Address Poisoning: Why Seven of Forty Characters Were Enough to Divert $2 Million
A fake wallet address matched the real one in just seven of forty characters and still intercepted 2 million USDC. Our own count of the affected wallet shows that a third of all counterparties in its history belong to such look-alikes.

Table of Contents
Table of Contents



Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
On August 21, 2026, a transfer of 2,000,000 USDC left a wallet and landed at an address that matched the correct one in exactly seven of forty characters. Four characters at the front, three at the end. The remaining thirty-three were completely different. That precise cut is the entire attack, because wallets and block explorers usually show addresses in shortened form: a few characters at the front, a few at the back, three dots in the middle. Anyone who looks only at that short form sees the same thing on the fake as on the original.
The technique is called address poisoning. Address poisoning means that an attacker plants a fake but similar-looking address into your wallet's transaction history, so that you later copy it from there and send your money to it yourself. Nothing is hacked, no key is stolen, no signature is forged. The transfer is technically flawless and authorised by the owner. It simply goes to the wrong recipient, and on a blockchain that makes it final.
This article takes the August 21 case apart and then goes further than the reports published so far: we read out the full transaction history of the affected wallet and counted it. The result shows that the decoy address was not a one-off but part of a stock that accounts for a third of all counterparties this wallet has ever touched.
Address poisoning explained: how a fake wallet address gets into your history
The attacker needs no access to your wallet. They need only an entry in your history, because for most users that history is the most convenient source for a receiving address. Instead of fetching a forty-character string from a contract, an email or a slip of paper, you scroll back in the wallet app or the explorer, find the line with the last transfer to the same recipient and copy the address from there. That reach is the target.
There are two common ways to get into the history. The first is the dust transfer: the attacker sends you a tiny, economically meaningless amount from their fake address. A fraction of a cent is enough. That puts their address in your history without them having to know anything about you.
The second way is the fake transfer event. On Ethereum and comparable networks, anyone can publish their own token contract, and that contract may report whatever it likes. Such a contract emits an event that looks as though you had just sent a large amount to a particular address. A completed transfer that never happened appears in your history. The advantage for the attacker is obvious: an address you have supposedly already sent two million to looks more familiar than one that only sent dust.
Both routes cost the attacker almost nothing and can be repeated at will. They do not need to know when you will next transfer funds. They only need their entry to sit at the top of your list at that moment. Part of why this works so well on a network such as Ethereum is that any token contract can be published there without review.
The Bofur Capital case: 2 million USDC thirty minutes after the Compound withdrawal
The security firm PeckShield reported the incident on August 22, 2026 and attributes the affected wallet to the market participant Bofur Capital. That attribution comes from PeckShield, it cannot be confirmed from the blockchain data alone, and we carry it here as a third-party statement. The sequence of events, by contrast, is out in the open on the chain and can be verified. All times below are coordinated universal time.
On August 20 at 20:12:23, the wallet transferred 2,000,000 USDC to an address it had already used a month earlier. Eight minutes and thirty-six seconds later, at 20:20:59, a dust transfer of 0.0002 USDC arrived. The sender was an address that looked similar to the one just used. That same address had been topped up seconds earlier by a third party with 0.000801 USDC, in other words with just enough balance for this single decoy.
Over the next not quite two hours, two supposed transfers of 2,000,000 each to the same fake address also appeared in the wallet's history, at 20:41:11 and at 21:16:11. Both come from an external token contract and never took place. To anyone looking at the list the following day, the fake address therefore looked like one this wallet had only just sent millions to, several times over.
On August 21 at 16:01:23, the wallet withdrew 2,000,000 USDC from the Compound USDC contract. At 16:31:11, thirty minutes later, 2,000,000.000000 USDC went to the fake address. No second attempt followed and no correction. The amount then moved through a collection wallet, was swapped into DAI at 23:28:35 via the settlement contract of CoW Protocol and parked at 23:31:11 as 1,999,939.476314 DAI on a third address. There it sits, as of this analysis, unchanged.
Four characters at the front, three at the back: how similar the fake address really was
The decisive point is how little similarity this attack requires. The recipient address actually used and the fake one match in four characters at the start and three at the end. That is seven of forty characters. Thirty-three characters in the middle are different, many of them obviously so at first glance.
The reason that is still enough lies in the display. The usual short form in wallet apps, explorers and overview lists shows roughly the first six and the last four characters. That exact section is practically identical on both addresses. The thirty-three diverging characters sit in the part that the interface replaces with three dots.
Generating such an address is neither an art nor a feat of computation. The attacker runs through key pairs until one produces an address with the desired opening and closing characters. The more characters have to match, the longer it takes, but four at the front and four at the back are a matter of minutes on off-the-shelf hardware. That is also why the number of decoys is not limited by effort.

