Wallet security
Address poisoning: matching ends are not enough

At a glance
Matching the beginning and end does not verify a complete destination. Obtain current receiving instructions through a trusted channel, compare the entire final address, and stop if any part differs. A suspicious history entry alone does not establish that your private keys were stolen.
On this page
A familiar-looking recipient can still be the wrong recipient. This article focuses on one narrow failure: choosing a lookalike destination from transaction history. It does not diagnose a compromised wallet.
History is a record, not approval
MetaMask describes address poisoning as an attempt to plant a lookalike address in history so that a later transfer goes to the wrong recipient. Familiarity is not evidence that you selected the intended destination.
Try this comparison without sending anything
These are deliberately invalid demonstration strings, not cryptocurrency addresses:
| Check | Reference | Candidate | Result |
|---|---|---|---|
| Beginning | ABCD | ABCD | Matches |
| Middle | MNOP | QRST | Differs |
| End | WXYZ | WXYZ | Matches |
| Complete string | ABCD · MNOP · WXYZ | ABCD · QRST · WXYZ | Does not match |
Two matching fragments do not make the complete strings equal. An interface displaying only ABCD … WXYZ would conceal this difference. Expand the destination instead of treating the ellipsis as evidence.
Separate the source check from the screen check
Ledger recommends comparing the full address against a trusted source. Our practical worksheet separates two questions:
| Stage | Question | Stop condition |
|---|---|---|
| Obtain | Did I open the recipient's current receiving instructions through a trusted channel? | Source cannot be established |
| Compare | Does the entire final destination match those instructions? | Any unexplained difference |
| Context | Are asset, network and any required memo/tag also correct? | Receiving requirements are unclear |
| Confirm | Can I inspect the destination at the final signing/confirmation step? | Only a truncated destination is available |
A saved contact is useful only when its contents were verified. A successful earlier transfer does not validate a different destination selected today. The transfer checklist covers network and memo checks separately.
A strange entry is not a diagnosis
Etherscan explains zero-value token-transfer impersonation. Such an entry alone does not demonstrate that your private key leaked; it also cannot establish that every other part of your wallet is safe. Distinguish an unfamiliar history record from an actual unauthorized balance movement.
If a transfer already went to an unintended destination, preserve the network, transaction hash, time and expected versus recorded recipient. Use the provider's official reporting route; MetaMask documents its process here. Do not assume a confirmed transaction can simply be edited or that recovery is guaranteed. Never disclose a recovery phrase. Read our separate recovery-scam warning before responding to anyone offering paid recovery.
Editorial note: CoinFom prepared this original example and worksheet with AI-assisted research, writing, translation and review. No transfer, wallet attack or recovery was performed. Sources checked October 2, 2026. This is educational information, not investment advice. CoinFom may earn referral commissions elsewhere; this article has no signup link. See About, editorial policy and corrections.