One of the cryptocurrency investors has just lost nearly 400,000 zlotys due to an "address poisoning" attack. In short, he sent his savings to a scammer's wallet address thinking it was his own. Cybersecurity experts warn that such schemes are becoming increasingly common, with criminals leveraging automation and hoping that the law of large numbers will allow them to "catch" a sufficient number of victims. Statistics show that they succeed remarkably often. In this article, we will describe in detail what address poisoning entails and how to protect yourself from it.
Address poisoning, or sending cryptocurrencies to someone else's address
The mechanism of classic address poisoning is quite primitive but still incredibly effective. It involves the attacker using automation software to create a vast number of addresses on the blockchain that mimic existing user wallets. Primarily, they try to replicate the first and last 4-6 digits, as these elements are most often checked by senders before they click the "Send" button.
The next step is to "encourage" the victim to "use" the fake address. This is done through a process called dusting, where tiny worthless tokens or NFTs are sent to the victim's address (this process is also fully automated), which appear in the transaction history of the attacked wallet.
The victim's fate is then sealed by their own actions. The cybercriminal relies on the fact that, after sending funds from one of their wallets to another for the umpteenth time, the victim will (out of laziness) use the address found in the transaction history and copy it using the simple copy-paste method into the "Recipient" field, EVENTUALLY checking the first and/or last 4-6 digits beforehand.
If everything goes smoothly, the money goes entirely to the "poisoner's" account. According to Blockaid data, one in 200 "attempts" ends in success. A lot? A little? If we consider the scale (17 million attacked according to 2025 data), the above number translates to losses reaching nearly 90 million USD (or about 350-400 million Polish zlotys) during the period from 2022 to 2024.
A new attack vector is even more dangerous
Address poisoning requires that the victim themselves choose the substituted address of their own free will. However, a new attack vector has emerged that does not even require this.
On July 27, a modified version of the script trackpoint-async.js appeared on the servers of Adform, one of the largest European advertising platforms. The company detected irregularities the very next day, but the malicious code was available on the network for at least another week.
The mechanism was exceptionally dangerous. The script checked the clipboard content every few seconds, where we copy content by pressing, for example, the CTRL+C key combination. When it detected a correctly formatted Bitcoin, Ethereum, or Tron address, it immediately replaced it with an address belonging to a scammer.
But that's not all. The code could also:
In practice, re-copying the correct address did not solve the problem. If the malicious script was still running on the page, it could perform another substitution.
The attack did not require the victim to install a program, download a file, or consciously run a suspicious attachment. It was enough to visit a website using Adform's advertising infrastructure that loaded the infected script.
The scale of potential exposure was enormous. Thousands of companies use Adform, and the platform boasts 1.5 billion ad impressions daily for clients from over 180 countries.
How to protect yourself?
How to avoid becoming a victim of address poisoning? For large transfers, check the entire address, not just the first and/or last digits, preferably using a source independent of where it was copied from.
It is also worth adhering to a few rules:
In the case of cryptocurrencies, one substituted letter or digit usually means an irreversible transaction. Therefore, for larger amounts, the recipient's address should be treated similarly to a bank account number in a bank transfer, with the difference that there is usually no bank on the blockchain that can stop a wrongly sent operation.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.





