Dust transfer and fake transfer event: two techniques, one goal
In this case both techniques ran side by side, and that is the part missing from the reports so far. What was reported was the dust transfer of 0.0002 USDC. Alongside it, the chain holds several supposed million-dollar transfers from fake contracts, and those are what complete the picture in the history.
The difference matters in practice. Many users ignore a dust amount from an unknown address because they file it under advertising or spam. An entry that looks like your own million-dollar transfer, made only moments ago, reads like a receipt instead. Anyone looking for the last payment to the same recipient finds precisely that entry, and it sits higher in the list than the original.
Neither entry can be technically deleted from your own history. A blockchain forgets nothing, and an event from an external contract stays visible even when it is pure invention. Some interfaces hide suspicious contracts or flag them. You cannot rely on that, because detection varies in strictness from provider to provider.
Homoglyphs in the token name: why a fake ticker looks like USDC in the explorer
For the false entries to pass unnoticed, the token has to be right as well. The contracts used for this carry tickers that look like USDC, DAI or ETH in the explorer but are not. The trick is called a homoglyph. A homoglyph is a character that looks confusingly similar to another one but is technically a completely different character.
The data we read out contains several designs. One group of contracts uses Cyrillic letters: a Cyrillic Dze in place of the Latin S and a Cyrillic Es in place of the C, plus a U with an accent. What appears on screen is something you read as USDC. A second group slips invisible control characters between the letters, a zero-width joiner or a Mongolian vowel separator for instance. The ticker then looks exactly like the real one, but is not. A third group works with the simplest means available and writes a lowercase L instead of a capital I, which in many typefaces cannot be told apart. And some contracts do without any disguise at all and simply carry the correct ticker, because a token symbol does not have to be unique.
For you that means: the ticker next to an amount is no proof of which token was actually moved. The only reliable identifier is the contract address. USDC and DAI each have exactly one correct address, and every explorer displays it when you click on the token.
Our own survey: how many decoy addresses sit in a single wallet's history
This analysis was carried out by cryptoticker.io itself on August 22, 2026. Using the public interface of the Blockscout block explorer, we retrieved every token transfer event of the affected wallet, across six pages, then deduplicated and counted the records. We captured timestamps, amounts, the token's contract address and both sender and recipient.
Examined: 300 unique transfer events from the period between November 22, 2025 and August 22, 2026, among them 84 different counterparties. 165 of these events come from the genuine USDC or DAI contracts, 135 from other contracts.
Nine clusters, thirty-three addresses: the count in detail
We grouped all 84 counterparties by whether they match in the first four and the last four characters, which is exactly the section a shortened display shows. Result: 33 of the 84 addresses fall into nine such groups. Each of these groups contains at least two addresses that cannot be told apart in short form. Around a third of all counterparties this wallet has ever touched therefore belongs to a stock of look-alikes.
The largest group comprises eight addresses. The second largest five, the third largest four. Three further groups have three members each, two have two each. The group the August 21 theft came from holds three addresses, and a neighbouring group with the same opening but a different ending holds another three, among them the recipient address actually used.
The distribution says something about the method: for every recurring counterparty of this wallet, several decoys were evidently created rather than a single one. Anyone copying an address from the history is reaching into a stock in which the correct address is in the minority.
Limits of this survey
We do not know whether the same actor stands behind all nine groups; the grouping describes a pattern, not culpability. We do not know whether all 135 events from external contracts are attack attempts, because among them are recognisably ordinary advertising tokens with no connection to this technique. We do not know which wallet software the affected wallet used or how it displays addresses. We do not know whether and how many German investors were approached by the same groups, because places of residence cannot be read from blockchain data. And we do not know whether the funds can be recovered.
The Compound contract has look-alikes too: why even protocol addresses get faked
One side result of the count deserves attention of its own. This wallet's most frequent counterparty is the Compound USDC contract, through which it regularly deposits and withdraws. For this address as well, two others were found that are identical in the first four and the last four characters.
That extends the danger beyond the payment recipient. Anyone copying a contract address from their own history, to enter it into a wallet interface or to check that they are talking to the right protocol, can be misled in the same way. The countermeasure is simpler here than with a private recipient: contract addresses of known protocols are listed in their own documentation, and explorers mark verified contracts by name. For the Compound contract and the settlement contract of CoW Protocol that marking was present in our retrieval; for the look-alikes it was not.
Eight minutes after the real payment: when the decoy is set
The timing of the decoys was the most surprising detail in our analysis. The attack followed immediately on a real payment, and did so twice to the same pattern.
On July 21, 2026 at 14:37:11, the wallet transferred 2,000,000 USDC to its usual counterparty. At 14:45:23, eight minutes and twelve seconds later, a dust transfer of 0.0002 USDC arrived from an address with the same four opening characters. On August 20 this repeated itself: real transfer at 20:12:23, dust transfer at 20:20:59, a gap of eight minutes and thirty-six seconds.
It follows that the chain is being watched and that the decoy is only set once a real, recurring payment has become visible. That matters for the defence: the most dangerous spot in the history is the entry directly above the last real transfer, because it was placed where the next search will look. Anyone who regularly sends the same amount to the same place is a particularly rewarding target for this technique.

