
Every step in this section came out of the same public dataset, queried conversationally through Bitquery MCP. Point it at a suspicious address and ask where the money went, which addresses look like it, or who paid for its gas.
10 · FreezesDoes anyone freeze the stolen money?
Tether can freeze USDT, and it did so once. Over twelve months it blacklisted one of the 1,691 thief addresses we found, within a day of the theft. None of the others were touched. When Tether acts it can be quick, but the December thief was out of Tether within half an hour.
11 · The crewsWho is behind the attacks?
Eight million targeted wallets and 47 million fake addresses suggest a crowd. The money for gas says otherwise.
Fake addresses need ether to pay network fees, called gas, and that ether comes from somewhere. Ninety-seven funding wallets paid the fees for more than one thief address. The four largest sit behind 542 of the 1,691 thief addresses we found.
| Gas funder | Thief addresses funded |
|---|---|
0x1676973d…dcc8 | 228 |
0x68f473bb…e23e | 174 |
0x8efe1836…a778 | 95 |
0x0c0755e5…85d3 | 48 |
The August case shows the shape of it. Four scam tokens raced for that victim within fourteen minutes, which looks like four rival crews. The gas money says two. The token that took the $39,889, 0x647a139b…acb8, and a second one, 0x5b40f9e4…2437, draw their fees from the same funding wallet, one of the four largest on the chain. A third draws from another.
The December theft had a crew behind it too. The day before, a fake with the same three-and-four match took $205,900 of WBTC from another wallet. That thief swapped the coins for DAI through the same MetaMask service and sent the DAI to a holding wallet. The next afternoon, the holding wallet paid the gas for the wallet selling the $50 million of DAI, two minutes before the sales began.
The money trail points to one crew behind both thefts, a day apart, using the same recipe.
12 · DefenceHow to avoid address poisoning
Never copy an address out of your transaction history. It is the one field on your screen a scammer can write to. Keep the addresses you pay in your wallet's address book or a password manager, where nobody else can add lines.
If you send a test payment, copy the main payment's address from wherever you first checked it. Never take it from the record the test made, because the test is what gives a scammer something to copy.
Check the middle of the address as well as the ends. Every theft we found matched at least three characters at each end, and 57 percent matched exactly four and four. Three at the front was enough for the largest theft of the year.
Treat your own exchange deposit address as the risky one. That is where 28.3 percent of these thefts landed, a share we could measure because those addresses carry Bitquery address labels. Be careful, too, when you pay an old contact in a new way. The January victim paid its partner in dollar tokens many times a year, but had not sent it ether since 2021. When it did, the scammer's ether dust from the day before was sitting in its history.
If you build wallets, hide the bait instead of warning about it. With a median of 4.5 days from bait to theft, hiding zero-value transfers, unknown tokens and dust will protect more people than a pop-up at signing. Wallet and exchange teams can screen incoming transfers against address labels and risk scores before showing them to anyone.
13 · MethodHow we did this
Written by Bitquery Research with AI tools; every figure was checked against the raw data. We read every Ethereum transfer in the twelve months to the end of July 2026 in Bitquery's full-history archive of the chain.
A theft needed four things. A fake address reached the victim's history through dust or a fake transfer. It copied an address the victim had really paid before. The victim had never paid the fake before. Then real money went to the fake. Only coins nobody can forge counted as real money: ether, USDT, USDC, DAI, WETH and WBTC.
The fake had to match at least three characters at each end of the real address. For wallets that had paid more than 1,000 different addresses in the previous two years, we asked for four, because a shorter match there happens by luck. We checked that rule by running the same count on characters from the middle of each address, which found no thefts below that size.
For this correction we ran the full count again. Under the old four-character rule it found the same 1,355 thefts as in August. We then checked 73 thefts against raw records and a public Ethereum node: every new theft over $10,000, thirty smaller new ones picked at random and ten from August. All 73 passed, and a separate re-count of every headline figure matched to the cent.
14 · EvidenceEvery address and transaction cited
Readers who want to check the work can paste any of these into a block explorer. We publish them as text rather than links because explorer coverage of older Ethereum history varies, and a link that returns an empty page is worse than no link at all.
