📈 Get daily crypto insights that make you smarter about your money

Address Poisoning Attacks Surge: How a Million Theft Was Reversed

On May 11, 2024, the cryptocurrency community witnessed both the devastating potential and surprising resilience of the ecosystem when a victim of a $71 million address poisoning attack recovered approximately $66.8 million in stolen funds. The incident, which involved wrapped Bitcoin tokens transferred to a spoofed address, serves as a stark reminder that sophisticated social engineering attacks remain a primary threat to crypto holders, even as the market trades near all-time highs with Bitcoin at $61,448.

The Threat Landscape

Address poisoning attacks represent one of the most deceptively simple yet effective vectors in the crypto security space. The technique involves spamming a target wallet with transactions from addresses that closely resemble the victim frequently used addresses. By generating addresses that share the same first and last few characters as legitimate counterparts, attackers create a false trail in the transaction history. When the victim later copies an address from their transaction history rather than verifying it character by character, they inadvertently send funds to the attacker wallet. In this case, the victim transferred $71 million worth of wrapped Bitcoin (WBTC) to an address that mimicked their intended destination. The attack was particularly notable for its scale, representing one of the largest address poisoning incidents recorded.

Core Principles

The recovery of $66.8 million highlights several important security principles. First, rapid response and professional negotiation play a crucial role in fund recovery. Match Systems CEO Andrei Kutin, working with Cryptex, led negotiations that ultimately persuaded the attacker to return the majority of stolen assets. Second, the attacker converted WBTC to ether during the holding period, meaning the recovered amount was slightly lower in dollar terms despite representing most of the original tokens. Third, the growing willingness of attackers to negotiate may be influenced by the conviction of Avraham Eisenberg for fraud related to the Mango Markets exploit, which demonstrated that law enforcement can successfully prosecute crypto crimes. CertiK reported that April 2024 saw the lowest scam losses since March 2021, suggesting that deterrence mechanisms are beginning to take effect.

Tooling and Setup

Protecting against address poisoning requires a multi-layered approach. Hardware wallets like Trezor and Ledger provide an additional verification step by displaying full receiving addresses on their screens. Address book features in wallets like MetaMask allow users to save and label frequently used addresses, eliminating the need to copy from transaction history. Browser extensions and security tools from firms like Blowfish and Blockaid can detect suspicious address patterns and warn users before they complete a transaction. For institutional users, multisignature wallets add an approval layer that can catch poisoned addresses before funds are dispatched. The DEA itself lost $55,000 in an address poisoning scam in May 2024, proving that even experienced users are vulnerable.

Ongoing Vigilance

The broader trend in crypto security shows improvement even as attack volumes remain significant. Immunefi data reveals that total losses in May 2024 reached $52 million across 14 incidents, with Ethereum accounting for 43% of attacks and BNB Chain for 19%. DeFi platforms bore the brunt, while centralized finance platforms experienced zero major incidents. Hacks dominated at $50 million versus just $1.7 million from fraud, suggesting that technical exploits rather than social engineering remain the primary loss vector at the protocol level. However, for individual users, address poisoning and phishing remain the most direct threats.

Final Takeaway

The $71 million address poisoning incident and its partial resolution demonstrate that the crypto security ecosystem is maturing. Professional recovery services, improved wallet security features, and growing legal consequences for attackers are creating a more hostile environment for bad actors. Yet the fundamental vulnerability persists: human error in address verification. As long as users can be tricked into copying the wrong address, these attacks will continue. The simplest defense remains the most effective — always verify the complete address, character by character, before sending any funds. With Bitcoin at $61,448 and Ethereum at $2,928, the stakes of a single transaction error have never been higher.

Disclaimer: This article is for informational purposes only and does not constitute financial advice. Always conduct your own research before making investment decisions.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

26 thoughts on “Address Poisoning Attacks Surge: How a Million Theft Was Reversed”

  1. glad they got $66.8M back but lets be real, thats the exception. most address poisoning victims never see a sat again

    1. the attacker generated matching first/last chars on a 42-char address. bots can brute force that in seconds. scary part is how automated this has become

      1. matching first and last 4 chars on a 42 char address takes the attacker about 15 seconds with modern GPUs. the ease of automation is what makes this so dangerous

        1. Rui C. 15 seconds on modern GPUs to match first and last 4 chars. and thats before you account for vanity address tools that can pre-generate thousands of lookalikes

