The decentralized finance ecosystem suffered yet another security breach as Florence Finance, a real-world asset (RWA) lending protocol, fell victim to an address poisoning attack that resulted in the loss of approximately $1.45 million worth of USDC. The incident, reported by blockchain security firm PeckShield, highlights the growing sophistication of social engineering tactics deployed against DeFi protocols and their operators.
The Exploit Mechanics
Address poisoning, also known as address spoofing, is a deceptive technique that exploits human oversight rather than smart contract vulnerabilities. In the Florence Finance attack, the perpetrator first generated a wallet address that closely resembled the protocol’s legitimate transaction partner address — sharing identical first and last characters while differing in the middle segments.
The attacker then sent a small amount of fake or dust tokens from this spoofed address to the Florence Finance treasury wallet. This transaction appeared in the protocol’s transaction history, creating a convincing decoy. When the Florence Finance team initiated a legitimate transfer of $1.45 million in USDC, they inadvertently copied the attacker’s address from their transaction history instead of the intended recipient, routing the funds directly to the scammer.
This type of attack preys on the common practice of copying wallet addresses from recent transaction records rather than verifying each character independently. With Ethereum-style addresses spanning 42 characters, most users only glance at the first few and last few characters — exactly the elements that the attacker matched.
Affected Systems
Florence Finance operates as a lending protocol focused on real-world asset tokenization, bridging traditional finance instruments with DeFi infrastructure. The protocol allows users to supply liquidity that is deployed against tokenized real-world assets such as invoices and credit instruments.
The $1.45 million USDC loss represents a significant portion of the protocol’s operational capital. USDC, as a fully-reserved stablecoin pegged to the US dollar, is the primary medium of exchange within the Florence Finance ecosystem. The attack compromised the protocol’s ability to process lending operations at full capacity during a period when Bitcoin was trading around $37,831 and the broader crypto market was experiencing renewed bullish sentiment.
The breach occurred during November 2023, which has emerged as the worst month for crypto hacks in 2023, with over $363 million stolen across multiple incidents. High-profile exploits including the Poloniex hack ($100 million) and the KyberSwap Elastic vulnerability ($48 million) contributed to a devastating month for DeFi security.
The Mitigation Strategy
Following the detection of the attack, blockchain security analysts recommended several immediate countermeasures. First and foremost, protocols should implement address verification systems that compare the full destination address character-by-character before executing high-value transfers. Automated whitelist contracts can ensure that funds only flow to pre-approved addresses that have undergone multi-signature verification.
Additionally, DeFi teams are advised to implement secondary confirmation steps for transactions exceeding a specified threshold. This could include a time-lock mechanism that delays execution by several hours, providing a window for review and potential cancellation. Hardware wallet integrations with address book features offer another layer of protection by storing verified addresses independently of the transaction history.
Industry-wide solutions being explored include ENS (Ethereum Name Service) adoption for protocol-level addresses, reducing reliance on hexadecimal strings. Some security firms have also developed browser extensions that detect and flag suspiciously similar addresses in transaction histories.
Lessons Learned
The Florence Finance incident reinforces a critical reality: the weakest link in DeFi security is often human rather than technical. While smart contract audits and formal verification protect against code-level exploits, address poisoning attacks bypass these defenses entirely by targeting operational practices.
Protocols managing large treasuries must treat address verification with the same rigor applied to smart contract security. The cost of implementing robust address verification infrastructure is negligible compared to the potential losses from a single successful poisoning attack.
The attack also underscores the importance of real-time monitoring tools. Blockchain analytics platforms like PeckShield, CertiK, and Cyvers can detect suspicious address patterns and alert protocols before funds are transferred. Early warning systems that flag newly created addresses matching existing counterparties could have prevented this $1.45 million loss entirely.
