Address poisoning on Solana: the lookalike waiting in your history
Scammers on Solana answer payments within seconds with a near-perfect fake of the address you just paid. We went through 11 months of the chain's transfers to see how often the trap works and where the money goes.
- 4.5 million
- 1 in 2,750
- 40%
- 28%
- 19 of 20
01 · A payment to the wrong placeThe address had the right ends
Open a crypto wallet app and look at your recent payments. Next to a payment you made, there may be one you never made. It is worth less than a cent, and it comes from an address that looks like one you pay often. It is there so that next time, you copy the wrong one.
On the evening of 3 December last year, a Solana wallet sent SOL to an address it had paid before. SOL is Solana's own coin. The address belonged to Crypto.com, which gives each customer one for topping up their account. Nine seconds later, someone sent a little over one SOL to a brand-new address. Two seconds after that, the new address sent the wallet a hundred-thousandth of a SOL, a fraction of a cent. The new address started with HJ7f and ended with rYEz, the same four characters at each end as the Crypto.com one.
Less than an hour later, the wallet sent $166,330 in SOL to the lookalike. Seven and a half hours after that, the money left it. Within 35 seconds it had hopped through ten more fresh wallets.
What happened to that wallet has a name: address poisoning. The tiny transfer is called dust, which is why the trick is also known as a dusting attack. Bitquery records every transfer on Solana, so we went through all of them from 30 October 2025 to 7 October 2026 and looked for the pattern: a real payment, then dust from an address that copies the ends of the one just paid. Then we followed the people who paid a fake, and their money. Losses count for wallets poisoned before mid-July, so that each had three months in which to make the mistake.
02 · The trickWhat is address poisoning?
A Solana address is a long string of letters and numbers. Most wallet apps show only the first few and the last few, because nobody reads the middle. And many people copy an address from their recent payments instead of going back to the exchange or the person who gave it to them.
Address poisoning uses both habits. Scammers run bots that watch the chain for payments. When one lands, the bot creates an address with the same first and last characters as the one that was paid, sends the payer a little dust from it, and waits. The dust puts the fake into the payer's history, right next to the real payment, so the next time the payer copies from there, it may be the wrong one.
Dust costs less than a cent to send on Solana, so the bots can afford to answer almost every payment on the chain. In most of the cases we found, the lookalike matched four or more characters at each end, and in the rest it matched three. The same Solana scam has a twin on Ethereum, where we counted 6.9 million targeted wallets in 12 months.
03 · The scaleHow many Solana wallets get poisoned?
We counted a wallet as poisoned on any day when two things happened. First, it paid someone at least a dollar in SOL or in USDC or USDT, the two main dollar coins. Then a different address, with the same first three and last three characters as the one it paid, sent it dust or a fake USDC or USDT token.
By that rule, 4,497,798 Solana wallets were poisoned in the 11 months, by 9.4 million fake addresses. On the median day about 42,000 wallets got dust, and some were hit again and again: about 305,000 wallets got dust on ten days or more.
| What we counted | Solana, 30 October 2025 to 7 October 2026 |
|---|---|
| Wallets poisoned | 4,497,798 |
| Lookalike addresses that sent them dust | 9.4 million |
| Wallets poisoned on the median day | 42,000 |
| Busiest day | 21 August: 80,348 wallets |
| Wallets hit on ten days or more | 305,000 |
| Poisoned wallets that got dust in real SOL | 80% |
| Wallets poisoned up to 9 July 2026 | 3.0 million |
| Of those, wallets that later paid a lookalike | 1,104, 1 in 2,750 |
| Their payments to lookalikes | 1,335 |
| Dollars sent to lookalikes | $940,106: $600,510 in SOL, $269,418 in USDC, $70,178 in USDT |
| Median payment to a lookalike | $50 |
The count fell off a cliff in July. In the ten days before the third of July, about 52,000 wallets a day got dust. For the next eight days, no day reached 10,000. The count came back in mid-July, dropped again for three days, and has stayed high since 21 July. The largest single funder of fake addresses went quiet in the same month: it sent SOL to 23,745 addresses in July, against 1.8 million in August.
04 · DeliveryHow fast does the dust arrive?
Fast. On the median day the dust came 18 seconds after the real payment, and three in four dust transfers landed within a minute. Answering that quickly takes software that reads every new block on the Solana blockchain and fires off a transfer as soon as it sees a payment.
