Investment Company Lost $2 Million in Address Poisoning Attack

cryptonews.ruPublished on 2026-08-24Last updated on 2026-08-24

Abstract

An investment firm, Bofur Capital, lost $2 million in a crypto dusting (address poisoning) attack. The scammers first sent a minuscule 0.0002 USDC transaction to the firm's Ethereum wallet. The recipient address had nearly identical starting and ending characters to a legitimate counterparty the firm regularly transacted with. It is believed a wallet operator later copied the wrong address from the transaction history, inadvertently sending 2 million USDC to the fraudulent wallet, which promptly converted the funds to DAI. Analysts noted the trap was set 20 hours before the large transfer, suggesting hackers monitored the target wallet for a major withdrawal. Following the Ethereum Fusaka upgrade, such address poisoning attacks have surged dramatically. Data shows a 612% increase in USDT dusting transactions over three months, with one investor losing over 500,000 USDT. An earlier Etherscan study (covering July 2022-June 2024) identified roughly 17 million poisoning attempts, affecting at least 1.3 million users and causing over $79.3 million in losses. These attacks are even more frequent on chains with lower fees, like BSC.

The recipient turned out to be wallet 0xF0e6A496...fc19721aF, which was under the control of scammers who had previously sent a micro-transaction of 0.0002 $USDC to the Bofur Capital address on the Ethereum blockchain. The beginning and ending characters of the scammers' address almost completely matched the address of the real counterparty with which the investment company regularly conducted settlements. Presumably, the wallet operator copied the wrong address from the transaction history and pasted it into the transfer field. Upon receiving 2 million $USDC, the unknown parties quickly converted the entire amount into DAI stablecoins.

Analysts noted that the attackers prepared the trap 20 hours before the company executed the stablecoin transaction. They believe the hackers specifically monitored the Bofur Capital wallet, waiting for a large withdrawal, and placed the fake address in advance so it would appear in the transaction history at the right moment.

This spring, following the Fusaka update on the Ethereum network, the number of address poisoning attacks surged sharply. According to Etherscan analysts, over the past three months, the number of "cryptodust transfers" in $USDT has increased by 612%. One crypto investor lost over 500,000 $USDT. However, even before the Ethereum update, this scheme was profitable for scammers.

A 2025 Etherscan study covering the period from July 2022 to June 2024—still before the Fusaka update—identified about 17 million wallet poisoning attempts. At least 1.3 million users were affected by this scheme, with total damages amounting to no less than $79.3 million. Analysts note that in networks with lower fees, such as BNB Smart Chain (BSC), such attacks occur 1355% more frequently.

end-content

Related Questions

QWhat is 'address poisoning' in the context of cryptocurrency?

AAddress poisoning is a scam where attackers send tiny, worthless transactions to a target wallet. The sending address in these transactions is crafted to look almost identical to the address of the victim's legitimate counterparty. The goal is to trick the victim into accidentally copying the scammer's address from their transaction history for a future, large payment.

QHow did the attackers likely trick Bofur Capital into losing $2 million?

AThe attackers prepared the trap 20 hours in advance by sending a 'dust' micro-transaction of 0.0002 USDC to Bofur Capital's wallet. The attacker's wallet address closely mimicked the address of a real counterparty Bofur Capital regularly transacted with. It's suspected that a wallet operator then accidentally copied the scammer's address from the transaction history and pasted it for a large 2 million USDC transfer.

QWhat happened to the stolen $2 million USDC after the attack?

AAfter receiving the 2 million USDC, the unknown attackers quickly converted the entire sum into the stablecoin DAI.

QAccording to the article, how did the Ethereum 'Fusaka' update affect 'address poisoning' attacks?

AAfter the Fusaka update on the Ethereum network in the spring, the number of 'address poisoning' attacks sharply increased. Data from Etherscan indicates that the number of 'cryptodust' USDT transfers surged by 612% in the three months following the update.

