How the scam works
MetaMask describes it in three steps (MetaMask Help Center). You send an ordinary transaction — to a friend, or to another account of your own. A scammer running software that watches transfers of certain tokens, usually stablecoins, notices it. They use a vanity address generator to create an address that closely matches yours or your contact’s, and send you a transaction of negligible value from it — usually a transfer of zero tokens.
Nothing has been stolen at that point. The transfer’s only job is to sit in your history, next to the real address, looking almost the same.
Why it works
Addresses are long, so wallets and explorers shorten them. Often you see only the first characters, or the first few and the last few with the middle skipped — and, as MetaMask notes, that is how most people recognise an address. A generated look-alike only has to match those visible parts. The next time you copy “the usual address” out of your history, you may be copying the scammer’s.
How to avoid it
MetaMask’s advice (MetaMask Help Center):
- Check the whole destination address before sending, especially for large amounts — the middle characters, not only the start and the end.
- Save addresses you use often in the address book once you have verified them, and send from there.
- Do not copy addresses from your transaction history.
- Use a hardware wallet, since most of them make you confirm the destination on the device itself. Ledger’s own guide describes the same check on the receiving side: compare the address on the device’s screen with what the app shows (Ledger).
What the wallet does about it
MetaMask compares a destination address against your transaction history. If it closely resembles an address you have used before, it shows a blocking warning before the transaction is sent; if it is an address you have never interacted with, it warns you about that too (MetaMask Help Center). The detection is live on MetaMask Mobile and Extension across EVM networks (MetaMask). A warning helps only if you read it: the scam is designed for the moment you are sure you are sending to the right place.
If you have already sent funds
MetaMask is direct about it: confirmed on-chain transactions cannot be altered, so funds lost this way are irretrievable (MetaMask Help Center). What remains in your control is the next step. Whoever then offers to get the money back and asks for your recovery phrase or private keys is, in MetaMask’s words, trying to steal all of your assets (MetaMask Help Center). More on that pattern is in wallet drainers.
Questions
What is address poisoning in crypto?
A scam in which someone sends a worthless transfer to your wallet from an address made to look like one you use, so that it appears in your transaction history. If you later copy that address from the history to send funds, they go to the scammer.
How does an address poisoning attack work?
Software watches for transfers of certain tokens, usually stablecoins. When it sees yours, the scammer generates an address that closely matches your own or your contact's and sends you a transfer of negligible value, often zero tokens, from it — hoping you copy it next time.
What should I do after an address poisoning scam?
Accept that the transfer itself cannot be undone: MetaMask states that funds sent this way are irretrievable, because confirmed on-chain transactions cannot be altered. Stop copying addresses from history, and treat anyone who asks for your recovery phrase to "recover" the funds as a thief.
Sources
- MetaMask Help Center — address poisoning scams · checked 2026-09-14
- MetaMask — address poisoning detection now live · checked 2026-09-14
- Ledger Academy — how to send, receive and spend crypto with Ledger Wallet · checked 2026-09-13
- MetaMask Help Center — basic safety and security tips · checked 2026-09-14