Most of the dust is real SOL. Four in five poisoned wallets got a tiny SOL transfer from the fake, and one in five got a tiny amount of real USDC or USDT; some got both.
Fake tokens, which carry the name USDC or USDT without being the real coin, were rare: about 1 in 1,000 cases. On Ethereum, counterfeit tokens are a main tool of the same scam. On Solana real SOL is cheap enough that the scammers seem to have no need for fakes.
05 · The lossesHow many people fall for it?
Most poisoned wallets never fall for it. Of the 3.0 million wallets poisoned before mid-July, 1,104 later sent at least a dollar to the fake, about 1 in 2,750. Together they sent $940,106.
That total leaves out cases that look like people paying their own wallets or partners: the fake paid the wallet back, the wallet paid it more than three times, or the wallet had paid it before the dust arrived. Those rules removed 90 such cases worth $343,799. Most of those excluded dollars came from wallets that fund lookalikes themselves, so much of it is scammers moving their own money.
Most losses are small. The median payment to a fake was $50, and 64% of payments were under a hundred dollars. A few were large. The 12 payments of ten thousand dollars or more carried 62% of the money, and the December payment alone carried 18%. SOL made up 64% of the stolen money, and the rest was USDC and USDT.
| Date | Paid to the lookalike | Coin | What they meant to pay | Time after the dust |
|---|---|---|---|---|
| 3 December 2025 | $166,330 | SOL | Exchange deposit address | under an hour |
| 14 January 2026 | $85,234 | SOL | Exchange deposit address | 10 days |
| 12 November 2025 | $70,000 | USDC | Gambling site deposit | 4 days |
| 2 July 2026 | $59,054 | USDC | No label | 3 days |
| 7 December 2025 | $55,693 | SOL | Gambling site deposit | 7 days |
| 3 June 2026 | $31,766 | USDC | No label | 36 days |
| 17 November 2025 | $30,750 | USDT | Exchange deposit address | under an hour |
| 6 December 2025 | $26,618 | SOL | No label | 26 days |
| 29 January 2026 | $20,009 | SOL | Exchange deposit address | 76 days |
| 30 November 2025 | $13,778 | SOL | No label | under an hour |
Six of the ten largest went to lookalikes of exchange or gambling deposit addresses, and seven of the ten came more than a day after the dust.
06 · The clockWhen do people make the mistake?
The dust does its work later, when someone goes back to their history to pay again.
Only one payment in ten to a lookalike came within an hour of the first dust, and a quarter within a day. Half came more than a week later. Payments made more than a month after the dust were 28% of the total and carried 17% of the money, which is why we counted losses over three months.
A test payment does not help if the test goes to the fake too. On 17 November last year a wallet sent ten dollars in USDT to its deposit address at the exchange Gate.io. Twelve seconds later a fake address sent it dust. Two minutes after that, the wallet sent another ten-dollar test, this time to the fake. It arrived, and a minute and a quarter later the wallet sent the rest: 30,749.80 USDT.
07 · The targetsWhose addresses get copied?
Fake copies of exchange deposit addresses did the most damage. People pay the same deposit address again and again, which is exactly the habit the scam needs. 40% of the stolen dollars went to copies of exchange deposit addresses, as marked by Bitquery's address labels, most of them at Binance and Bybit.
Another 17% went to fake copies of deposit addresses at gambling sites, led by Stake. The rest went to fake copies of addresses that carry no label in our data.
08 · The fundersWho pays for the dust?
A fake needs a little SOL before it can send anything, so every fake has a funder. On 44 sample days, one a week plus the middle of each month, we found the first SOL each fake received: 1.2 million of them, funded by about 708,000 different wallets. The ten busiest funders paid for 15% of them. The rest are close to disposable: 98% of all funders paid for one or two fakes and were never seen again on our sample days.
The largest funder, QVtW…KNQ4, started sending in late March and has sent SOL to 5.1 million addresses since. From April it gave the first SOL to 7% of the fakes on our sample days.
The funder's busiest month was April and its quietest was July, the same month the daily count of poisoned wallets fell. In August it was back.
09 · The exitWhere does the stolen money go?
We followed the money from the twenty fakes that took the most, which together took 68% of all the stolen dollars. We went up to ten steps from each one and would have stopped at any wallet with more than a hundred senders, such as an exchange or a bridge, a service that moves coins to another blockchain. None got that far.
