Why Address Poisoning Only Uses Tiny Transfers

 / 
4

You notice a tiny amount suddenly appear in your wallet—don't panic. This usually does not mean your private key has leaked or your wallet is hacked. Instead, someone is "poisoning" your transaction history. Attackers spend just a few cents on gas fees to send a dust transaction of 0 USDT or less than $0.01 in USDC, planting a fake address that closely matches the first and last characters of an address you use often. The small amount itself is harmless. The real danger is that next time you copy an address from your history, you might accidentally copy this fake address and send your large assets straight to the attacker.

Step 1: Recognize a poisoning transaction and confirm it's not a security threat

What to do: Check if this small incoming transfer is a sign of an address poisoning attempt.

How to do it: Open your wallet or a block explorer and look at the details of this suspicious transaction. Compare it with these signs:

  1. Extremely small or zero amount: Usually a 0 USDT transfer (using the USDT contract's TransferFrom function, which does not need your private key signature) or a dust amount of USDT/USDC under $0.01.

  2. Receiving address looks like a familiar one: The attacker has generated a vanity address whose first and last characters match an address you use frequently, while only the middle part is different.

  3. The transaction shows as "sent" from you: Your wallet's transaction history will display a record of "you sending funds to this fake address," even though you never made that transfer.

How to know you've done it right: You can confirm that this tiny transfer was sent by someone you don't know, the amount is negligible, and the destination address looks "familiar"—in other words, it's a poisoning trace, not a real movement of your funds.

Why people often get confused: Many people see an unknown transaction and keep checking if their balance has decreased or worry about malicious contract approvals. This transaction does not touch any asset in your wallet. It only creates a fake history entry and waits for you to make a mistake later.

Step 2: Understand why attackers only send a tiny amount

What to do: Learn the real purpose behind that small payment.

How to do it: Break down the attack path with this logic:

  • Extremely low cost, extremely high reward: After Ethereum's Fusaka upgrade in December 2025, gas fees dropped significantly. Sending millions of poisoning transactions became very cheap. Dust USDT transfers surged 612% in the 90 days after the upgrade, jumping from 4.2 million to 29.9 million.

  • Waiting for you to make the mistake: The attacker doesn't need to hack anything. They simply do two things: create a fake address, and insert a fake record into your transaction history. Then they wait for you to copy an address from your history without checking every single character, and accidentally send money to the fake address instead of your friend or exchange.

  • One success pays for everything: The success rate of poisoning attacks is very low (estimates suggest about 0.01%), but a single hit can bring huge gains. In December 2025, a victim mistakenly sent 49.99 million USDT after copying a poisoned address. Total known stolen funds from these attacks have now exceeded $7.4 million.

How to know you've done it right: You understand that this tiny transfer is not designed to "steal your coins now," but to dig a trap you might step into in the future.

High risk note: Poisoning attacks are now running on a massive automated scale. In January 2026 alone, on-chain poisoning attempts hit 3.4 million, a 5.5x increase compared to before the upgrade. Attackers can automatically plant a poisoning transaction within minutes after you complete a legitimate transfer. Some active "dust dispenser" addresses can even send poison dust to over 400,000 addresses at once.

Step 3: Block the poisoning trap—how to operate safely

What to do: Stop relying on your transaction history to copy addresses, and use safer methods to send funds.

How to do it: Build these habits:

  1. Never copy an address from your transaction history. Addresses in your history may have already been poisoned.

  2. Check the full address, not just the first and last characters. Wallets often show abbreviated addresses—always open the full details and check every single character. Tools like the Binance wallet suggest verifying "first 4 + middle 4 + last 4" characters.

  3. Save frequently used addresses to your wallet's address book or contacts. When making a transfer, select from your address book instead of pasting manually.

  4. Enable the "hide small/zero-value transactions" setting in your wallet. Many popular wallets, such as imToken and SafePal, already support this feature. It automatically filters out low-value noise, reducing the risk at the source.

How to know you've done it right: You no longer copy addresses from your transaction history. Instead, you use an address book, a whitelist, or scan a QR code. When you see any small unknown incoming transfer, you can correctly identify it and ignore it without worrying.

A quick verification method: Before sending a large amount, send a tiny test transaction first (e.g., 1 USDT). Wait for the recipient to confirm receipt, then use the exact same address to send the remaining funds. If you already have a poisoning transaction in your wallet, simply turn on the "hide small transactions" function to filter it out—no other action is needed. The transaction itself does not affect the safety of your assets.