Cointime

Download App
iOS & Android

MetaMask Warns of ‘Address Poisoning’ Wallet Scam

MetaMask notified the crypto community of a new type of scam called “address poisoning” in a recent post.

The scam was rated as “rather innocuous compared to other scam types.” However, the company warned that address poisoning still has the potential to dupe unsuspecting users into losing funds.

“Address poisoning is an attack vector that, in contrast to other scams — which often use methods that have served many scammers so well, such as unlimited token approvals, phishing for your Secret Recovery Phrase, etc. — relies on user carelessness and haste above all else.”

How “address poisoning” works

Address poisoning centers on wallet addresses being long hexadecimal numbers that are difficult to remember and easy to mistake for other, similar addresses.

Crypto addresses are often shortened to show the first few characters, a blank, and then the last few. Scammers exploit the tendency to trust the familiarity of the first and last few characters.

When transacting, the usual routine consists of copying and pasting an address. Many wallet providers, including MetaMask, feature a one-click function to copy an address.

Address poisoning exploits users’ inattention at this point in the transaction process. Specifically, scammers observe and track transactions of particular tokens, with stablecoins commonly targeted. Then, using a “vanity” address generator, the scammer will create an address that closely matches the target address, especially the first and last few characters.

The scammer sends a transaction of nominal value from the newly generated address to the target address; at this point, the latter becomes poisoned.

In the future, when wishing to send a transaction, the user may mistakenly copy the wrong address based on the familiarity of the first and last few characters. Once executed, the funds end up with the scammer.

“And since on-chain transactions like this are immutable (cannot be altered once confirmed), the lost funds will be irretrievable.”

MetaMask explains how to stay safe

Unfortunately, the nature of public blockchains means anyone, including scammers, can send transactions to any address if they choose.

MetaMask reiterated the importance of checking every address character when sending funds, not just the first and last few.

“Develop a habit of thoroughly checking every single character of an address before you send a transaction. This is the only way to be completely sure you’re sending to the right place.”

Other strategies to avoid falling victim to address poisoning include not using transaction history to copy addresses, whitelisting frequently used addresses to avoid copying and pasting altogether, and using test transactions, especially when transferring large sums.

Comments

All Comments

Recommended for you

  • Iran Launches Seventh Round of Missile Attacks; Jerusalem Intercepts Missiles

    On April 5, local time, air raid sirens sounded in multiple locations including Jerusalem and central Israel on the evening of the 4th. Several intercepting missiles were seen launching from Jerusalem, followed by several loud explosions. Israeli officials stated that the latest round of missile attacks by Iran targeting the Jerusalem area did not result in any casualties, marking the seventh round of missile attacks by Iran that day. The Israeli military reported that one missile landed in an open area, while the others were intercepted by the air defense system. (CCTV News)

  • Twitter Co-founder Jack Dorsey to Launch Free Bitcoin Faucet

    On April 4, Jack Dorsey's Bitcoin at Block will launch a free Bitcoin faucet, marking the return of Bitcoin faucets after 16 years. Dorsey disclosed the faucet site 'btc.day' in a post on the X platform. The total distribution pool is approximately $1 million worth of BTC (around 15 BTC), funded by the Bitcoin treasury of Dorsey's Block company.

  • US Nonfarm Payrolls Rise Sharply in March, Exceeding Expectations

    April 3rd (Beijing Time): The United States added 178,000 nonfarm jobs in March, significantly exceeding the forecast of 65,000. This follows a revised figure of a decrease of 92,000 jobs in the previous month.

  • Market Pricing Shows Reduced Bets on Fed Rate Cuts in 2026

    As of April 3rd, market pricing indicates a decrease in expectations for Federal Reserve interest rate cuts in 2026.

  • BTC Surpasses $67,000

    Market data shows that BTC has surpassed $67,000, currently priced at $67,007.8, with a 24-hour decline of 2.04%. The market is experiencing significant volatility, so please ensure proper risk management.

  • BTC Surpasses $67,000

    Market data shows that BTC has surpassed $67,000, currently priced at $67,015.44, with a 24-hour decline of 1.94%. The market is highly volatile, so please ensure proper risk management.

  • U.S. Initial Jobless Claims at 202,000 Last Week

    On April 2, the number of initial jobless claims in the U.S. last week was 202,000, estimated at 212,000, with a previous value of 210,000.

  • BTC Falls Below $66,000

    Market data shows that BTC has fallen below $66,000, currently priced at $65,999, with a 24-hour decline of 3.86%. The market is experiencing significant volatility, so please ensure proper risk management.

  • Iran: Enemy Forces Will Be Annihilated in Ground Attack

    On April 2, Iranian Army Chief of Staff Hatami warned that if enemy forces attempt a ground invasion, no enemy soldiers will survive. He urged the military to maintain the highest level of vigilance and skepticism, constantly monitoring enemy movements and actions, and to implement operational plans to counter any enemy attacks at the appropriate time. (CCTV International News)

  • Metaplanet Acquires 5,075 BTC in Q1, Total Holdings Reach 40,177 BTC

    On April 2, Metaplanet CEO Simon Gerovich announced that in the first quarter of 2026, the company purchased 5,075 BTC at an average price of approximately $79,898, with a total investment of around $405.48 million. The year-to-date return on Bitcoin is 2.8%. As of March 31, the company has accumulated a total of 40,177 BTC, with a total cost of approximately $4.18 billion and an average cost of about $104,106.