Cointime

Download App
iOS & Android

Address Poisoning Scam: What You Need to Know and How to Protect Yourself

This scam is not specific to Safe or Safe{Wallet} but is generally possible in all types of wallets. Also, there is no need to be worried about assets at risk in this type of situation as long as no other transaction is initiated to the fraudulent address.

At Safe, we work continuously to keep abreast of the latest security issues our users face and release features and resources to help users out whenever possible. Today we will be tackling address poisoning and what users can do to keep Safe!

Imagine walking down a familiar street and spotting your friend waving from afar. You stride towards them, only to realize it’s a stranger wearing similar clothes. This moment of mistaken identity is akin to address poisoning in the crypto world. Scammers craft wallet addresses that mirror legitimate ones, much like a doppelgänger in a crowd. Just as you might inadvertently approach the wrong person, users unknowingly send assets to these deceptive addresses, falling prey to a sophisticated digital masquerade. This is the address poisoning scam, a subtle yet devastating form of fraud. This post aims to dissect the anatomy of these scams, illustrating how they manifest and offering strategies to fortify against them.

What is Address Poisoning?

Address poisoning is a type of scam trying to trick users into sending assets to a fraudulent address. The attacker specifically designs the fraudulent address to look very similar to the correct one. This is done by generating a “vanity address” with a number of characters matching. In case victims carelessly copy the address without further verification, they may accidentally send their assets to the fraudulent address instead.

HOW COULD SUCH FRAUDULENT ADDRESSES EVEN SHOW UP INSIDE WALLET INTERFACES IN THE FIRST PLACE?

In order to display a full transaction history such as token transfers into and outside an account, wallets typically rely on backend services. These services listen to ERC20 events emitted on chain in order to learn about these transfers. Any contract can trigger these events with any content, no matter if legit or fraudulent. Besides, wallets typically display only the first and last four characters of an address on the transaction history, thereby increasing chances of an attacker since they would have to only create a “vanity address” which shares common first and last 4 characters with the legit address.

In the above screenshot, only the lower transaction has been done with a legitimate token and authorised by the owner of the Safe. The upper one is a fake transfer as part of the scam attempt.

What should users do to protect themselves?

There are a number of preventative actions users should take whenever transferring assets and generally executing transactions.

Verify, Verify, Verify

Any address should always be thoroughly checked in its entire length. Never copy addresses blindly from transaction history in order to transfer assets but rather from a trusted source. Safe{Wallet} displays checksummed addresses throughout the application. Always double check the correct use of uppercase and lowercase letters as well.

Use human-readable labels wherever possible

Account addresses are cryptic. It is hard and time consuming for a human to reliably verify all characters of an address. Besides the checksums mentioned above, users should use human readable ENS names as well as the Safe{Wallet} address book feature as much as possible.

Small tests save big losses

Before transferring high value assets, always do a test transfer with a small amount. Once the recipient confirms the successful transfer, authorise the transactions transferring the full amount.

Take security warnings seriously

Safe{Wallet} partnered with Redefine to scan each transaction for potential risks before execution. All affected Safes have received a risk warning of category “medium” before execution, referring to suspicious recipient addresses as the cause. Yet users still decided to proceed. The DeFirewall feature enhances transaction security by scanning every onchain transaction prior to signing. Its automated engine identifies risks associated with the transaction and provides a risk profile for each identified issue, clearly showing if a transaction would likely result in the user losing funds.

How is Safe{Wallet} improving security?

Ultimately, it is the user’s responsibility to carefully examine each transaction before execution. For enhanced security, Safe has also implemented the following several measures.

Labeling of Risky Addresses and Tokens

We have systematically marked addresses and tokens involved in the recent scams. This ongoing process is a part of our commitment to actively identify and label potential threats. While we strive for comprehensiveness, there may be instances of delay in identifying and labeling new threats. Users should be aware that not all potential risks may be immediately flagged and continue to exercise caution

Modifying Transaction Visibility

To help mitigate risks we released a hotfix hiding suspicious token transfers completely. As a proper fix, outgoing transfers unrelated to a direct transaction involving an unknown token will be marked better in the user interface. This measure is designed to help prevent scams while ensuring that genuine transactions, like those involving decentralized exchanges remain operational, albeit less visible in the transaction history. While we strive for comprehensiveness, there may be instances of delay in identifying and labeling new threats. Users should be aware that not all potential risks may be immediately flagged and continue to exercise caution.

The scam transfer is marked as such in the transaction history.

The Safe{Wallet} asset overview already leverages Safe’s default tokenlist. The transaction history now implements the same approach.

On assets overview, users can choose between seeing only default/trusted tokens or all tokens. The latter would contain any spam and scam token.

Enhanced Detection by Redefine

Redefine has upgraded its detection algorithms, significantly enhancing the accuracy in pinpointing address poisoning attacks targeting Safe users. Users will now receive 'High' severity alerts, accompanied by detailed insights and explanations, explicitly mentioning 'address poisoning' to ensure clarity and immediate awareness of the specific risk involved.

Conclusion

Crypto, just like in everyday life, is filled with both familiar and deceptive faces. By understanding the mechanics of address poisoning scams and adopting proactive measures, users everywhere can better navigate this landscape, ensuring a safer transaction environment for all.

Finally, knowledge is your best defense. For a deep dive into security best practices on avoiding address poisoning scams, check out our comprehensive guide.

Stay alert, stay safe.

Disclaimer:

Please note that the measures and implementations described in this article are provided for informational purposes only and do not imply any changes to the license terms and/or any applicable terms of use of Safe Wallet. Users should always refer to the official terms of service for the most accurate and up-to-date information regarding the use of our services.

