Wallet security

Address poisoning: matching ends are not enough

A practical way to compare a destination with its trusted source, without mistaking transaction history for an address book.
Two blue metal strips have matching ends but different central openings
An original visual metaphor, not wallet hardware or a real transactionCoinFom · AI-generated illustration with OpenAI

At a glance

Matching the beginning and end does not verify a complete destination. Obtain current receiving instructions through a trusted channel, compare the entire final address, and stop if any part differs. A suspicious history entry alone does not establish that your private keys were stolen.

On this page

A familiar-looking recipient can still be the wrong recipient. This article focuses on one narrow failure: choosing a lookalike destination from transaction history. It does not diagnose a compromised wallet.

History is a record, not approval

MetaMask describes address poisoning as an attempt to plant a lookalike address in history so that a later transfer goes to the wrong recipient. Familiarity is not evidence that you selected the intended destination.

Try this comparison without sending anything

These are deliberately invalid demonstration strings, not cryptocurrency addresses:

CheckReferenceCandidateResult
BeginningABCDABCDMatches
MiddleMNOPQRSTDiffers
EndWXYZWXYZMatches
Complete stringABCD · MNOP · WXYZABCD · QRST · WXYZDoes not match

Two matching fragments do not make the complete strings equal. An interface displaying only ABCD … WXYZ would conceal this difference. Expand the destination instead of treating the ellipsis as evidence.

Different middle
Fictional strings, not wallet addresses CoinFom

Separate the source check from the screen check

Ledger recommends comparing the full address against a trusted source. Our practical worksheet separates two questions:

StageQuestionStop condition
ObtainDid I open the recipient's current receiving instructions through a trusted channel?Source cannot be established
CompareDoes the entire final destination match those instructions?Any unexplained difference
ContextAre asset, network and any required memo/tag also correct?Receiving requirements are unclear
ConfirmCan I inspect the destination at the final signing/confirmation step?Only a truncated destination is available

A saved contact is useful only when its contents were verified. A successful earlier transfer does not validate a different destination selected today. The transfer checklist covers network and memo checks separately.

A strange entry is not a diagnosis

Etherscan explains zero-value token-transfer impersonation. Such an entry alone does not demonstrate that your private key leaked; it also cannot establish that every other part of your wallet is safe. Distinguish an unfamiliar history record from an actual unauthorized balance movement.

If a transfer already went to an unintended destination, preserve the network, transaction hash, time and expected versus recorded recipient. Use the provider's official reporting route; MetaMask documents its process here. Do not assume a confirmed transaction can simply be edited or that recovery is guaranteed. Never disclose a recovery phrase. Read our separate recovery-scam warning before responding to anyone offering paid recovery.

Editorial note: CoinFom prepared this original example and worksheet with AI-assisted research, writing, translation and review. No transfer, wallet attack or recovery was performed. Sources checked October 2, 2026. This is educational information, not investment advice. CoinFom may earn referral commissions elsewhere; this article has no signup link. See About, editorial policy and corrections.

All articles ↗