Address Poisoning and Lookalike-Address Transfers After Airdrop Claims: 2026 Safety Checklist
Claim season puts a lot of new activity in your wallet history: claim transactions, bridge hops, transfers from an exchange to a fresh claim wallet, and transfers back to cold storage. That busy history is exactly what address-poisoning scammers target. They send a zero-value or dust transfer from an address that starts and ends like one you really use, then wait for you to copy the wrong entry. Nothing is “hacked”—you simply send funds to an address the scammer controls, and on-chain transfers cannot be reversed. This 2026 checklist explains how address poisoning works around airdrops, the red flags in your activity feed, and the send-flow habits that block it. It complements our fake gas token and approval drain checklist (which covers unknown tokens you are lured into approving) and the claim-site phishing checklist. Educational safety information only—not financial, legal, or investment advice, and no recovery guarantees.
What address poisoning is (and what it is not)
MetaMask’s Help Center describes address poisoning as a scam where attackers send you a tiny transaction from an address that closely resembles one you have used before, hoping you will copy it by mistake and send funds to them instead. Wallet addresses are long hexadecimal (or base58) strings, and most interfaces abbreviate them to the first and last few characters—for example 0x7a3f…9c1e. Attackers generate “vanity” addresses that match those visible characters and differ only in the middle.
It helps to be precise about what this attack can and cannot do:
- It cannot move your funds by itself. The poisoning transfer only adds an entry to your history. It does not need an approval, a signature, or your seed phrase.
- It relies on haste. The loss happens later, when you copy an address from your transaction history or a block explorer instead of from a trusted source, and do not check every character.
- It is not limited to other people’s addresses. Scammers also mimic your own addresses—useful to them when you move funds between your exchange account, a claim wallet, and a hardware wallet.
- It is permanent if it works. As the FTC notes in What To Know About Cryptocurrency and Scams, crypto payments usually lack the legal protections of cards and are generally not reversible.
Why airdrop season makes poisoning more likely
Airdrops concentrate the exact conditions this scam needs. Many people create a dedicated claim wallet (a sensible habit we recommend in the Solana claim hygiene checklist), which means more addresses to remember and more copy-paste between wallets. Claimed tokens are often moved quickly—to an exchange to sell, or to cold storage to hold—so you are sending to a recently used address under time pressure. And public claim contracts make it easy for scammers to see which addresses just received a distribution and are likely to move it soon.
A typical sequence looks like this:
- You claim and move funds. For example, you send claimed tokens from your claim wallet to your exchange deposit address.
- The scammer watches the chain. Automated tools spot the transfer and generate a vanity address matching the first and last characters of your exchange deposit address.
- The poison lands. Within minutes or hours, a zero-value transfer, a tiny dust amount, or a fake token transfer appears in your history from that lookalike address.
- You repeat the move. Days later you open your history, copy the “recent” deposit address, glance at the start and end, and send—to the scammer.
MetaMask reported in its address poisoning detection announcement that Blockaid flagged 65.4 million address poisoning transactions between January 2025 and February 2026. You do not need to memorize that figure; the takeaway is that this is a high-volume, automated tactic, not a rare targeted attack.
Red flags in your activity feed
- Zero-value transfers you did not make. A “0” token transfer “from” or “to” your address that you never initiated is a classic poisoning marker.
- Tiny dust amounts from unknown addresses that look almost like one of your regular counterparties.
- Fake tokens with familiar tickers. A transfer of a token that uses a well-known stablecoin name but comes from an unverified contract, timed right after one of your real transfers.
- Two near-identical entries in a row. Your real transfer followed shortly by an entry whose abbreviated address looks the same.
- Lookalikes in the middle characters. When you expand the full address, the start and end match but the middle differs.
Seeing these entries does not mean your wallet is compromised. Leave them alone: do not interact with the fake tokens, do not try to “send them back,” and never visit any URL embedded in a token name. Our fake gas token guide covers why interacting with unknown tokens can lead to approval drains.
Send-flow habits that block address poisoning
The core defense is simple: never let your transaction history be the source of an address. Both the MetaMask Help Center and ethereum.org’s security and scam prevention guide emphasize careful verification before sending, because confirmed transactions cannot be undone.
- Use a saved contact or address book entry for addresses you send to repeatedly, created once from a trusted source (for example, the deposit page shown when you are logged in to your exchange) and labeled clearly.
