The scammer never touches your private keys. They don’t crack your wallet or phish your seed phrase. They just wait for you to copy the wrong address, and that’s the whole trick.
Binance, one of the largest crypto exchanges, has published a warning about address poisoning. It’s a scam that relies on lookalike wallet addresses and plain human error, and it doesn’t involve breaking into anything. “Not every crypto scam involves hacking,” Binance said in the post.
One bad paste is all it takes
The attack goes after a habit most active crypto users share. You send to the same few addresses over and over, so you stop typing them. You scroll back through your transaction history, find the one that looks right and copy it.
Address poisoning makes that habit a liability. “A single copy-paste mistake can send funds to a scammer — and blockchain transactions can’t be reversed,” Binance said.
That second half matters most. No bank will reverse the charge for you, and no support ticket brings the money back. Funds sent to a poisoned address may be unrecoverable.
How attackers plant the fake address
The setup is patient and methodical. First, the attacker finds a target wallet with a history of recurring transactions. According to Binance, the most frequent targets are active crypto users with larger balances.
Next, they generate a lookalike address that matches the first and last few characters of an address the victim regularly sends to. Automated tools handle that part. The attacker is betting on how wallets display addresses: abbreviated, with the middle cut out, so you only see the start and the end.
Then comes the poison. The scammer sends a small transaction, usually zero-value or a dust amount, from the fake address to the target wallet. It lands in the victim’s transaction history, sitting right next to the real entries.
The next time the victim goes to send funds, they scroll back, spot what looks like the familiar address and copy it. If they grab the poisoned one, the money goes straight to the attacker.
Which chains are exposed
Address poisoning attacks have been reported on many blockchains, including Ethereum, BNB Smart Chain and others that use long hexadecimal addresses. Binance’s reasoning is simple: any chain where addresses are long and routinely shown in shortened form is vulnerable.
That covers most of the places where people hold tokens and in-game assets. If your wallet shows you something like “0x1a2b…9f8e” and you trust it at a glance, you’re the person this scam is built for.
What Binance recommends
The exchange’s advice is short and unglamorous. Only send to full addresses, and only after you’ve verified them. Use address book allowlists so you’re pulling from a saved list instead of your transaction history. And send a small test transfer first before moving anything that matters.
None of that is new advice, and all of it adds friction. But the attack is built entirely on skipping those steps. Check every character of the address, not just the first four and last four, because matching those eight is exactly what the scammer paid a script to do.