User Action Required
For users interacting with DeFi protocols, the Florence Finance hack serves as a stark reminder to verify every transaction destination thoroughly. Never copy wallet addresses directly from transaction histories without cross-referencing the full address string. Use address books built into hardware wallets or trusted software wallets, and enable any available address verification features on the platforms you use. If you are a liquidity provider on Florence Finance or similar RWA protocols, monitor official communications for updates on remediation efforts and any planned compensation distributions. Stay vigilant — as the crypto market continues to rally with Bitcoin above $37,000 and Ethereum near $2,050, the incentive for attackers only grows stronger.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Always conduct your own research before engaging with any DeFi protocol.
1.45m gone because someone copy-pasted from transaction history. not even a smart contract bug, just human error. brutal
rekt_onc_ $1.45M gone from a copy paste error. no smart contract exploit needed. the human element is always the weakest link
^ the dust tx trick is slick. most people never verify the full middle characters of an address before hitting send
nonce_wraith the dust tx trick works because most wallets only show first and last 4 chars. hardware wallets with full address display should be mandatory for treasuries
$1.45m and they couldnt afford a $200 hardware wallet with address book features. this is treasury management 101
hardware wallet with address book would have prevented this entirely. $200 device saves $1.45M. the ROI is insane
every treasury team should use ENS or a similar name service instead of raw hex addresses. the fact that we still copy paste 42 character strings in 2023 is absurd
Address poisoning is one of those things that sounds dumb until it happens to your team. The spoofed addresses are genuinely hard to spot when you are moving fast.
worked in ops for a defi protocol. we started requiring full address paste from a secure doc, no copying from history. takes 10 extra seconds but prevents exactly this
vlad is right. we implemented the same full-paste-from-secure-doc rule after a near miss. the problem is it slows down every transfer by 2 minutes and ops people start cutting corners under pressure. you need tooling that enforces it
Vlad N. same. our treasury ops started using a signed address book in notion after a near miss. zero copy paste from transaction history anymore
1.45M gone because someone copy-pasted from tx history instead of verifying the full address. hurts to read but this happens way more than people think
address poisoning is one of those attacks that sounds dumb until you realize how easy it is to fall for. the dust tx looks identical at a glance
^ exactly. everybody thinks theyre too smart for it until theyre moving 7 figures at 2am and their eyes glaze over checking hex strings
November 2023 was absolutely brutal. Poloniex lost $100M, KyberSwap $48M, and now Florence Finance $1.45M. Over $363M in one month. The Florence one stings most because it wasn’t even a code bug, just someone copying the wrong address from their tx history
Sanjay Mehta november 2023 was genuinely the worst month for defi since terra. kyberswap was the one that scared me most because the attacker used the protocol mechanics against itself
Sanjay Mehta is right, November 2023 was brutal. $363M lost to copy-paste errors is insane.
the most devastating part about address poisoning is it costs basically nothing to execute. send one dust transaction with a lookalike address and wait. no contract hack needed, no exploit, just basic human pattern recognition working against you
the wild part is address poisoning costs literally nothing to execute. just send a tiny dust tx to create a lookalike address and wait for someone to copy paste. 1.45m for a 0.01 dollar attack cost
opsec_lapse 0.01 dollar attack cost for 1.45M return. the asymmetric economics of address poisoning make it the perfect scam. no code to audit, no contract to exploit, just human pattern matching working against you
Treasury teams need ENS names with verified addresses. Copy-pasting hex strings is begging for this to happen.
Our protocol now requires 2-factor verification for all treasury transfers. This attack would have been caught.
1.45M USDC lost because someone copy pasted from tx history. every treasury team should mandate ENS resolution at this point
aino ENS helps but even ENS can be spoofed with lookalike names. the only real fix is hardware confirmed address books
370758 ENS can be spoofed with lookalike characters. vitalik.eth vs vitallik.eth. the real fix is hardware wallet address book confirmation, period
1.45M lost because someone copy pasted from tx history. every DeFi DAO treasury should require multisig with a pre loaded verified address book. this is solved infrastructure
address poisoning attack cost is literally the gas to send one dust transaction. under a dollar on most L2s. 1.45M return on a $0.50 attack. treasury teams have no excuse