Of the twenty, 19 sent the whole amount on in single file. The fake passed it to a fresh wallet, which passed it to another, and so on, each hop within seconds. Ten hops took less than a minute in most cases. No wallet on any of the paths had more than five senders. The same pattern on so many separate thefts points to the same software behind most of the large ones.
We stopped after ten hops, so we cannot say where the money ended up. Any of the wallets can be followed further with the Bitquery MCP, which lets an AI assistant answer questions from Bitquery's blockchain data. If you have lost money this way, Bitquery's investigation services can trace it for you.
10 · EthereumHow does Solana compare with Ethereum?
Our Ethereum study found 6.9 million wallets targeted in 12 months, more than the 4.5 million we found on Solana in 11. Ethereum's losses were far bigger too: 1,319 people paid a lookalike and lost $22.3 million between them. Solana's victims fall for the trick about twice as often, but they lose much smaller sums.
| Solana | Ethereum | |
|---|---|---|
| Period | 30 October 2025 to 7 October 2026, 11 months | 1 August 2025 to 31 July 2026, 12 months |
| Wallets targeted | 4,497,798 | 6,922,366 |
| Wallets or people that paid a lookalike | 1,104 | 1,319 |
| Share of targeted wallets that paid | 1 in 2,750 | 1 in 5,248 |
| Money lost | $940,106 | $22.3 million |
| Median theft | $50 | $336 |
| Largest theft | $166,330 | $12.4 million |
The two studies use different rules, so treat the comparison as rough. The Ethereum piece matched four characters at each end against a wallet's earlier contacts; this one matches three against the address paid that day.
11 · DefenceHow to avoid address poisoning
The defence is a habit, and it costs nothing. Copy an address from its source every time: the deposit page of the exchange, or the message from the person you are paying. Never copy one from your list of recent payments.
When you paste an address, check a few characters from the middle as well as the ends, because the ends are what the scammers copy. If you pay the same address often, save it in your wallet's address book and pay from there, so the fake never comes into play.
Ignore dust from strangers. Some wallets hide it, and a transfer of a fraction of a cent from an address you do not know is almost always bait. A test payment will not save you either. If the test goes to the fake, it arrives, and the main payment follows it.
Dust cannot take money out of your wallet on its own. The danger is only in copying the address it came from. Exchanges and wallet makers can help by warning when someone pays an address that shares its ends with one they used before, and businesses that screen payments can use Bitquery's compliance tools to check addresses against labels before money moves.
12 · MethodHow we did this
We used Bitquery's records of every Solana transfer: the full-history archive up to the end of August, and Bitquery's live Solana data from 31 August to 7 October 2026. On two days that both sources cover, they found the same poisoned wallets to within about 1%. The full history of Solana transfers is also sold as files on the Bitquery Data Store, and the same records are available through Bitquery's address APIs.
A payment counts when it was worth at least a dollar. Dust is a transfer of SOL, USDC or USDT worth less than a cent. A loss is a payment of at least a dollar from the poisoned wallet to the fake after the dust arrived, within three months of the first dust or on a later day when more dust came.
We tested the rule three ways. Matching on characters from the middle of addresses, which no scammer would do, found almost nothing. Every loss of five hundred dollars or more showed up again in a second Bitquery data set, together with the dust before it. And the five largest losses were checked one by one on a public Solana node.
13 · EvidenceAddresses and transactions cited
| What | Address or transaction |
|---|---|
| Wallet that lost 1,176.73 SOL on 3 December | 9xTV94…HX3hLD |
| Its Crypto.com deposit address | HJ7fn4…sBrYEz |
| The lookalike | HJ7f9h…fBrYEz |
| The payment to the lookalike | 42MCeV…Xgr4 |
| Wallet that sent 30,749.80 USDT on 17 November | 5tCdfz…X9RUr7 |
| Its Gate.io deposit address | 8SnDMn…cMGNKH |
| The lookalike | 8SnDST…EMGNKH |
| The payment to the lookalike | QjYL7N…yH8w |
| The largest funder of lookalikes | QVtWcA…TrKNQ4 |
| Relay wallet 1, 3 December money | CdxkKb…2Dp3Zj |
| Relay wallet 2 | BvgPvp…fXzQTx |
| Relay wallet 3 | 8f31Ay…coFzqg |
| Relay wallet 4 | ACBtoE…YTZp5r |
| Relay wallet 5 | 6erASQ…sZ5qVT |
| Relay wallet 6 | 9FMKMk…XWqRwx |
| Relay wallet 7 | 8YAazV…qdCBXa |
| Relay wallet 8 | DnH7mF…et5XXZ |
| Relay wallet 9 | 4CXuJj…sUd4Vg |
| Relay wallet 10 | 7D9RvL…MRs5a2 |
FAQ
What is address poisoning?