| The January theft | Address / transaction hash |
|---|---|
| Victim | 0xd6741220a947941bf290799811fcdcea8ae4a7da |
| Real counterparty, paid 48,235 ETH in 2020–21 and dollar tokens since | 0x6d90cc8ce83b6d0acf634ed45d4bcc37eddd2e48 |
| Lookalike that was paid instead | 0x6d9052b2df589de00324127fe2707eb34e592e48 |
| Sweep wallet, 33 minutes later | 0x49a21fc945312c6fb4f8c6c4d224e74a5b96e9df |
| First forged transfer to the lookalike, 25 Feb 2025 | 0xd460826223059f49244c12505d79490f4f694b628583708b51d68b3e19c347b0 |
| First ether dust, 3 Oct 2025 | 0x2f5994408da597dd47e7a259ce0381795e625a5a3338821f5a5fe87583e9e7f1 |
| Dust ping, 29 Jan 2026 | 0xb2e0b6573641ae1800faf4782c2526ab97e7df3df7281557c87e099025f4e0fd |
| The theft, 4,556 ETH, 30 Jan 2026 16:10:59 | 0x7facade9d4731a639c4f31e84f5dfef0ddce8d2dc4d8a4399b72cd66817a8ac7 |
| The sweep, 16:43:47 | 0x253ca9ded3b39ca3484c3a605087c06ecdb8fd6bbd910b84a882e85c8d8b8716 |
| First of 56 deposits into Tornado Cash, 31 Jan 2026 07:57:59 | 0x09a37e37183cfb730d5e0afebed25a8759b4907dcc0ccccc55548e12120ceca1 |
| The December theft (times UTC) | Address / transaction hash |
|---|---|
| Victim | 0xcb80784ef74c98a89b6ab8d96ebe890859600819 |
| Real address, paid about $400 million since December 2023 | 0xbaf4b1af7e3b560d937da0458514552b6495f8b5 |
| Lookalike that was paid instead | 0xbaff2f13638c04b10f8119760b2d2ae86b08f8b5 |
| Test transfer, 50 USDT, 19 Dec 2025 15:06:47 | 0x7f5d895ce0eca61d4e3230b7d3471c60c7dc507e1e400e1b5c449e54cfca9a98 |
| Zero-USDT transfer to the lookalike, 15:10:11 | 0xfc1ea6df1228546a9634dd26cf1bf602f1f7fcb0540752c8c95def0743c091be |
| Half a cent of USDT from the lookalike, 15:20:35 | 0x9780f38b63f761ccfb8fde3b2c27630646baace1f06b2959a3874849937288bd |
| The theft, 49,999,950 USDT, 15:32:59 | 0xc0514a795f065fce8a3e1238a1ba480e8a792d45f6431ee4ba8d800bedd86a0f |
| Swap to 49,533,438 DAI, 16:01:23 | 0x40c3071839bcfba2623fe9e419bcaaf667b6570489d04d194f106282202de077 |
| DAI moved to the second wallet, 16:04:47 | 0x9129e55ada6438d02777591abc469742e3fd723107285dd6df1868037da8f05f |
| Same crew: 2.38 WBTC theft, 18 Dec 2025 20:56:59 | 0xfda53b40c3b3ed13dbacc0df8f81141f6dde7c86164a013ae7ef24d883554a11 |
| Its 200,797 DAI to the holding wallet, 22:53:23 | 0xde0efa6fe7abc71f78b095befd15fab2af7be385160e42b0448ed9da67f5b5c7 |
| Holding wallet pays ether to the second wallet, 19 Dec 16:41:23 | 0xe9851d3d621d59a2156653549c365885daf0a5b7a56eb13fda3015fc03191ebf |
| First deposit into the mixer from 0x9da0…7c9b, 18:00:59 | 0x2eecee5176ce9cd018768ac3e83ee0e0b88df818ad6c47ee705df00dff32ffde |
| First deposit into the mixer from 0x7a1b…de76, 18:05:35 | 0xbf6c9652c17515e6d4fa0a169029233d6feba268e29e4c4e61fa992a40cd663b |
| The August case and the crews | Address / transaction hash |
|---|---|
| Victim | 0xb83f1c98b6d799f8ec56a002f2c0a2c343a0f50e |
| Real address | 0x053dba7292957341779cb0e9aae1aa7b139ada3a |
| Lookalike that was paid | 0x053dc459bade1baf76aed6e8630823f8392fda3a |
| Test transfer, 115.147641 USDT | 0x9f8f6ecc7b3a2f294818dcb504b1667d44e1bfec4288bb8174c6740d9851c33d |
| The forgery, 12 seconds later: 145 transfers in one transaction | 0xf84dacfeb3a92ae3291120d954b86d89932fe31702103754cad4f8e8ac41a10d |
| The loss, 39,889.952535 USDT | 0x374076fa28ed745227c28f42c5054a0bcd024c51ad7a41c17d52e7c6c24980eb |
| Counterfeit USDT, 1,057,569 addresses touched | 0x647a139b234dcf9f91b1b749993604e715d3acb8 |
| Counterfeit USDT, same crew | 0x5b40f9e45655ebf058e253444c90019a61012437 |
| Counterfeit USDT, ASCII clone | 0xe75ae445601fcb52fb8c167b6a4131d54d37e377 |
| Gas funder, 228 thief wallets | 0x1676973d3a8848cc1d02f795c5bf4682af34dcc8 |
| Gas funder, 174 | 0x68f473bb27e7e53e61891dd1d059fb8e593de23e |
| Gas funder, 95 | 0x8efe183664c5f01a507a76de2a5979cdcd3aa778 |
| Gas funder, 48 | 0x0c0755e56f0d10e4d8e19284fc0632ed7f3d85d3 |
FAQ
What is address poisoning?