The thief gets poisoned in turn: what happened in the perpetrator's history 25 minutes after the theft
At 23:31:11 the stolen 1,999,939.476314 DAI sat at their new address. Twenty-four seconds later, at 23:31:35, a transfer of exactly the same amount appeared in the collection wallet's history, sent to an address that matched the one just used in the first four and the last four characters. The amount came from a fake contract whose ticker was made to look like DAI by an invisible control character.
It did not stop there. At 23:44:23 a genuine dust transfer of 0.0002 DAI arrived from another look-alike address. Three further fake transfers of the same amount to three different look-alikes followed during the night, along with entries from contracts passing themselves off as ETH, and on the morning of August 22 a transfer of zero from the genuine DAI contract. Within a few hours, at least four different addresses stood in the perpetrator's history, all beginning with the same four characters and ending in the same four as their own hiding place.
The episode is more than a footnote. It shows, first, how automated this technique is: a freshly filled large holding is evidently spotted and served within seconds, without anyone having to check whose it is. And it shows, second, that the attack needs to know nothing about its victim. It targets a habit, not a person.
Check the address instead of copying it: the steps that make the attack come to nothing
The good news about this technique is that it hangs entirely on a single habit. Anyone who does not take the receiving address from their transaction history is not exposed to address poisoning, no matter how many decoys sit in their list.
The first step is therefore the most important: take the address from the source it originally came from. That is the invoice, the withdrawal page of your exchange, your wallet's address book or the recipient's message. Your own history is not a source but a copy that anyone can write into.
The second step is the full check. Compare the entire string, not the short form. The most reliable way is to place the address from both sources side by side and go through it character by character, or to paste it into a search field and check that the address found actually has the expected history. A glance at the first and last characters delivers exactly what the attacker has budgeted for.
The third step concerns the middle. If you can only check a section, then deliberately check characters from the middle of the address rather than the edges. In our case thirty-three of the forty characters were different, and all thirty-three sat in the part nobody looks at.
Why the hardware wallet display is the last line of control
A hardware wallet shows the receiving address on its own screen before you confirm the transaction. That screen is not attached to the computer and cannot be rewritten by a manipulated interface. It is therefore the last place where a wrong recipient can be caught, and on most devices the full address can be scrolled through there. The comparison is worth making with large amounts in particular, and it costs a few seconds. Which devices implement this display and how is set out in our hardware wallet comparison.
Address book and whitelist: how to set a receiving address once
Recurring payments are, as the case shows, the preferred target. An address book is exactly what helps against that. Almost every wallet application and every larger exchange lets you store a receiving address once, give it a name and from then on select only that name. The copying step out of the history falls away completely.
At exchanges the same function is usually called a withdrawal whitelist. It has an additional benefit: new addresses often cannot be used until a waiting period of 24 or 48 hours has passed. Even if somebody takes over your account, they cannot send the balance to a fresh address straight away. Check whether your provider offers this lock-up period and whether it is switched on, because frequently it is not on by default.
