📈 Get daily crypto insights that make you smarter about your money

$70 Million Wrapped Bitcoin Stolen in Address Poisoning Attack Targeting Ethereum Users

On May 3, 2025, blockchain security analysts uncovered a devastating address poisoning attack that resulted in the theft of approximately $70 million worth of Wrapped Bitcoin (WBTC) from an unsuspecting Ethereum user. The incident, flagged by on-chain security monitor Scam Sniffer, represents one of the largest single-victim phishing losses recorded in 2025, underscoring the persistent and evolving threat posed by address spoofing campaigns across the crypto ecosystem.

The Exploit Mechanics

Address poisoning—also known as address spoofing—is a deceptive technique in which attackers generate wallet addresses that closely resemble those a victim frequently transacts with. The fraudulent addresses share the same first and last several characters as the legitimate recipient, making them nearly indistinguishable at a glance. Attackers seed the victim’s transaction history with these look-alike addresses by sending small token transfers, ensuring the fake addresses appear in the wallet’s recent activity.

When the victim later initiates a transfer, they often copy the address from their transaction history rather than manually verifying the full string. In this case, the victim was tricked into sending a massive WBTC transaction to a spoofed address that mimicked their intended recipient. Given that WBTC was trading near Bitcoin’s price of approximately $95,891 at the time, the stolen amount represented hundreds of wrapped BTC tokens. The attack exploited no smart contract vulnerability—instead, it weaponized human behavior and the limitations of how most users interact with wallet interfaces.

Affected Systems

The attack targeted the Ethereum network, where WBTC operates as an ERC-20 token backed 1:1 by Bitcoin. The victim’s wallet had recently interacted with WBTC contracts, and the attacker used this transaction pattern to craft convincing spoofed addresses. Address poisoning attacks typically exploit the default display settings of popular wallet applications and block explorers, which truncate long hexadecimal addresses to show only the first four and last four characters. This truncation makes visually distinguishing between legitimate and poisoned addresses extremely difficult without explicit verification.

This incident is part of a broader surge in address-based scams throughout 2025. Blockchain analytics indicate that phishing and address poisoning attacks have accelerated significantly, with losses from such scams contributing to the over $333 million lost to crypto crime in April 2025 alone. The sophistication of these attacks has increased as attackers deploy automated tools to generate vanity addresses that match target patterns within seconds.

The Mitigation Strategy

Preventing address poisoning attacks requires a multi-layered approach. First, users must verify the complete wallet address—every single character—before confirming any transaction, especially large transfers. Second, wallet developers should implement address book features with verified entries, eliminating the need to copy addresses from transaction histories. Third, the crypto community is increasingly adopting ENS (Ethereum Name Service) domains and Unstoppable Domains as human-readable alternatives to hexadecimal addresses, reducing the attack surface for spoofing.

Several security tools now offer real-time address checking. Scam Sniffer, the same platform that flagged this WBTC attack, provides browser extensions that cross-reference destination addresses against known malicious patterns. Hardware wallet users benefit from on-device confirmation screens that display full addresses, creating an additional verification layer that software wallets cannot replicate.

Lessons Learned

The $70 million WBTC theft reinforces a critical truth in the cryptocurrency space: the most sophisticated security infrastructure can be rendered useless by a single moment of human error. Address poisoning succeeds not because of technical brilliance but because it exploits the gap between what users see and what is actually happening. As Bitcoin trades above $95,000 and the total crypto market cap exceeds $3.2 trillion, the financial stakes of even minor lapses in verification have never been higher.

The incident also highlights the urgent need for wallet developers to rethink how addresses are displayed and selected. Truncated address displays, while cleaner, create a false sense of security. The industry must prioritize UX designs that make verification intuitive rather than burdensome.

