The recipient turned out to be wallet 0xF0e6A496...fc19721aF, which was under the control of scammers who had previously sent a micro-transaction of 0.0002 $USDC to the Bofur Capital address on the Ethereum blockchain. The beginning and ending characters of the scammers' address almost completely matched the address of the real counterparty with which the investment company regularly conducted settlements. Presumably, the wallet operator copied the wrong address from the transaction history and pasted it into the transfer field. Upon receiving 2 million $USDC, the unknown parties quickly converted the entire amount into DAI stablecoins.
Analysts noted that the attackers prepared the trap 20 hours before the company executed the stablecoin transaction. They believe the hackers specifically monitored the Bofur Capital wallet, waiting for a large withdrawal, and placed the fake address in advance so it would appear in the transaction history at the right moment.

This spring, following the Fusaka update on the Ethereum network, the number of address poisoning attacks surged sharply. According to Etherscan analysts, over the past three months, the number of "cryptodust transfers" in $USDT has increased by 612%. One crypto investor lost over 500,000 $USDT. However, even before the Ethereum update, this scheme was profitable for scammers.
A 2025 Etherscan study covering the period from July 2022 to June 2024—still before the Fusaka update—identified about 17 million wallet poisoning attempts. At least 1.3 million users were affected by this scheme, with total damages amounting to no less than $79.3 million. Analysts note that in networks with lower fees, such as BNB Smart Chain (BSC), such attacks occur 1355% more frequently.
end-content