The timing of the entry remains crucial. An address you carry over into your address book from a poisoned history is permanently wrong there, and the next mistake then happens automatically. Enter it from the original source, and check it in full once as you enter it.
Test transfer: when a small advance payment helps and when it only costs fees
A small advance payment to a new address is a sensible safeguard if the recipient can confirm receipt to you. You are then checking the result rather than the address, and that is the more robust test. At an exchange you see the credit in your own account; with a business partner you need a reply.
Without that confirmation the test transfer achieves little. The fact that a transaction was confirmed says only that the address exists. In an address poisoning attack the false address obviously exists, and it accepts the test amount just as readily as the large one. Anyone who then transfers without a reply has merely paid the same attacker twice.
Factor in the cost as well. On networks with high fees a test transfer can be expensive, while a full address comparison costs nothing. The order that works: check the address in full first, then additionally test with new recipients and large amounts.
Documenting the loss: which details to secure after a misdirected transfer
Once the money is gone, the blockchain will not change that. A confirmed transaction cannot be recalled, and nobody can reverse it. What counts now is documentation, and immediately, because interfaces change and overviews get re-sorted.
Secure the transaction hash, the full recipient address, the exact time, the amount and the contract address of the token moved. Secure the entry you copied the address from as well, with its timestamp, because that establishes the sequence of events. A screenshot adds to this but does not replace the identifiers. What is still practically possible afterwards and what is definitively lost, we have written up in our piece on crypto sent to the wrong address.
For the tax treatment of such a loss there is no clear, generally accepted line in Germany, and we deliberately do not set one out here. What you can do is create the basis: a complete and consistent record of all the transactions involved, which a tax adviser can work with. Portfolio and tax tools help with this because they hold addresses and transactions on file permanently.
Spotting address poisoning: what to take away
- Never take the receiving address from your transaction history. Take it from the invoice, the withdrawal page or the address book. The history is the one place an attacker can write to, and that is precisely why they start there. Which wallets come with a usable address book is shown in our software wallet comparison.
- Check the full address, with the emphasis on the middle. Seven of forty characters were enough in our case to make the short form look identical. With larger amounts, read the address off your hardware wallet display as well, because that screen cannot be manipulated; the devices at a glance are in the hardware wallet comparison.
- Set up an address book and a withdrawal whitelist before you need them. Enter recurring recipients once from the original source and, where available, switch on the lock-up period for new addresses. Keep your addresses and transactions cleanly on file, for instance with one of the tools from our overview of tax and portfolio tools.
The evidence for this article is publicly verifiable: the report of the incident at The Crypto Times and the full transaction history of the affected wallet in the Blockscout block explorer, on which our count is based.
(As of August 22, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Related articles
- Crypto Scams: How to Protect Your Cryptos?
- Crypto Withdrawals to Your Own Wallet: Why Exchanges Demand Proof of Address Ownership Above €1,000
- Fake AML Checks for Crypto Wallets: How to Spot the Scam Sites
- How to Identify Fake TRUMP tokens: A Guide to Staying Safe in the Crypto World
- Crypto Withdrawal to Your Own Wallet: Ten Providers Checked, Three Will Not Let Your Coins Out
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
September 8, 2026 7:33 AM