Address poisoning is a scam in which someone sends you a tiny amount from an address that looks like one you have paid, so that it appears in your payment history. If you later copy the lookalike from your history, your money goes to the scammer.
What is a dusting attack in crypto?
A dusting attack is when someone sends tiny amounts of crypto, called dust, to many wallets. In address poisoning the dust comes from a lookalike address, so that it sits in your history next to a real payment and waits for you to copy it.
Is address poisoning common on Solana?
Very common. In the 11 months we checked, more than four million Solana wallets got dust from a lookalike after making a payment, tens of thousands on most days.
How many people lose money to address poisoning?
On Solana, about 1 in 2,750 poisoned wallets later sent money to the fake. Most of those payments are small, though a handful run to tens of thousands of dollars.
Does a test payment protect me from address poisoning?
No. If you copy the address from your history, the test goes to the lookalike. It arrives, and the address looks safe. One wallet in our data sent a ten-dollar test to a lookalike and then sent the rest of its payment there too.
Should I remove dust from my Solana wallet?
You do not have to. Dust cannot move money out of your wallet. What matters is never copying the address it came from. Some wallets let you hide unknown tokens so they do not clutter your history.
How do I avoid address poisoning?
Copy addresses from the source every time, never from your payment history. Check characters in the middle as well as the ends, keep the ones you often pay in your wallet's address book, and ignore dust from strangers.
Losses are a floor. We counted payments of at least $1 to a lookalike within 90 days of its first dust, or on a later day when it sent more, for wallets poisoned up to 9 July 2026. Mistakes after that, or by wallets poisoned later, are not counted.
A wallet counts as poisoned only after a payment of at least $1 in SOL, USDC or USDT the same day. Specks aimed at other payments, or at wallets that had not paid anyone that day, are not counted.
From 31 August the counts come from Bitquery's live Solana tables. They do not record token names, so fake-token dust is missing on those days, and on 30 August they found 1% more poisoned wallets than the archive.
SOL is priced by the minute in the archive and at the day's average in the live tables. A lookalike and the address it imitates share at least three characters at each end; a few matches of that kind can be chance.
Pairs where the lookalike paid the wallet back, the wallet paid it more than three times, or the wallet had paid it before the dust were left out as likely relationships. Some real thefts may be among them.
Exchange and gambling labels come from Bitquery's address labels. An address with no label can still belong to an exchange.
The money trail follows the 20 lookalikes that took the most, up to ten steps, and splits each wallet's outgoing money in proportion when it sent to several places.
Check a Solana address in plain English
Every transfer in this story comes from Bitquery's Solana data. The Bitquery MCP server puts that data behind an AI assistant, so you can ask who sent you a tiny transfer, whether an address looks like one you paid, or where a wallet's money went, without writing the query yourself. The full history of Solana transfers is also sold as files on the Bitquery Data Store.
This article is provided for informational and educational purposes only and reflects analysis of publicly available on-chain data as of the dates indicated. It does not constitute legal, financial, compliance, or investment advice, and nothing in it is a recommendation to buy, sell, or hold any token or asset.
The findings describe transfers observed on Solana between 30 October 2025 and 7 October 2026. A wallet is counted as poisoned, and a payment as a loss, by the rules set out in the method section; the counts depend on those rules and on Bitquery's records of the chain. Wallets, copies and funders are described by their behaviour on the chain. None of them is attributed to a named person or group.
Crypto.com, Gate.io, Binance, Bybit and Stake are named because Bitquery's address labels mark addresses that were copied as their deposit addresses. That shows which addresses the scam imitated. It says nothing about the conduct of those companies, which did not send or receive the stolen payments described here. Gambling sites are a restricted and high-risk activity in many places.
Reported by Gaurav Agarwal for Bitquery Research, with AI tools; every figure was checked against the raw data.
Nothing herein should be relied upon as a definitive determination of fact. Readers should conduct their own independent verification before taking any action. The authors and publisher accept no liability for any loss or damage arising from reliance on this material. All trademarks and company names are the property of their respective owners.