Address Poisoning: Why Seven of Forty Characters Were Enough to Divert $2 Million

1 hour ago 2



On August 21, 2026, a transfer of 2,000,000 USDC left a wallet and landed at an address that matched the correct one in exactly seven of forty characters. Four characters at the front, three at the end. The remaining thirty-three were completely different. That precise cut is the entire attack, because wallets and block explorers usually show addresses in shortened form: a few characters at the front, a few at the back, three dots in the middle. Anyone who looks only at that short form sees the same thing on the fake as on the original. The technique is called address poisoning. Address poisoning means that an attacker plants a fake but similar-looking address into your wallet's transaction history, so that you later copy it from there and send your money to it yourself. Nothing is hacked, no key is stolen, no signature is forged. The transfer is technically flawless and authorised by the owner. It simply goes to the wrong recipient, and on a blockchain that makes it final. This article takes the August 21 case apart and then goes further than the reports published so far: we read out the full transaction history of the affected wallet and counted it. The result shows that the deco...

Read Entire Article