Withdrawal Whitelist at the Crypto Exchange: How to Lock the Withdrawal Path Against Foreign Addresses
A withdrawal whitelist lets balances leave only to addresses approved in advance, and it works even when password and second factor are compromised. On September 8, 2026 we checked which of thirteen providers document the function publicly.
September 4, 2026 10:17 AM

Cypher Shutdown on September 6: What Users Should Know Now the Withdrawal Deadline Has Passed
Recap as of September 27, 2026: Cypher had announced it would take its app, dApp and withdrawal window offline on September 6, 2026 and end the token protocol. This article describes the situation before the deadline, how the payout worked and what our own measurement showed at the time about what was left of the CYPR token.
September 20, 2026 4:15 PM

Crypto Phishing After a Data Breach: The Warning Signs in a Fake Exchange Email
After every major data breach, the number of phishing emails sent in the name of crypto exchanges and wallet manufacturers rises. This article shows you how to recognise such a message, which data a reputable provider never requests by email, and what to do in the first hour after a click.
September 1, 2026 7:27 AM

Clipboard Attack: How Malware Swaps the Wallet Address You Copied
A clipper replaces the receiving address between copying and pasting with the attacker’s, and your wallet’s checksum notices nothing. What Microsoft and the Federal Office for Cybersecurity have documented, and which check really makes the attack come to nothing.
August 22, 2026 4:16 PM

Stolen Crypto: Where You Actually File a Report and What Counts in the First Hours
After a theft most people google first and preserve the evidence last, when the right order is the other way round. What you have to record in the first hours, where private individuals actually turn, and where the limit of what is possible lies.
September 13, 2026 10:13 AM

Humanity Protocol Unlock of September 23: What H Holders Should Know Now the Kraken Deadline Has Passed
Recap as of September 27, 2026: Humanity Protocol was scheduled to release 292,857,143 H on September 23, 2026, and Kraken withdrawals for H and HUMANITY ended on September 25. This article recalculates the tranches and describes what holders should have checked before those dates.
August 28, 2026 1:33 AM

Sending Crypto: Why the Wrong Network Costs You the Balance on 51 of the 100 Largest Crypto Assets
When you withdraw from a crypto exchange, the network you pick decides whether your balance arrives or is lost for good. Our own analysis of August 26, 2026 shows that 51 of the 100 largest crypto assets exist on several chains at once.
August 23, 2026 4:36 PM

Operation ASTERIX: How a Fake Support Call Delivers a Counterfeit Wallet App
Security researchers analysed an open server on which a phone system, phishing interfaces and cloned wallet programs all came together. The largest list of numbers was the German one.
April 25, 2024 11:44 AM

Beware of New Ethereum Node Scam: USDT Fraud Exposed
Crypto Scammers exploit Ethereum nodes and USDT to deceive crypto users. How are they pulling it off and what essential tips can help you protect yourself against these crypto scams?
September 4, 2026 10:32 AM

Crypto Deadlines This Autumn: Nine Cut-Off Dates Checked, and Only Three Leave You Time After Trading Ends
Nine running crypto deadlines, eleven provider pages, one query date: we counted how much time really lies between the end of trading and the withdrawal cut-off. In six of nine cases the stated date is the end of the line.
August 18, 2026 10:14 PM

Sent Crypto to the Wrong Address: What Still Works and What Is Gone for Good
A sent transaction cannot be recalled. That is true, but it is only half the story. Whether your money is gone depends on who holds the key to the destination address. Six cases, cleanly separated: four of them are recoverable.
January 9, 2024 5:59 AM

27 Bitcoins Sent to Satoshi Nakamoto Address – What’s Behind This Cryptic Move?
The transfer of 27 Bitcoins to the wallet associated with Bitcoin's creator, Satoshi Nakamoto, has caught attention.
December 26, 2025 1:50 PM

Breaking: Trust Wallet Chrome Extension Hack Drains $7M, Full Reimbursements Promised
A supply-chain attack hit Trust Wallet’s Chrome extension, draining $7M from users. Binance’s CZ says all victims will be reimbursed.
December 26, 2024 1:08 PM

