Glossary · Security

What is Address poisoning?

Address poisoning is a scam where an attacker sends a dust transaction from a lookalike address: the same first and last characters as one you have paid before, different in the middle where nobody looks. The poisoned entry then sits in your transaction history, waiting to be copy-pasted.

The defense is mechanical, not vigilance-based: never copy addresses from history, verify from the source (an invoice, a web3 name), and prefer names over hex entirely. The scam works because humans pattern-match beginnings and endings; removing the hex from the workflow removes the attack.

Address poisoning on U.CASH

U.CASH checkouts display the payment address per invoice and support web3 names everywhere an address can appear, so payers verify against the source instead of scavenging history.

See also

Web3 nameNon-custodial

Address poisoning: FAQ

Can address poisoning steal my funds by itself?
No: it only plants a decoy. Loss happens when a human copies the decoy into a send. Nothing moves without a signature from your key.
Why do the lookalike addresses exist at all?
Vanity generation is cheap: an attacker grinds thousands of addresses to find first-and-last character matches. It costs them pennies and occasionally pays.
Keep reading

The glossary, A to Z

Every term behind the rails, the assets, and the settlement.