What Is Address Poisoning? Zero-Value Transfer Scams and How to Avoid Them
Address poisoning needs no stolen keys. An attacker creates an address whose first and last characters match one you use, sends you a zero-value or tiny transfer so it shows up in your history, and waits for you to copy the wrong address next time. Based on MetaMask's help center and Etherscan, here is how it works, how to spot it and how to avoid it.

How address poisoning works
Many people copy "the address from last time" out of their transaction history and check only the first and last few characters. Attackers exploit exactly that: they use a vanity address generator to create an address with the same first and last characters as the target, then send you a zero-value token transfer, a tiny "dust" transfer or a spoofed token transfer so the address appears in your activity.
The transaction itself does not touch your funds. Etherscan notes that seeing such a transfer does not mean your wallet is compromised and your keys are safe. The danger is the next time you copy an address from that history.
How to spot it
- Token transfers you did not make, for zero or a tiny amount, appear in your history.
- The counterparty address matches a familiar one at the start and end but differs in the middle.
- You receive a token with a familiar name but the wrong contract address, which is a spoofed token.
Etherscan mutes zero-value token transfers and marks them with a grey warning icon. It also suggests checking the entries just above and below your real transaction in the Token Transfers tab, since impersonating addresses often sit right next to it.
How to avoid it
- Do not copy addresses from your transaction history: take them from the recipient's deposit page, from the recipient directly, or from an address book entry you have verified.
- Check the whole address, especially the middle: MetaMask specifically warns against checking only the start and end.
- Save frequent addresses in your address book: verify once when saving, then pick from the book.
- Send a small test for large amounts: send the rest only after the recipient confirms.
- Heed wallet warnings: MetaMask compares the destination with your history and shows a blocking warning before sending when it closely resembles an old address; it also alerts you when sending to an address you have never used.
- Use a hardware wallet for one more check: read the full address again on the device screen; see what a hardware wallet is.
If you have already sent funds
On-chain transfers cannot be reversed, so funds sent to a poisoning address are almost always lost. Keep the transaction hash and report it to the relevant platforms or authorities. Be wary of anyone offering to "recover" the funds: as Revoke.cash puts it, anyone who promises to recover stolen assets is likely a scammer themselves.
Related reading: how to check a transaction hash, why an address must be checked with its network, what a wallet drainer is.