QWhat were the key findings of Etherscan's 2025 research on address poisoning attacks before the Fusaka update?

AEtherscan's 2025 research, covering the period from July 2022 to June 2024 (before Fusaka), identified approximately 17 million attempted wallet 'poisoning' incidents. This scheme affected at least 1.3 million users, with total damages of no less than $79.3 million. The study also noted such attacks occur 1355% more frequently on networks with lower fees, like BNB Smart Chain (BSC).

Related Reads

Grayscale Reassesses Zcash: In the Era of AI Surveillance, What is Financial Privacy Worth?

Grayscale Research reevaluates Zcash (ZEC) in the context of AI-powered financial surveillance. The report posits that stablecoins, transparent blockchains, and AI analytics tools are increasing the traceability of digital finance, potentially reigniting mainstream demand for financial privacy as a core monetary attribute. While AI could drive a third wave of privacy concern, Zcash's investment thesis hinges on whether this theoretical demand translates into sustained adoption. Zcash, operational for nearly a decade, uses zero-knowledge proofs to offer users a choice between transparent and shielded transactions, placing control of information disclosure back in users' hands. Recent infrastructure improvements—like wallet enhancements, mining pool expansions, and protocol upgrades—have reduced usability barriers. On-chain data shows shielded transactions comprise ~90% of transaction count, with ~25% of circulating ZEC in shielded pools, indicating existing use. However, significant risks remain. These include regulatory hurdles for exchanges and custodians dealing with shielded assets, past protocol vulnerabilities (theoretical, now patched), long-term quantum computing threats, and execution risks for future scalability upgrades. Grayscale's analysis suggests ZEC's current low market share (~0.6% of the "digital currency" crypto sector) offers valuation upside *if* the market reprices privacy. A scenario analysis notes that capturing 5% of this sector could imply a ~9x valuation increase, though this is a simplified sensitivity test, not a price target. Ultimately, Zcash's opportunity lies in the unresolved question: in an AI-monitored era, what price will the market assign to financial privacy? Validating the thesis requires monitoring growth in real shielded usage, wallet usability, upgrade timelines, and regulatory accessibility, not just price appreciation.

marsbit1h ago

Grayscale Reassesses Zcash: In the Era of AI Surveillance, What is Financial Privacy Worth?

marsbit1h ago

AI Democratizes Hacking, Bitcoin Red Team White Hats Race in Speed-Based Attack-Defense Contest

AI is democratizing powerful hacking tools, putting them in the hands of those with little cybersecurity expertise. Cryptocurrency developers are now in a race to find system vulnerabilities before attackers do. The Bitcoin Red Team, a group of 20-25 volunteers including anonymous developers like Calle, has formed to urgently address these AI-augmented security threats within the Bitcoin ecosystem. Calle emphasizes that while the Bitcoin core protocol itself is secure, the real risk lies in the wallets, applications, services, and other third-party software built on top of it—the software most users interact with. Incidents like the Coldcard wallet hack and the emergence of powerful Chinese AI models have accelerated their proactive security auditing efforts. The team both accepts audit requests from Bitcoin projects and proactively scans major open-source projects. They report found vulnerabilities to developers and refine their classification standards. Notably, Calle states the team frequently uses Chinese AI models over US counterparts, as the latter's strict safety guardrails often block cybersecurity research tasks, hindering their utility for finding or fixing vulnerabilities. Calle warns that AI is erasing the information asymmetry that previously protected some vulnerabilities. It lowers the technical barrier, allowing non-experts to exploit simple flaws. He describes the current state of Bitcoin software as "on fire" and believes the direct financial incentive of cryptocurrency makes it a first target in this industry-wide shift, with other sectors to follow. The era of security through obscurity is over.

marsbit1h ago

AI Democratizes Hacking, Bitcoin Red Team White Hats Race in Speed-Based Attack-Defense Contest

marsbit1h ago

Trading

Spot
活动图片