1 min read

Address-Poisoning Attack Leaves User With About $305,000 in DAI Losses

Small “dust” transfers put a lookalike address in transaction history and induced the user to copy it by mistake.

Mentioned assets
A hand checks a phone beside a small test transfer / TokenPost.ai
A hand checks a phone beside a small test transfer / TokenPost.ai

A user lost about $305,000 in DAI after mistakenly copying a fake wallet address from transaction history in an address-poisoning attack.

The fake address matched the prefix and suffix of the address the user expected to use. Small amounts of “dust” funds were sent to induce the user to copy the fake address from transaction history by mistake.

The attack type is fully automated, including target discovery, fake-address generation and laundering through mixers. Users should check the full destination address and avoid copying addresses from transaction history. A small test transfer is advised before sending a larger amount.

Simon Yoon

Reporter

Simon Yoon reports on blockchain technology for TokenPost. Send corrections or tips to info@tokenpost.com.

Loading…