        2. Rui C. 15 seconds on a GPU to match 4 chars. vanity address tools can brute force 6-8 matching chars on both ends now. checking first and last 4 is officially dead advice

          1. Karlitos M. vanity tools can match 6-8 chars now. checking first and last 4 is useless advice at this point. wallets need to show full addresses or at minimum highlight the checksum portion

    2. use an address book. whitelist your frequent contacts. takes 2 minutes to set up and makes this entire attack vector useless

      1. address books should be built into every wallet by default. the fact that most wallets still dont have this in 2026 is embarrassing

        1. Pavel G. hardware wallets have had address books for years. the problem is software wallets optimize for UX over safety and users just click through warnings

  2. deadcatbounce

    imagine checking your wallet and seeing a $71M oopsie because you copied an address from history instead of your address book. cold sweat material

    1. deadcatbounce a 71M oopsie from copying the wrong address. the victim got 66.8M back which is basically a miracle. most poisoning victims get zero

      1. Eline V. 66.8M recovered because the attacker returned it, not because of any protocol mechanism. next victim wont be so lucky. address poisoning has maybe a 5 percent recovery rate

    2. zero_checksum_

      deadcatbounce 71M because someone copied from tx history instead of verifying. wallets need to stop truncating addresses by default. show the full string or at least highlight the checksum chars

  3. victim got 66.8M back out of 71M. that only happens because the attacker got spooked by on-chain tracing. chainalysis watching the wallet in real time forced the return

  4. hexcheck_daily_

    checking first 4 and last 4 chars of an address is not enough. these poisoning attacks generate thousands of lookalikes. verify the full string every time or use ENS

  5. checking first AND last 4 chars is not enough anymore. modern poisoning attacks match 6-8 chars on both ends. always verify the full address or use ENS

  6. Double-check every address character by character. The 30 seconds it takes is worth more than any transaction you will ever make.

  7. 66.8M recovered because the attacker basically returned it. that is not a security feature it is a miracle. the next victim of address poisoning will not get a negotiation

  8. 15 seconds on a consumer GPU to match 4 chars on each end of an address. vanity address generators can do it in real time. the attack is basically free

  9. ens_maximalist_

    71M sent to a spoofed address because it looked similar. this is why ENS exists. no excuse for copying addresses from tx history in 2024

  10. 66.8M recovered out of 71M is a miracle. chainalysis traced the wrapped BTC fast enough to freeze it before the attacker could bridge. next victim wont be so lucky

  11. victim got 66.8M back out of 71M. thats basically a miracle. chainalysis real-time tracing is the only reason that money came back. next person wont be so lucky

  12. 71M sent to a spoofed wrapped BTC address and they got 66.8M back. that recovery is almost unheard of for address poisoning. someone negotiated hard

  13. address_book_risk

    hexcheck the problem is hardware wallets show the address on device but people still copy from their transaction history instead of verifying on the screen

  14. cold_storage_kev_

    15 seconds on a GPU to match 4 chars on each end. address poisoning will keep working until wallets stop showing truncated addresses entirely

    1. cold_storage_kev_ GPUs matching 4 chars in 15 seconds means even careful users get caught. wallets need to show the FULL address with checksums highlighted, not truncated previews

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$64,975.00+0.1%ETH$1,916.58-0.1%SOL$76.75+1.0%BNB$604.36+0.7%XRP$1.04-0.3%ADA$0.1971-0.8%DOGE$0.0700-0.8%DOT$0.8013-1.8%AVAX$6.49+0.4%LINK$8.26-0.7%UNI$4.03+0.7%ATOM$1.380.0%LTC$45.65-0.7%ARB$0.0789+0.6%NEAR$1.620.0%FIL$0.7042-1.3%SUI$0.6938+0.5%BTC$64,975.00+0.1%ETH$1,916.58-0.1%SOL$76.75+1.0%BNB$604.36+0.7%XRP$1.04-0.3%ADA$0.1971-0.8%DOGE$0.0700-0.8%DOT$0.8013-1.8%AVAX$6.49+0.4%LINK$8.26-0.7%UNI$4.03+0.7%ATOM$1.380.0%LTC$45.65-0.7%ARB$0.0789+0.6%NEAR$1.620.0%FIL$0.7042-1.3%SUI$0.6938+0.5%
Scroll to Top