User Action Required

Every crypto user should take immediate steps to protect against address poisoning. Set up an address book in your wallet for frequent recipients and use it exclusively. Enable any available address verification features. Consider registering an ENS domain for your primary wallet. For transactions exceeding $10,000, perform a test send of a small amount first and confirm receipt before executing the full transfer. If you use a hardware wallet, always verify the full address on the device screen before signing. The five seconds it takes to check an address can save millions.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Always conduct your own research before making any financial decisions.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

25 thoughts on “$70 Million Wrapped Bitcoin Stolen in Address Poisoning Attack Targeting Ethereum Users”

  1. metamask truncating to 4 and 4 characters in 2024 is negligent. hardware wallets solved this years ago but browser extensions still havent caught up

  2. 70M stolen with zero smart contract exploit. just a spoofed address that looked like the real one. humans are always the weakest link

  3. Amara Diallo

    wallets need to stop truncating addresses by default. showing first 4 and last 4 chars is what makes these attacks possible

  4. Amara Diallo exactly. metamask and phantom both show truncated addresses. hardware wallets at least show the full string on device

    1. hardware wallet showing the full address on device is the only reliable check. but even then people skip the verify step because its annoying. $70M because someone copy pasted from their tx history

      1. verify_chars_ 70 million because someone copied from their tx history instead of checking the full address on a hardware wallet. the lookalike address trick is brutally effective

    2. phish_sad_ metamask and phantom show truncated addresses by default. hardware wallets at least show the full string. wallet UX needs to prioritize security over convenience

      1. Jin-woo L. hardware wallets showing the full address on device is the only fix but even Ledger and Trezor truncate on small screens. 70M because someone trusted the first and last 4 chars

    1. one address poisoning attack wiped out more than most protocols hold in their entire treasury. user education is the weakest link in crypto security by far

  5. $70M stolen because someone copy-pasted from their tx history instead of verifying on hardware. address poisoning is the dumbest way to lose life-changing money

  6. the attacker generated a lookalike address matching first and last characters. MetaMask truncates to 4 and 4 chars. that UX choice directly enabled this theft

    1. checksum_audit_

      Yuna K. ENS would have prevented this entirely. paying a $5 gas fee to register a human-readable name vs losing $70M to a hex character mismatch. brutal ROI calculation

      1. checksum_audit_ ENS costs 5 dollars a year and prevents this entirely. 70M lost because someone was too lazy to register a name

  7. 70M gone because metamask shows 4 chars on each end. wallet UX literally designed the attack surface. ENS should be default not optional

  8. address poisoning works because humans pattern match. first 6 and last 4 characters look right so people hit send. the only fix is ENS or reading every character on a hardware wallet screen

    1. ens_maximalist_

      this is why ENS exists. no human can eyeball 42 hex characters. 70m stolen from a single victim via address poisoning should be the case study for human-readable addresses

      1. ens_advocate_

        ens_maximalist_ 70M stolen because humans cant read 42 hex characters properly. ENS should be mandatory for any address handling, period

  9. 70M stolen and the victim probably verified the first 6 characters thinking that was enough. address poisoning is the most low-tech attack vector for the biggest losses

    1. Bruna C. attackers can match 8 characters now with vanity address tools. checking first 4 and last 4 is useless. ENS or full 42 char verification is the only option

      1. vanity address tools can match 8 characters in under 10 minutes on a laptop. checking first 4 last 4 is literally useless now

      2. relay_gas_ vanity tools can match 8 chars in minutes now. checking first 4 and last 4 has been insufficient since 2023. anyone moving size without ENS is playing roulette

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$64,276.00-1.4%ETH$1,876.27-2.5%SOL$75.87-1.6%BNB$600.17-1.2%XRP$1.02-2.0%ADA$0.1947-1.2%DOGE$0.0695-1.5%DOT$0.8040-0.8%AVAX$6.48-0.6%LINK$8.29-0.6%UNI$3.94-2.6%ATOM$1.40+1.1%LTC$45.15-2.7%ARB$0.0801+2.2%NEAR$1.63-0.1%FIL$0.6962-2.1%SUI$0.6883-1.6%BTC$64,276.00-1.4%ETH$1,876.27-2.5%SOL$75.87-1.6%BNB$600.17-1.2%XRP$1.02-2.0%ADA$0.1947-1.2%DOGE$0.0695-1.5%DOT$0.8040-0.8%AVAX$6.48-0.6%LINK$8.29-0.6%UNI$3.94-2.6%ATOM$1.40+1.1%LTC$45.15-2.7%ARB$0.0801+2.2%NEAR$1.63-0.1%FIL$0.6962-2.1%SUI$0.6883-1.6%
Scroll to Top