Binance Warns of Address Poisoning Scams Using Lookalike Wallet Addresses
Key Takeaways
- •Binance cautioned that address poisoning scams rely on inserting lookalike wallet addresses into a victim's transaction history rather than compromising the wallet or its private keys.
- •Scammers can generate Ethereum-style addresses that share the same starting and ending characters as a legitimate recipient, so shortened address views should not be treated as proof of authenticity.
- •The fraud typically begins with a zero-value or minimal transaction from the fake address, and the actual loss occurs later when a victim mistakenly sends funds that blockchain transfers cannot reverse.
- •The technique has been observed on networks including Ethereum and BNB Smart Chain, meaning it can affect anyone transacting on public blockchains.
- •Binance recommends verifying the complete destination address, saving verified recipients in an address book, and sending a small test transaction before making larger payments.

Binance has issued a warning to cryptocurrency users about address poisoning scams, in which attackers deliberately place lookalike wallet addresses into victims' transaction histories. The goal of the scheme is to trick users into sending future payments to the wrong destination.
According to the exchange, the scheme relies on a simple weakness in how people retrieve wallet addresses. Rather than compromising a wallet or obtaining its private keys, the attacker attempts to make a fraudulent address appear familiar enough that a user may copy it during a later transaction. Because confirmed blockchain transfers cannot be reversed, the danger sits not in the poisoning transaction itself — often worth nothing — but in the moment a victim later sends funds to the wrong place.
How Crypto Address Poisoning Works
The attack begins when a scammer identifies a wallet that has previously transferred funds to a particular recipient. Because blockchain transactions are publicly visible, the attacker can examine the wallet's activity and identify addresses that the owner may use again.
The scammer then creates another wallet address designed to resemble the legitimate destination. The fraudulent address can be made to share similar characters at the beginning and end, making it harder to distinguish when only shortened wallet addresses are displayed. Two different addresses may therefore appear nearly identical in a shortened view while containing completely different characters in the middle. Generating address candidates until one matches a desired opening and closing sequence is technically straightforward on Ethereum-style networks, so a familiar-looking prefix and suffix should not be treated as proof that an address is genuine.
The attacker subsequently sends a zero-value or small transaction from the lookalike address to the target wallet. This causes the fraudulent address to appear in the wallet's transaction history alongside legitimate transactions. Binance noted that the attacker does not need access to the victim's private keys to carry out the scheme, meaning the wallet itself is never directly compromised.
Why Wallet History Can Become a Trap
The risk emerges when the wallet owner later prepares to send funds to a recipient they have used previously. A user who relies on transaction history rather than retrieving a verified address may accidentally select the attacker's lookalike address instead of the correct one. Once the transfer is approved, the cryptocurrency is sent to the fraudulent wallet rather than the intended recipient, and the blockchain offers no built-in mechanism for clawing it back.
The presence of a small incoming transaction should not be treated as evidence that an address belongs to a trusted recipient. Its appearance in recent activity can nevertheless make the address seem legitimate or familiar, particularly when a payment is being prepared quickly. The attack therefore exploits user behavior rather than directly breaking the security of the wallet itself. For the same reason, a small, unexpected incoming transfer in a wallet's history is worth scrutinizing before the next payment is prepared.
Binance Recommends Verifying the Full Address
Binance advises users to check the complete destination address before approving a cryptocurrency transfer. The exchange also recommends saving verified recipients in an address book rather than repeatedly selecting addresses from transaction history when sending funds.
For larger payments, Binance recommends making a small test transaction first and confirming that it reaches the intended destination before sending the remaining funds.
These precautions are particularly relevant when wallet software shortens addresses or when users routinely copy destinations from recent transactions. The technique has been observed on networks including Ethereum and BNB Smart Chain, a reminder that the method applies anywhere users transact on public ledgers. While the attack itself can begin with a transaction involving little or no value, a subsequent mistaken payment could involve a substantially larger amount.
A blockchain transaction history records where previous activity occurred, but it does not establish that every address appearing there belongs to a trusted recipient. Verifying the complete destination before sending remains an important safeguard against address poisoning scams.
The original report was written by Marcus Renfield, a cryptocurrency market analyst and on-chain writer.
Source: Hokanews. Binance's alert was also published via its official X account: https://x.com/binance/status/2103635663518392667