Address poisoning is a scam where an attacker sends a dust transaction from a lookalike address: the same first and last characters as one you have paid before, different in the middle where nobody looks. The poisoned entry then sits in your transaction history, waiting to be copy-pasted.
The defense is mechanical, not vigilance-based: never copy addresses from history, verify from the source (an invoice, a web3 name), and prefer names over hex entirely. The scam works because humans pattern-match beginnings and endings; removing the hex from the workflow removes the attack.
U.CASH checkouts display the payment address per invoice and support web3 names everywhere an address can appear, so payers verify against the source instead of scavenging history.
Every term behind the rails, the assets, and the settlement.