Accept crypto with CoinGate
Accept crypto with confidence using everything you need in one platform.
Address Poisoning: How a Lookalike Address Steals a Crypto Payout
You pay the same supplier every month. Their address is in your history, so you copy it from last month’s payment, paste it, check the first and last few characters, and send.
The first and last characters matched. The middle did not. The money is gone, and there is no bank to call.
That is address poisoning. It does not break into anything. It waits for a habit.
Paying suppliers, affiliates or refunds in crypto? Open a CoinGate account.
How the attack works
It takes three steps, and none of them needs access to your wallet.
- The attacker watches the chain for regular payments, usually stablecoin transfers between the same two addresses. Every transfer on a public blockchain is visible to anyone who looks.
- They generate an address that looks like one you use. Software can churn through addresses until one matches the characters most people check, the first few and the last few. Chainalysis describes attackers generating addresses “until they create one that closely resembles the address that the target most often interacts with”.
- They send you something tiny from that lookalike. Often it is a transfer of zero tokens, which costs them almost nothing and puts their address in your history, right next to the real one. Then they wait.

The money only moves when you copy the wrong line.
It rarely works, which is why it goes out to so many people at once. One 2024 campaign that Chainalysis analysed planted 82,031 lookalike addresses against 2,774 target wallets, and only 0.03% of the fake addresses received more than 100 dollars. The one that did work took about 68 million dollars in wrapped bitcoin in a single transfer on 3 May 2024. That victim eventually got the money back.

Why a business is the better target
A person sends crypto to a handful of addresses. A business that pays suppliers, affiliates, contractors or refunds sends to many, often repeatedly and often from the same wallet. That makes its history long and predictable, which is exactly what the attack needs.
And a business payout is final. Once a crypto payout is sent, the only way to get it back is to ask the recipient to return it. When the recipient is an attacker, that conversation does not happen.
The two checks that do not work
Checking the first and last four characters is precisely what the lookalike was built to pass. MetaMask’s own advice is to “pay close attention to the middle characters, not just the start and end”.
A test payment does not help either. Sending a small amount first proves that the address can receive money. It does not prove that the address belongs to the person you meant to pay. The attacker will be happy to receive your test.

What actually stops it
Never copy an address from your transaction history
This is the whole attack in one habit. Take addresses from the recipient, from an invoice they sent you, or from a list you keep yourself, never from the list of past transactions in a wallet or an explorer.
Pay saved recipients instead of pasted addresses
On CoinGate you can save a recipient once and pick them from your saved payout contacts every time after that, in the dashboard or through the API. You check the address once, when you add the recipient, instead of every time you paste it.

Let the recipient enter their own address
With a Payout Link you send an amount to an email address. The recipient confirms a one-time code sent to that email and types in their own wallet address. Nobody on your side copies an address at all, so there is nothing in your history to poison.

Prove the wallets you withdraw to
When you withdraw crypto to a self-hosted wallet of your own, we ask you to prove that you control it before the funds go out, by connecting the wallet, signing a message with it or, as a fallback, sending a screenshot. Once an address is approved, it stays approved for next time. A lookalike fails that check by design, because you do not hold its keys.

Put a second person in front of every batch
With four-eye approval switched on, every batch payout one team member submits waits for a second authorised person before it goes out, and the person who created the batch cannot approve it. The funds are held while it waits, so they cannot be spent twice, and a rejection returns them. You need at least two users with the Owner, Administrator or Accountant role.

Payout Links have an approval setting of their own. When it is on, every new link waits in draft until someone other than its creator approves it. A second person reading the address is exactly the step address poisoning hopes you skip.
Read the whole address on the device
If you sign payments from a hardware wallet, most models show the destination on their own screen before you confirm. Read all of it there, not in the app you pasted it into.
If it has already happened
Stop sending from that history until you have checked every saved address against the real one. Write down the transaction hash and the lookalike address, report it to your wallet provider and to the police, and treat anyone who contacts you offering to recover the funds for a fee with a great deal of suspicion.
For the wider picture of what a crypto payout can and cannot undo, can crypto payments be reversed covers the rest.
Address poisoning needs one shortcut to work. Take the shortcut away, with saved recipients, links the recipient fills in themselves and a second person on every batch, and it has nothing left to work with.
Want payouts where nobody on your team has to paste an address? Start with us.
Accept crypto with CoinGate
Accept crypto with confidence using everything you need in one platform.