Constatum
Security

Address Poisoning: The $50M Copy-Paste Scam

Constatum Team4 min read
A machined titanium bar on a dark background, shadowed by a faint, near-identical mirrored copy of itself, with a single orange warning notch glowing on its face.

On December 20, 2025, someone sent 49,999,950 USDT — just under $50 million — to the wrong address. No hack. No stolen key. They copied an address from their own transaction history and pasted it, the way they had a hundred times before. Twenty-six minutes earlier they had made a $50 test transfer to be safe. The scammer was watching, slipped a near-identical address into that history, and waited. One paste, and the money was gone. CoinDesk reported it as one of the largest single losses of its kind.

That is address poisoning. It isn't clever code. It's a trick that preys on one habit almost everyone in crypto shares: copying an address from a past transaction instead of getting it fresh. And in 2025 it stopped being rare.

How the trick works

An attacker first generates a "lookalike" address — one whose first few and last few characters match an address you use often. Cheap software brute-forces billions of keypairs until it finds a match for the parts your eye actually reads. Then they get that fake address into your transaction history so it sits right next to the real one.

There are three common ways they do it:

  • Zero-value transfers. The scammer sends a $0 transfer that appears to come from a spoofed lookalike of an address you trust. It needs no signature from you, so it simply shows up in your history. Later you scroll back, grab the address that "looks right," and send for real.
  • Dust. A tiny amount — a few cents — from the lookalike address. Same effect: it lands in your history looking like a normal past payment.
  • Clipboard hijacking. Malware on your device silently swaps the address you copied for the attacker's the moment you paste. You never see the switch.

The first two dominate because they cost the attacker almost nothing and scale to millions of targets at once.

It's not rare — it's industrial

Since January 2025, the security firm Blockaid has flagged more than 65 million address-poisoning transactions on-chain — over 160,000 a day. The vast majority fail. But roughly 316,000 of them worked: a real person sent real funds to a poisoned address. That's about 1 in every 200 attempts landing.

And the ones that land, land big. In May 2025, a trader lost $843,000 to a fake zero-value transfer — then, three hours later, sent another $1.75 million the same way, for about $2.6 million in total. The December $50 million loss is the record so far.

Why it targets the careful, not the careless

You would think this catches newcomers. It's the opposite. Poisoning pays off on wallets that move a lot, often — exchanges, OTC desks, treasuries, active traders. The more transactions in your history, the more places to hide a lookalike, and the more likely you're moving fast on muscle memory. Attackers even time it: they watch for a real transfer to a counterparty, then poison the history minutes later, so the fake is the freshest-looking entry when you come back to repeat the payment. The December loss followed exactly that pattern — a real test transfer, a planted address, a full send less than half an hour later.

The address is the whole story

Here is the uncomfortable part. On-chain there is no "undo," and no name is attached to an address. To your eye, the fake and the real look the same — matching at the start and the end, different only in the middle stretch you never check. Your wallet shows you something like 0x71C7…9F2A, and the impostor shows the same. That truncated preview is exactly what the scam is built on.

So the fix isn't a plugin or a product. It's a habit, plus one check.

What actually protects you

  • Never send from your history. Get the address from the person or the original source every time, even when it's slower. Your history is the one place the attacker controls.
  • Read the middle, not just the ends. Compare 6–8 characters from the middle of the address against a trusted source. That's the part a lookalike can't fake.
  • Test — then re-verify. A small test transfer is good, but confirm it arrived at the real destination and re-check the address before the large one. The $50 million victim did send a test; they just didn't look again.
  • Use an address book. Save addresses you reuse to a wallet allowlist, so you're picking a saved contact instead of scrolling raw history.
  • Screen before you release funds. On a business payment, or any address you didn't type yourself, check the address itself first. A quick screen shows whether it's tied to known scams, mixers, or sanctions — and it forces you to look at the full string instead of a truncated preview.

Address poisoning works precisely because it's boring. It doesn't break anything; it waits for a half-second of autopilot. The people losing millions aren't careless — they're fast. Slow down for the ten seconds it takes to read the whole address, pull it from the source instead of your history, and the most expensive copy-paste in crypto simply doesn't happen to you.

Sources

  1. 1.Crypto user loses $50 million in 'address poisoning' scamCoinDesk
  2. 2.Address Poisoning: The Growing Threat Draining Millions from Crypto UsersBlockaid
  3. 3.A Deep Dive into Address PoisoningBlockaid
  4. 4.Investor loses $2.6M in zero-transfer phishing scamCointelegraph
  5. 5.Anatomy of an Address Poisoning ScamChainalysis
  6. 6.Address poisoning detection now live in MetaMaskMetaMask
  7. 7.What Are Address Poisoning Attacks in Crypto and How to Avoid Them?Ledger Academy
  8. 8.Crypto trader loses $50M USDT to address poisoning scamProtos

This article is general information, not legal, tax, financial, or investment advice. Crypto carries risk — do your own research and consult a qualified professional before acting. Constatum makes no warranty as to accuracy or completeness and accepts no liability for decisions made based on it.

Keep reading