1 min read
Address-Poisoning Attack Leaves User With About $305,000 in DAI Losses
Small “dust” transfers put a lookalike address in transaction history and induced the user to copy it by mistake.

A user lost about $305,000 in DAI after mistakenly copying a fake wallet address from transaction history in an address-poisoning attack.
The fake address matched the prefix and suffix of the address the user expected to use. Small amounts of “dust” funds were sent to induce the user to copy the fake address from transaction history by mistake.
The attack type is fully automated, including target discovery, fake-address generation and laundering through mixers. Users should check the full destination address and avoid copying addresses from transaction history. A small test transfer is advised before sending a larger amount.