BGB News: Bitget Token Reaches New ATH Amid Market Momentum
Bitget Token (BGB) defies the market downtrend, hitting a new ATH of $7.32. What's driving this 368% surge and what the future holds for this top-performing cryptocurrency?
August 31, 2026 7:20 AM

Browser Extensions as Wallet Thieves: How a Sports App Became a Seed Phrase Collector
In August 2026 the security firm Socket disclosed two separate campaigns: 40 confirmed malicious Firefox extensions and 19 for Chrome and Edge, all of them from the official marketplaces. Nine of them were harmless sports apps that only turned into wallet thieves through an update.
August 23, 2026 7:17 AM

OKX Delisting: What MAJOR and J Holders Should Know Now the August 26 Withdrawal Deadline Has Passed
Recap as of September 27, 2026: OKX had announced it would halt withdrawals of the tokens MAJOR and J on August 26, 2026 at 08:00 UTC; they had not been tradable there since the start of June. This article describes the situation before the deadline.
May 12, 2025 9:05 PM

US-EU Trade Tensions Rise as US-China Conflict Cools Down
Just as the long-standing US-China trade war appears to ease, new tensions are emerging between the United States and the European Union. With Trump calling Europe “nastier than China,” are we about to witness a new transatlantic trade conflict?
June 1, 2024 11:00 PM

Bitget Wallet Token (BWB) makes debut on the Bitget Launchpad
Bitget, the world's leading cryptocurrency exchange and Web3 company, has announced the launch of Bitget Wallet's BWB token on its Launchpad.
July 25, 2026 12:44 PM

Samsung Puts Stablecoins in Its Wallet: What It Means for Crypto Prices
Samsung Wallet is getting native stablecoin support, with USDC demoed on stage. No launch date yet — but the distribution potential is real.
April 19, 2026 10:29 AM

RAVE Token Crash 95% in $6 Billion Wipeout: Insider Scam or Trader’s Paradise?
RAVE plummets 95% as allegations of insider manipulation surface. While retail investors suffer, professional traders eye a "Dead Cat Bounce" opportunity.
December 31, 2023 8:11 AM

Ultimate Guide To Rainbow Wallet Airdrop
Rainbow has unveiled its Rainbow Points rewards initiative. This article is all about the simple guide on Rainbow wallet airdrop
September 29, 2026 1:15 AM

BaFin warns over nova-c-solutions.com: What is behind a genuine registration number
The BaFin has warned about a website offering crypto-asset services without authorisation and speaks of a presumed identity theft at the expense of a real US company. The case shows why the advice to look a provider up in the register does not carry on its own.
September 23, 2026 10:32 AM

Switching crypto exchange: what happens to the holding period and the tax when you transfer
A transfer to another exchange or to your own wallet triggers no tax and does not reset the one-year period. What does get lost is the acquisition data, and that is exactly what you need later as evidence.
September 14, 2026 1:27 PM

Bitcoin Lost to a Scam: What Counts as a Tax Loss in Austria
Lost bitcoin to a scam? Why Austria generally does not recognise the damage as a tax loss for privately held assets, and when compensation payments start to matter.
September 5, 2026 10:24 PM

Fake German Finance Ministry Letters: Why Nobody May Demand 19 Percent VAT on Your Crypto Purchase
Since September 1, 2026, Germany's Federal Ministry of Finance has been warning about forged letters that demand 19 percent VAT on cryptocurrency purchases while citing real transactions. That tax does not exist, and this is how to spot the forgery.
August 11, 2026 9:18 AM

Your Crypto Exchange Is Telling You to Withdraw: How to Spot Phishing After the MiCA Deadline
Unauthorised crypto providers now have to tell their EU customers to withdraw, which leaves fraudsters an easy run with faked requests. Here is how to check in two minutes whether the message is genuine.
September 28, 2026 10:26 AM

Phantom Wallet and Solscan: What a Solana Transfer Really Costs and Where It Fails
A transfer on Solana costs 0.000005 SOL, a new token account ties up 0.00148844 SOL once — both values measured on-chain by us today. This practical guide shows how to set up Phantom, how to get there from the exchange, how to read Solscan and what applies for tax in Germany.
More from CryptoTicker


