OFICIAL CoinGate Blog

Address Poisoning: How a Lookalike Address Steals a Crypto Payout

What happened
Based on CoinGate Blog · Oct 07, 2026

Address poisoning exploits copy-paste habits in crypto payouts, tricking users into sending funds to lookalike addresses that match only the first and last characters.

Address Poisoning: How a Lookalike Address Steals a Crypto Payout
CoinGate Blog — CoinGate
Key points
·
Address poisoning exploits copying addresses from past transactions without full verification of the string.
·
A 2024 Chainalysis analysis found 82,031 lookalike addresses targeting 2,774 wallets, with one victim losing 68 million dollars in wrapped bitcoin.
·
CoinGate mitigates risks via saved recipients, Payout Links, wallet ownership checks, and four-eye approval for batch payouts.
Key numbers
·
03% receiving over $100, yet one victim lost approximately 68 million dollars in wrapped bitcoin in a single transfer on May 3, 2024.

Address poisoning does not involve hacking wallets or systems; instead, it relies on users copying payment addresses from past transactions without verifying the full string. Attackers create lookalike addresses that match the first and last few characters of legitimate addresses, making the fraud easy to overlook during routine payments. The method targets businesses that frequently send crypto to the same recipients, as their transaction histories provide predictable patterns for attackers to exploit.

A 2024 campaign analyzed by Chainalysis deployed 82,031 lookalike addresses against 2,774 wallets, with only 0.03% receiving over $100, yet one victim lost approximately 68 million dollars in wrapped bitcoin in a single transfer on May 3, 2024. The victim later recovered the funds, but the incident highlights the potential scale of losses. The attack succeeds because crypto transactions are irreversible, leaving victims with no recourse once funds are sent to an incorrect address.

MetaMask advises users to verify the middle characters of an address, not just the start and end, as lookalike addresses are designed to pass superficial checks. Sending a small test payment does not confirm the recipient’s identity, as attackers will accept even nominal amounts to appear legitimate. Businesses can mitigate risks by avoiding address copying from transaction histories and instead using pre-approved recipient lists or invoices provided directly by the payee.

CoinGate offers solutions to prevent address poisoning, such as saving recipients in a dashboard or via API, using Payout Links where recipients input their own addresses, and requiring wallet ownership verification before withdrawals. Additional safeguards include four-eye approval for batch payouts and hardware wallet confirmation screens, which display the full destination address before signing. Users are also advised to document fraudulent transactions, report incidents, and avoid third-party recovery services offering to retrieve lost funds for a fee.

Original source → Deals on Clipraptor.com →