- Get your own receive address from the receiving wallet itself—open the destination wallet or exchange deposit screen and copy from there, not from an old transaction.
- Check every character, especially the middle. MetaMask specifically advises paying close attention to the middle characters, not just the start and end, because that is what a poisoned address is designed to disguise.
- Confirm on the hardware wallet screen. If you use a hardware wallet, compare the full address on the device display with the address from your trusted source before approving.
- Send a small test transfer first for large or first-time destinations, then confirm it arrived where you expected before sending the remainder. This costs an extra network fee but limits the damage of a mistake.
- Read wallet warnings instead of clicking past them. MetaMask now compares send recipients against addresses you have interacted with and shows a warning when a lookalike is detected, plus a first-time-recipient warning. Other wallets have similar features; a warning is a reason to stop and re-verify, not a formality.
- Slow down after claims. Rushing to sell or bridge immediately after a distribution is when most copy-paste mistakes happen.
A pre-send routine for claim wallets
If you move airdropped tokens regularly, a fixed routine is easier than remembering rules under pressure:
- Identify the destination by purpose (“exchange deposit,” “cold storage,” “claim wallet B”) and open the matching saved contact.
- Re-derive it once a month. Re-check saved contacts against the source wallet or exchange deposit page, because deposit addresses can change.
- Compare in chunks. Read the full address in groups of four characters against the trusted source. Do not rely on the abbreviated display.
- Confirm network and asset. Sending a token to the right address on the wrong network can be a separate, non-scam loss; check that the exchange supports that network for deposits.
- Test, then send. Small transfer, confirm arrival, then the full amount.
- Record the transaction hash in your own notes. If something goes wrong, it is the first detail investigators ask for.
If you already sent funds to a poisoned address
Be realistic: on public blockchains a confirmed transfer to an address you do not control generally cannot be reversed by you, your wallet provider, or this site. What you can do is reduce further harm and create a record.
- Stop using copied addresses from that history and rebuild your saved contacts from trusted sources.
- Collect the details: your sending address, the scammer’s address, the asset and amount, the transaction hash, and the date and time.
- Report it. The FBI’s Internet Crime Complaint Center explains what to include on its cryptocurrency page and in FBI Guidance for Cryptocurrency Scam Victims. In the U.S. you can also report to the FTC at ReportFraud.ftc.gov. Outside the U.S., use your national police or cybercrime reporting service.
- Tell the exchange if the funds went to, or came from, an exchange account; they may be able to act if the receiving address belongs to one of their customers, though there is no guarantee.
- Beware of recovery scams. IC3 warns to be wary of cryptocurrency recovery services, especially those charging up-front fees. Anyone who DMs you promising to “trace and return” your funds after you post about a loss is very likely a second scam—see our DM impersonation checklist.
Safety checklist (YMYL)
- Never copy a destination address from transaction history or a block explorer feed.
- Use saved contacts created from trusted sources; re-verify them periodically.
- Compare the full address, especially the middle characters, and confirm on a hardware wallet screen when available.
- Send a small test transfer to large or first-time destinations.
- Ignore zero-value transfers, dust, and fake tokens; never click URLs in token names.
- After a loss: document the transaction hash, report to IC3 / FTC or your national authority, and ignore recovery offers.
Key takeaways
- Address poisoning plants lookalike addresses in your history; you lose funds only if you copy one.
- Airdrop claim and transfer bursts make you a more likely target.
- Saved contacts, full-address checks, and test transfers stop the attack.
- Wallet lookalike warnings are a reason to stop, not a box to click.
- Confirmed transfers are generally irreversible—prevention beats recovery.
Sources and further reading
- MetaMask Help Center: Address poisoning scams
- MetaMask: Address Poisoning Detection announcement
- ethereum.org: Ethereum security and scam prevention
- FTC: What To Know About Cryptocurrency and Scams
- FBI IC3: Cryptocurrency and FBI Guidance for Cryptocurrency Scam Victims
- CISA: Recognize and Report Phishing
Related CoinDrop guides: fake “Connect Wallet to verify eligibility” drains, fake airdrop calendars and poisoned search results, and cryptocurrency airdrop safety considerations.
Not financial, legal, or investment advice. This article is general educational information about a common crypto scam pattern. Wallet features and reporting procedures change; confirm current guidance in your wallet provider’s official documentation and with the relevant authorities. CoinDrop cannot recover funds and does not endorse any recovery service. Last verified 2026-10-05.