If two records in your wallet history look almost identical, one of them is likely a "poisoned" address. This attack exploits the habit of checking only the first and last characters and copying addresses from transaction history. The truly safe approach is to abandon visual comparison and use tools and an address book.

A leading global cryptocurrency platform,suitable for both beginners and experienced traders.
New user benefit: 20% off trading fees upon registration!!
1. Understand How Address Poisoning Traps You
The attacker generates a fake address with the same first and last characters as an address you frequently interact with, then sends a tiny amount (usually 0.00000x tokens) to your wallet.
This "dust transaction" appears in your transaction history, right next to your genuine transfers. Next time you send funds, you habitually copy an address from history, see the same start and end, paste it—and the money goes to the attacker.
This isn't "hacking" your wallet; it's exploiting human routine.
Prerequisite: You are logged into your wallet, about to make a transfer, and the destination address looks "almost identical" to one in your history.
2. Don't Trust Your Eyes — Compare Character by Character, or Use a Tool
Step 1: Verify the Full Address, Not Just the Beginning and End
What to do: Compare every character of the target address, not just the first and last few characters.
How to do it:
Place the two addresses (the one provided by the recipient vs. the one in your history) side by side.
Compare character by character, not just the start and end. Attackers typically change only a few characters in the middle, impossible to notice with a quick glance.
If your wallet supports ENS (e.g., xxx.eth), use domain names instead of long addresses — this completely eliminates the risk of address tampering.
When you're done: You have confirmed that every character of the target address matches the original address provided by the recipient.
Step 2: Use Your Wallet's Address Book or History Filtering Tools
What to do: Don't copy addresses from transaction history every time. Save frequently used addresses into your wallet's Address Book.
How to do it:
In imToken, go to [Me] → [Address Book] and save your frequently used addresses.
When sending, select from the address book instead of copying from history.
When you're done: All addresses you transact with regularly are saved in the address book, and you prioritize the address book over history for every transfer.
3. If the Address Appears in History, Use Built-in Detection
Major wallets now include built-in address poisoning detection that alerts you automatically when you paste an address.
Step 3: Use Your Wallet's Protection for Real-Time Detection
What to do: If you're using a wallet that supports address poisoning detection (such as MetaMask, Trust Wallet, imToken), watch for warning pop-ups after entering an address.
How to do it:
MetaMask: Launched the feature in June 2026; it automatically compares the pasted address with your historical interactions and shows a blocking alert if the start and end match but the middle differs.
Trust Wallet: Supports real-time detection across 32 major blockchains; for high-severity threats, it displays a side-by-side address comparison so you can clearly see the differences.
If you see any "suspicious address" or "address poisoning" pop-up, cancel the transaction immediately — do not proceed.
When you're done: You haven't bypassed any security warning to submit the transaction. If you receive an alert, obtain the recipient address again from an official source.
4. If the Address Is in History and You're Still Unsure, Verify with a Second Tool
Step 4: Scan with a Dedicated Address-Checking Tool
What to do: Use a third-party tool that supports address poisoning detection to perform an on-chain check before submitting the transaction.
How to do it:
Use a tool like @hexora/address-guard, which scans your wallet's recent transaction history, identifies zero-value transactions or spoofed addresses with similar start/end characters, and gives a risk score (confidence score).
If the tool returns scam: true, absolutely do not transfer to that address.
When you're done: The tool returns a risk level of "none" or "low" for the address, confirming it's safe before you proceed.

A leading global cryptocurrency platform,suitable for both beginners and experienced traders.
New user benefit: 20% off trading fees upon registration!!
Common Reason for Failure
"I only checked the first and last few characters and assumed they were the same" — this is the sole reason address poisoning succeeds. When an attacker generates a fake address, their only goal is for it to "look similar." If you don't verify the full string, you're at risk.
Risk reminder: Once a blockchain transaction is broadcast, it is irreversible. If you send to a fake address, no customer support can recover your funds. According to Blockaid, between January 2025 and February 2026, there were over 65.4 million address poisoning attacks; Trust Wallet detected over 225 million poisoning attempts, with confirmed losses exceeding $500 million.
After completing the above steps, how to confirm an address is safe?
Before sending, verify the recipient address through two independent channels: one is the address sent to you via instant messaging; the other is an address published on a public social platform (such as Twitter or official website). If the addresses from both sources match exactly, proceed with the transaction. If you use the address book and the address has successfully received funds from you before and has never changed, you can use it with confidence.