Token lists are compiled using data from external third-party sources. We do not vouch for the accuracy of this data, and do not make any claims regarding its relevance or timeliness. Often, data may not be available for certain tokens, especially those that are new or less known.

The token lists are not to be taken as investment advice. They are not exhaustive in highlighting all possible risks. We advise conducting your own research on tokens before engaging in any buying or selling activities. The information provided is solely for informational purposes…

Comments

All Comments

Recommended for you

  • Binance assisted Taiwan’s law enforcement agencies in cracking a major virtual asset case involving nearly NT$200 million

    On May 17th, Binance announced that the Financial Crime Compliance department (FCC) of Binance, in collaboration with the Taiwan Department of Justice Investigation Bureau, has successfully cracked a major criminal case involving money laundering of virtual assets, with an involved amount of nearly 200 million New Taiwan dollars. Throughout the entire case, Binance provided support to Taiwan's crime fighters, offering crucial intelligence and assistance, and played a key role in promoting the investigation.

  • $1.2 billion in notional value of BTC options and $930 million in ETH options are set to expire

    Greeks.live data shows that on May 17th, 18,000 BTC options with a put/call ratio of 0.63 and a maximum pain point of $63,000 (nominal value of $1.2 billion) will expire. Additionally, 320,000 ETH options with a put/call ratio of 0.28 and a maximum pain point of $3,000 (nominal value of $930 million) will also expire. Greeks.live states that this week, inspired by the meme stock craze in the US, BTC ETFs have seen significant inflows, causing BTC to surge above $65,000. However, the rest of the crypto market remains weak, with trading volume continuing to decline, and the divergence in the options data of BTC and ETH reflects this. Looking at the structure of bulk trades and market trades, the downward trend in IV for major deadlines has ended and entered a consolidation phase, with limited downside potential at present. BTC longs and shorts are relatively balanced, while the weak ETH price has led to a continuous decline in market confidence, with selling calls becoming the absolute main transaction.

  • Tether CEO: 1 billion USDT will be issued on Tron Network, but it has been authorized but not yet issued

    On May 17th, Tether CEO Paolo Ardoino announced that 1 billion USDT had been issued on the Tron Network early this morning Beijing time, but not yet released. This means that the amount will be used as inventory for the next issuance request and chain exchange.

  • On-chain indexing service Subsquid completes financing of US$17.5 million, with participation from DFG and others

    Subsquid, a chain indexing service, announced the completion of a $6.3 million financing through the CoinList community. As of now, its total financing amount has reached $17.5 million, with participation from DFG, Hypersphere, Zee Prime, Blockchange, and Lattice. It is reported that its native token, SQD, is scheduled to be listed this Friday. The Subsquid SDK has been integrated with Google BigQuery, allowing developers to use Google's technology to analyze blockchain data and reduce the data costs of large-scale deployment in the blockchain and developer communities.

  • Optimism 2024 Q1 Report: The implementation of EIP-4844 reduces L1 submission costs by 99%

    Optimism has released its Q1 2024 report, which shows that the number of daily active addresses has reached 89,000 (a 23% increase compared to the previous period), and the daily transaction volume has increased to 470,000 (a 39% increase compared to the previous period). These indicators are slightly lower than the historical high point in Q3 2023.

  • US Secret Service seizes domain used to run cryptocurrency scam

    On May 17th, the US Secret Service seized a domain used for cryptocurrency trust fraud in a "pig-killing plate" scam. In the "pig-killing plate" scam, scammers contact victims through various means, including dating apps, social media websites, and even random text messages disguised as wrong numbers.

  • Peaq Completes $20 Million Fundraising via CoinList Launch

    Peaq, a Layer1 blockchain applicable for DePIN and machine RWA, announced on X platform that it raised $20 million through its native token Launch, which was launched on CoinList from May 9 to May 16. As of now, over 145,000 community members have completed over-subscriptions of over $36 million. The new funds will be used to accelerate the growth of the peqosystem and further consolidate various ecosystem and community plans.

  • LocalMonero to Shut Down in Six Months Amid Regulatory Pressure and Internal Factors

    LocalMonero, a peer-to-peer exchange for trading privacy coin Monero (XMR), has disabled all trades and will be taken down in six months, according to parent company AgoraDesk. The company cited a combination of internal and external factors for the decision, but did not provide specifics. The move follows a trend of P2P crypto trading platforms shutting down due to regulatory challenges, including LocalBitcoins and Paxful. LocalMonero's closure also comes amid pressure from regulatory authorities on privacy coins, with exchanges including Binance and Coinbase delisting tokens like Monero and Zcash.

  • French securities regulator issues new warning to Bybit

    The French securities regulator has issued a new warning to the cryptocurrency exchange Bybit, urging customers to make arrangements for the possibility that the platform may suddenly stop providing services to French customers. The Financial Markets Authority (AMF) stated in a notice on Thursday that the exchange is not registered as a Digital Asset Service Provider (DASP), and therefore is providing services illegally in France. Bybit has been blacklisted by the AMF since May 20, 2022 for illegal operations.

  • Gaming platform Param Labs completes $7 million financing, led by Animoca Brands

    Gaming platform Param Labs has completed a $7 million financing round, led by Animoca Brands with participation from Delphi Ventures and Cypher Capital. Param Labs aims to establish a gaming ecosystem managed by its native PARAM token, which is set to launch soon. The company's first game, "Kiraverse," is a multiplayer shooting game that allows players to earn money while playing.