Address poisoning is a crypto scam in which someone puts a fake address that looks like one you have paid into your wallet history. They send you dust or fake a transfer from you to that address. If you later copy the fake from your history, your money goes to the scammer.
How does an address poisoning attack work?
The scammer makes an address with the same first and last characters as one you use, then gets it into your history. Most wallets show only the ends of an address, so the fake looks right. The attack works when you copy the address from your history instead of from the source.
What is a zero-value token transfer?
It is a transfer of zero tokens. It moves no money, but it still shows up in your wallet history. Scammers use it to make it look as if you sent something to their fake address, so the fake sits next to your real payments.
How much money has address poisoning stolen on Ethereum?
In the year to July 2026 we measured $76.1 million taken from 1,635 people. That is a floor: thefts we cannot match to a fake in the victim's own history are not counted.
What was the $50 million address poisoning theft?
In December 2025 a trader sent a small test payment to an address it had paid many times, then sent $50 million in USDT to a fake that copied the first three and last four characters. The thief swapped it to DAI within half an hour, and most of it went into Tornado Cash that evening.
Does a test transaction protect you from address poisoning?
No. A test payment shows that one address works, but the scammer can copy it within seconds. If you then copy the address from your history for the main payment, you may pick the fake.
How do I avoid address poisoning?
Copy addresses from your address book or the original source, never from your transaction history. Read the characters in the middle too. Treat your own exchange deposit address with extra care, and hide dust and unknown tokens if your wallet allows it.
This analysis covers Ethereum mainnet only. Tron carries more counterfeit-Tether poisoning than Ethereum does, so these figures are not a cross-chain total.
Loss figures are floors. A victim who copied an address from an exchange's website rather than from their transaction history leaves no on-chain trace for us to match against, and is structurally invisible to this method.
One theft accounts for 65.7 percent of measured losses, and the two largest for 82 percent. Aggregate figures should always be read alongside the $300 median and the $13.7 million total excluding those two.
This article was corrected on 11 October 2026. The first version, published on 11 August 2026, required four matching characters at each end of an address and missed 342 thefts worth $53.9 million, including the largest. It also counted forged copies of a DAI transfer as real DAI, and its money trail dropped later payments into a service it had already seen, which hid the January Tornado Cash deposits.
The Tornado Cash figures for December count deposits from two wallets on the path of the stolen money; money that reached the mixer by other routes is not counted. Exchange figures refer to addresses labelled as those venues in our address-label dataset, and are mostly hot-wallet rather than deposit-address labels; they are not statements about the conduct of the companies named.
This article is provided for informational and educational purposes only and reflects analysis of publicly available on-chain data as of the dates indicated. It does not constitute legal, financial, compliance, or investment advice, and nothing in it is a recommendation to buy, sell, or hold any token or asset.
The findings describe transfer patterns observed in Ethereum data, matched by the rules described in the article to identify poisoning attempts and the payments that followed them. Loss figures, the identification of any address as a poisoner or a victim, and the routing of funds afterwards are inferences from transaction structure and address labels, and may be incomplete or incorrect. Blockchain addresses are pseudonymous, and a transaction between two addresses does not by itself establish the identity, intent, or knowledge of any party.
The words poisoner, thief, and attacker refer to whoever controlled the addresses described, and nothing here identifies or asserts the identity of any person. References to any named exchange, wallet, or service describe address labels and on-chain flows, and are not assertions that any named entity knowingly facilitated or participated in unlawful conduct or is legally liable for any loss.
Nothing herein should be relied upon as a definitive determination of fact. Readers should conduct their own independent verification before taking any action. The authors and publisher accept no liability for any loss or damage arising from reliance on this material. All trademarks and company names are the property of their respective owners.
Run this kind of analysis on your own data
Every figure in this investigation came from Bitquery's Ethereum archive: full history, every transfer, every token contract, with address labels attached. The same data powers exchange compliance desks and wallet risk screening.