A crypto investor lost roughly $100,000 after copying a wallet address directly from their transaction history and sending funds without double-checking it character by character, according to on-chain tracker Lookonchain. The victim fell for address poisoning, a scam that has become one of the more persistent threats in crypto precisely because it doesn't require tricking anyone into clicking a malicious link or signing a bad transaction — it exploits ordinary copy-paste habits.

The mechanics are straightforward but effective. Attackers monitor active wallets, study their transaction history, and generate a lookalike address that shares the same first and last few characters as one the target has genuinely transacted with before. They then send that lookalike address a tiny, often worthless, transaction so it appears in the victim's recent activity. When the victim later goes to send funds and grabs an address from their history rather than typing or verifying the full string, there's a real chance they copy the attacker's planted address instead of the legitimate one.

Victim Loses $100K to Address Poisoning After Copying From History
Image via @lookonchain on X

A Scam That's Scaling Fast

Research from Chainalysis shows just how quickly this tactic has spread: poisoning attempts jumped from roughly 628,000 in November 2025 to 3.4 million by January 2026, a more than fivefold increase in just two months. A separate Carnegie Mellon study cited in the same research identified over 270 million on-chain poisoning attempts targeting 17 million wallets, with confirmed losses already crossing $83 million.

How to Avoid Becoming the Next Case

Security researchers point to a handful of habits that neutralize most poisoning attempts: verifying an entire recipient address rather than just the first and last few characters, treating small unsolicited incoming transactions as a red flag rather than free money, maintaining a manually verified address book instead of pulling from raw transaction history, and sending a small test transfer before moving a large sum to a new or infrequently used address.

None of these steps are technically difficult, but the scam's growth suggests habits haven't caught up with the threat. As long as wallets display transaction history in a way that makes copying an address from a past transaction the path of least resistance, address poisoning is likely to keep claiming victims who assume familiarity in their history means safety.