Fifteen victims have been drained of a combined $9.4 million over the past four weeks by a single address poisoning operator.
On-chain investigator Specter (@SpecterAnalyst) flagged the losses on August 27. The stolen balances were swapped into $USDD, a Tron-based stablecoin, then funneled to one consolidation wallet.
How do address poisoning scams work?
A single scammer has stolen $9.4 million from 15 victims on the Tron network over the past four weeks using a simple trick called “address poisoning,” according to on-chain investigator Specter, who posts as “SpecterAnalyst” on X.
The two biggest victims lost $2.5 million each. The stolen funds were swapped into $USDD, a stablecoin on Tron, and moved to one main wallet.
Analyst Stacy Muur (@stacy_muur) explained on August 26 that address poisoning begins when an attacker sends tiny amounts of crypto from fake addresses that look almost identical to real ones the victims have used before. These transactions are called dust transactions.
When users copy these fake addresses from their transaction history, they send their money straight to the thief instead of the intended recipient.
Because blockchain addresses are long strings of letters and numbers (42 characters for Ethereum), most wallets only show the first and last few characters, and users get used to recognizing addresses by just those visible parts.
On August 22, investment firm Bofur Capital lost about $2 million to this exact trick. The attacker sent 0.0002 $USDC from a fake address 20 hours before the real transfer.
When Bofur pulled money from the lending platform Compound, they copied the wrong address from their history. The thief swapped the stolen $USDC into the DAI stablecoin to avoid having the funds frozen.
Can wallets protect against address poisoning?
MetaMask, which is owned by Consensys, and Trust Wallet have added protections against this attack, but their safety features work mainly on EVM chains like Ethereum, BNB Smart Chain, Polygon, and so on, not Tron.
MetaMask now shows a warning if an address’s first and last four characters match a previous recipient while the middle is different.
Trust Wallet launched “Address Poisoning Protection” in March, which checks every address against a database of known scam addresses and shows a side-by-side comparison if it finds a match.
Trust Wallet says it has detected over 225 million poisoning attempts, with more than $500 million confirmed stolen. That’s about 34,000 attacks every hour. Cryptopolitan has documented that the cheaper gas fees on Ethereum make mass dust transactions economically viable and even inflate the network’s daily transaction counts.
Cryptopolitan also reported that after a $50 million theft in December, Binance founder Changpeng Zhao called for all wallets to check for poison addresses and block them.
Until every wallet implements security features on every chain, users must protect themselves by verifying every character in the address and save trusted addresses in wallet address books instead of copying from history. Users can also send a small test transaction first when moving large amounts.