Learn · Threat research

Address poisoning: why your transaction history can lie

By Nova Team Published Oct 15, 2026 Updated Oct 30, 2026 ~8 min read Beginner
Nova Wallet · Learn

You copy an address from your own history, paste it, send. It lands at an attacker's address — because it was planted there days ago to look like the one you trust. This is how it works, at scale, and the twenty-second habit that kills it.

On this page 7 sections
Key takeaways
  • USENIX Security '25 measured 270 million poisoning attempts, ~17 million victim addresses, and ~$83.8 million in losses.
  • The attack needs zero access to your wallet — it plants a lookalike address into your history and waits for you to copy it.
  • Attackers generate addresses matching the first and last characters of your real counterparty — the parts most UIs show.
  • Verifying the whole string — not the prefix — is the complete defense. It takes seconds and costs nothing.
  • Never copy an address from history. Copy it from a source you verified once, and keep it in an address book.

The attack in thirty seconds§

You send ETH to the same exchange deposit address every week. One day a "received" entry appears in your history — a dust transfer of a few cents, or a zero-value token — from an address that starts and ends exactly like that deposit address. Next time you go to send, you open your history, copy the top entry, and the funds are gone. The attacker never touched your wallet, your keys, or a single contract you control. They touched your clipboard habit.

That is the entire attack. No malware, no signature request, no approval to revoke afterward. The transaction that robs you is one you authored and signed yourself — to an address you chose off a poisoned list.

Grinding a lookalike address§

EVM addresses are derived from a public key — pick a private key, and the address falls out of the math. There is no registration and no way to reserve one. That means anyone can generate millions of keypairs per hour on ordinary GPUs and keep only the ones whose address shares a prefix and suffix with a target. Matching four characters on each end takes minutes; six takes hours. The result is an address that is visually interchangeable with the real one in any UI that truncates the middle — which is nearly all of them:

Address
Real0x3C8F…a91E (your exchange deposit)
Planted0x3C8F…a91E (attacker's — same head, same tail, different middle)

Render both as 0x3C8F…a91E and they are identical. The only difference lives in the characters your wallet chose not to show.

Dust, zero-value transfers, and fakes§

The lookalike is useless until it's inside your history. Three delivery methods do the work:

  • Dust transfers. The attacker sends a few cents of ETH, or a token, from the lookalike to you. Harmless on its face — it exists purely to write a row into your activity list with their address on it.
  • Zero-value token transfers. On most chains a transfer of zero tokens is valid and cheap in bulk. Attackers spray thousands of zero-value transfers per block so lookalikes appear as "received" entries across huge populations of wallets.
  • Forged history entries. Some scam tokens emit fake Transfer events — logs claiming tokens moved between you and a lookalike even though no real transfer happened. Indexers and explorers that trust the event log surface these as real activity.

All three share one property: they are indistinguishable from normal traffic in a list that shows a timestamp, an amount, and a truncated address.

What the data says§

This is not an edge case. Researchers presenting at USENIX Security '25 measured the poisoning ecosystem on-chain and counted:

270Mpoisoning attempts observed
17Mvictim addresses targeted
~$83.8Mlosses attributed to poisoning

Source: USENIX Security '25 — large-scale measurement of address-poisoning attacks.

The economics explain the volume. A dust transfer costs cents; a lookalike costs compute time; a single hit pays for millions of attempts. Poisoning is industrialized — sprayed broadly, harvested passively. Most attempts fail, but at 270 million attempts a fractional success rate is still $83.8 million.

Why wallets can't fully fix it§

An honest caveat: no wallet can solve this completely for you. The poisoned entry is a real on-chain event — the dust actually arrived, the log actually exists. A wallet can hide obvious spam tokens and flag a recipient that shares a head and tail with your contacts but not the middle — Nova Shield does exactly that screening before you sign. But a lookalike planted to imitate an address you've never used, or one copied from a source you trust anyway, still comes down to the same human step: what did you check before you hit send?

The truncated display is the vulnerability. Any interface that renders 0x3C8F…a91E is asking you to trust 8 characters out of 40. Everything else in this attack — the dust, the timing, the scale — exists to exploit that one display decision.

The habits that stop it§

  • Never copy from history. Treat the activity list as a log, not a contact book. An entry's presence proves nothing about who controls the address.
  • Verify the middle, not just the ends. When you must paste, compare a few characters from the center of the address against the trusted source — the part every truncated display hides is the part attackers can't cheaply match.
  • Use an address book. Save addresses you've verified once under a name. Send to saved entries, never to history entries.
  • Test-send on anything big. A small transfer confirmed at the real destination is cheap insurance against a planted lookalike.
  • Ignore inbound dust. Unexpected tiny transfers and zero-value tokens are bait by default. They don't cost you anything to leave alone.

What Nova does — and doesn't§

When you send from Nova, the confirm screen renders the full recipient address — no middle ellipsis — so the lookalike's center is on screen, not hidden. Nova Shield screens the recipient before you sign: addresses that share a head-and-tail with your contacts but differ in the middle, or that have no history with you at all, get flagged as unusual before you confirm.

Honest limits
  • Flagging is a signal, not a verdict — a first-time recipient looks identical to a planted one until you confirm it yourself.
  • It can't catch an address you paste over a warning, or a poisoning attempt aimed at a brand-new contact.
  • It doesn't protect sends you make from other wallets or other devices.

Shield's job is to put the information on screen at the only moment that matters — before you sign. The read is still yours, and now you know exactly what to read.

See the whole address, every time.

Nova Wallet renders the full recipient on every confirm screen and flags lookalike and unusual recipients before you sign — on-device, with zero telemetry.