By: Eliza Bennet
A crypto trader recently fell victim to a sophisticated scam, losing $2.5 million in Tether (USDT). The incident occurred within a few hours as the trader unknowingly conducted two separate transactions to a phony address that closely mimicked a legitimate one in their transaction history. This scam tactic, often referred to as "address poisoning" or "history poisoning," exploits the typical user behavior of copying recipient addresses from their transaction logs.
Such scams involve scammers sending minuscule transactions from addresses that resemble legitimate ones, effectively embedding these addresses into the victim's transaction history. When users subsequently copy and paste an address from this tainted history, they inadvertently send funds to the scammer's address instead. This method has become increasingly prevalent due to its reliance on subtle, low-effort manipulations that exploit common user mistakes and interface familiarity.
This particular case is alarmingly similar to another incident in which a victim lost $2.6 million in stablecoins through successive zero-value transfer phishing scams. In that scam, attackers used a method that involves tricking users into sending real funds by manipulating token transfer functions to send zero tokens from the victim's wallet to a scam address. The deception is compounded by the use of the token transfer From function, a technique that snags unsuspecting victims in a sophisticated trap.
As these scams become more advanced, blockchain security experts are sounding the alarm about the evolving threat landscape. Social engineering tactics, for instance, are increasingly employed to directly target users. SMS phishing campaigns that impersonate notable crypto exchanges such as Coinbase have become rampant. Victims are led to believe they need to address a security issue by calling a support number, where they unknowingly hand over their recovery or mnemonic phrases on a phishing website.
Blockchain analysis suggests that such social engineering scams have cost users hundreds of millions. To mitigate these risks, users are advised to avoid sharing sensitive information such as recovery phrases, ignore unsolicited communications, verify interactions through official crypto exchange websites, and remain vigilant at all times to avoid falling prey to these scams.