Address Poisoning and Lookalike-Address Transfers After Airdrop Claims: 2026 Safety Checklist

By CoinDrop Editorial (gspteck) · Published 2026-10-05 · Last verified 2026-10-05

Claim season puts a lot of new activity in your wallet history: claim transactions, bridge hops, transfers from an exchange to a fresh claim wallet, and transfers back to cold storage. That busy history is exactly what address-poisoning scammers target. They send a zero-value or dust transfer from an address that starts and ends like one you really use, then wait for you to copy the wrong entry. Nothing is “hacked”—you simply send funds to an address the scammer controls, and on-chain transfers cannot be reversed. This 2026 checklist explains how address poisoning works around airdrops, the red flags in your activity feed, and the send-flow habits that block it. It complements our fake gas token and approval drain checklist (which covers unknown tokens you are lured into approving) and the claim-site phishing checklist. Educational safety information only—not financial, legal, or investment advice, and no recovery guarantees.

What address poisoning is (and what it is not)

MetaMask’s Help Center describes address poisoning as a scam where attackers send you a tiny transaction from an address that closely resembles one you have used before, hoping you will copy it by mistake and send funds to them instead. Wallet addresses are long hexadecimal (or base58) strings, and most interfaces abbreviate them to the first and last few characters—for example 0x7a3f…9c1e. Attackers generate “vanity” addresses that match those visible characters and differ only in the middle.

It helps to be precise about what this attack can and cannot do:

Comparison of a real wallet address and a poisoned lookalike that share the same first and last characters but differ in the middle
Illustrative example: abbreviated wallet views hide the middle characters a poisoned address changes.

Why airdrop season makes poisoning more likely

Airdrops concentrate the exact conditions this scam needs. Many people create a dedicated claim wallet (a sensible habit we recommend in the Solana claim hygiene checklist), which means more addresses to remember and more copy-paste between wallets. Claimed tokens are often moved quickly—to an exchange to sell, or to cold storage to hold—so you are sending to a recently used address under time pressure. And public claim contracts make it easy for scammers to see which addresses just received a distribution and are likely to move it soon.

A typical sequence looks like this:

  1. You claim and move funds. For example, you send claimed tokens from your claim wallet to your exchange deposit address.
  2. The scammer watches the chain. Automated tools spot the transfer and generate a vanity address matching the first and last characters of your exchange deposit address.
  3. The poison lands. Within minutes or hours, a zero-value transfer, a tiny dust amount, or a fake token transfer appears in your history from that lookalike address.
  4. You repeat the move. Days later you open your history, copy the “recent” deposit address, glance at the start and end, and send—to the scammer.

MetaMask reported in its address poisoning detection announcement that Blockaid flagged 65.4 million address poisoning transactions between January 2025 and February 2026. You do not need to memorize that figure; the takeaway is that this is a high-volume, automated tactic, not a rare targeted attack.

Red flags in your activity feed

Seeing these entries does not mean your wallet is compromised. Leave them alone: do not interact with the fake tokens, do not try to “send them back,” and never visit any URL embedded in a token name. Our fake gas token guide covers why interacting with unknown tokens can lead to approval drains.

Four-step flow: you move claimed tokens, a bot generates a lookalike address, a zero-value poison transfer lands, then a copy-paste error sends funds to the scammer
Typical address-poisoning sequence after an airdrop claim transfer.

Send-flow habits that block address poisoning

The core defense is simple: never let your transaction history be the source of an address. Both the MetaMask Help Center and ethereum.org’s security and scam prevention guide emphasize careful verification before sending, because confirmed transactions cannot be undone.

Three habit cards: copy addresses only from trusted sources, check the full address including middle characters, and limit damage with test transfers
Send-flow habits that stop address poisoning before funds leave your wallet.

A pre-send routine for claim wallets

If you move airdropped tokens regularly, a fixed routine is easier than remembering rules under pressure:

  1. Identify the destination by purpose (“exchange deposit,” “cold storage,” “claim wallet B”) and open the matching saved contact.
  2. Re-derive it once a month. Re-check saved contacts against the source wallet or exchange deposit page, because deposit addresses can change.
  3. Compare in chunks. Read the full address in groups of four characters against the trusted source. Do not rely on the abbreviated display.
  4. Confirm network and asset. Sending a token to the right address on the wrong network can be a separate, non-scam loss; check that the exchange supports that network for deposits.
  5. Test, then send. Small transfer, confirm arrival, then the full amount.
  6. Record the transaction hash in your own notes. If something goes wrong, it is the first detail investigators ask for.

If you already sent funds to a poisoned address

Be realistic: on public blockchains a confirmed transfer to an address you do not control generally cannot be reversed by you, your wallet provider, or this site. What you can do is reduce further harm and create a record.

Grid of six address-poisoning red flags and response steps, from zero-value transfers to ignoring recovery DMs
Red flags to recognize in your activity feed, and what to do after a loss.

Safety checklist (YMYL)

Key takeaways

Sources and further reading

Related CoinDrop guides: fake “Connect Wallet to verify eligibility” drains, fake airdrop calendars and poisoned search results, and cryptocurrency airdrop safety considerations.

Not financial, legal, or investment advice. This article is general educational information about a common crypto scam pattern. Wallet features and reporting procedures change; confirm current guidance in your wallet provider’s official documentation and with the relevant authorities. CoinDrop cannot recover funds and does not endorse any recovery service. Last verified 2026-10-05.