Transactions · 28 / 86
Address poisoning
Someone sends you a tiny transfer from an address that looks like yours, so the next time you copy from your history you copy theirs.
The trick
Addresses are long. People check the first and last characters. The attacker matches those and hides the difference in the middle. The fake transfer sits in your history, waiting for a careless paste.
The habit
Do not copy a destination from transaction history. Copy it from a saved, checked entry, or from the recipient through a channel you already trust.
Check more than the ends of the address on the device that will sign. A small test transfer is cheaper than a large mistake.
Check yourself
Is a matching start and end of an address enough?
No. The middle is where the copy hides.
After this you can stop pasting destinations from your history.
