A crypto user has lost approximately 100,000 $USDT after transferring the funds to a lookalike wallet address planted in the victim’s transaction history 66 days earlier.
Cyvers Alerts reported on Aug. 11 that its monitoring system detected the loss after the victim sent funds to an address controlled by an attacker.
🚨ALERT🚨Our system has detected an address poisoning attack resulting in a $100k solana:Es9vMFrzaCERmJfrF4H2FYD4KCoNkY11McCe8BenwNYB
— 🚨 Cyvers Alerts 🚨 (@CyversAlerts) August 11, 2026
The scammer initially poisoned the victim’s wallet around 66 days ago, and today, the victim unknowingly sent funds to the scammer’s address.
To… pic.twitter.com/8CtOeJLfIn
How the $100K address poisoning attack unfolded
About 66 days before the theft, the attacker sent transactions involving the victim’s wallet, according to Cyvers. The activity placed a malicious address in the wallet’s transaction history, where it appeared similar to an address the victim had used for a normal transfer.
When the victim later prepared the 100,000 $USDT payment, Cyvers said the user relied on the historical record without comparing the complete destination address. The funds consequently went to the lookalike address rather than the intended recipient.
Address poisoning does not require an attacker to obtain a private key, compromise a smart contract, or take control of the victim’s wallet. Instead, the method depends on the length and format of blockchain addresses, which many wallets and block explorers shorten by displaying only their first and last characters.
Attackers generate addresses that match the visible parts of a recipient’s genuine address and then use small or zero-value transfers to place the imitation in a target’s transaction record. A user who checks only the opening and closing characters can therefore select the attacker’s wallet even though the complete strings are different.
In the latest case, Cyvers attributed the loss to the victim’s failure to check the full address. The security company advised users not to treat transaction history as a trusted address book and recommended verifying every character before approving an on-chain payment.
Attacker converts stolen $USDT into 52.8 $ETH
Following the transfer, the attacker exchanged the stolen $USDT for Ethereum, Cyvers reported. The receiving wallet held approximately 52.8 $ETH when the security company published its alert.
Cyvers said the conversion appeared designed to reduce the risk that the stolen stablecoins could be frozen. $USDT is issued by Tether through smart contracts that allow specific addresses to be blocked, while native $ETH does not have an issuer with an equivalent freezing function.
The conversion also means the value of the attacker’s holdings can change with the $ETH market price. Cyvers did not report any recovery, return agreement, or exchange intervention in its initial alert, nor did the company identify the victim publicly.
No evidence cited in the alert suggested that a flaw in Tether, Ethereum, or the victim’s wallet software caused the transfer. Cyvers instead described the incident as a social-engineering attack that used a forged address record to exploit the victim’s payment habits.
Address poisoning losses have reached millions
The $100,000 incident follows several larger cases involving the same method. In February, crypto.news previously reported that two users had lost a combined $62 million after copying fraudulent addresses from their transaction histories.
Scam Sniffer attributed about $50 million of that total to a December 2025 incident, while another victim lost approximately $12.25 million, or around 4,556 $ETH at the time, in January 2026. The security company said attackers had quietly inserted lookalike addresses into both victims’ recent activity records.
During the December case, a stablecoin holder first sent a 50 $USDT test payment to the correct destination. An attacker then inserted a fraudulent address into the history with a 0.005 $USDT dust transaction, after which the victim mistakenly sent 49,999,950 $USDT to the poisoned address.
The stolen assets were converted into $ETH and spread across several wallets, according to an earlier report on the theft. The victim later offered the attacker a $1 million bounty for the return of the remaining funds and threatened to involve international law enforcement.
Low transaction costs have also made automated poisoning campaigns cheaper to operate. Scam Sniffer said in February that millions of dust transactions were being sent each day, with many created to prepare for possible future thefts rather than move funds between genuine users.
In March, a stablecoin user reported receiving 89 poisoning alerts within 30 minutes after completing only two legitimate transfers. Former Binance CEO Changpeng Zhao subsequently criticized transaction explorers that continued to display the malicious entries.
US lawmakers have proposed a crypto fraud task force
For U.S. users, address poisoning falls within a growing category of digital-asset fraud that lawmakers have sought to address through interagency coordination. Senators Elissa Slotkin and Jerry Moran introduced the bipartisan Strengthening Agency Frameworks for Enforcement of Cryptocurrency Act, known as the SAFE Crypto Act, in 2025.
According to the bill’s sponsors, the proposed legislation would establish a federal task force focused on identifying, monitoring, and preventing cryptocurrency scams. Its members would include representatives from government agencies, law enforcement, digital-asset companies, stablecoin issuers, blockchain intelligence firms, and consumer-protection organizations.
The proposal covers several forms of crypto crime, including investment fraud, money laundering, Ponzi schemes, rug pulls, and fraudulent token sales. Sponsors said the task force would examine scam patterns and improve coordination between federal authorities and private-sector specialists.
The bill does not create a reimbursement program for users who mistakenly authorize irreversible transfers. As earlier coverage explained, its proposed task force would focus on detection, disruption and cooperation among agencies and industry participants.
Full address checks can expose poisoned records
Cyvers advised users to compare complete wallet addresses rather than relying on shortened records in transaction histories. For large transfers, security specialists also recommend confirming the destination through a separate communication channel and sending a small test amount before moving the remaining balance.
A test payment alone may not prevent a poisoning attack, as the December 2025 theft demonstrated. Because an attacker can insert a lookalike address immediately after the test, the sender must verify that the address used for the main transfer is identical to the one used for the test transaction.
Address whitelists can add another check by limiting withdrawals to destinations approved in advance. Hardware wallets can also display transaction details before signing, though users must still read and compare the destination shown on the device.
Wallet interfaces and blockchain explorers have started filtering suspicious entries, but the protections vary by platform. A March report found that Etherscan hid zero-value transfers by default, while BscScan and Basescan required users to activate a “hide 0 amount tx” option to remove such records from view.
coinedition.com
cryptoticker.io
decrypt.co
u.today