Crypto Alert: 2 Victims Lose Over $60M In Address Poisoning Scam

bitcoinistОпубліковано о 2026-02-09Востаннє оновлено о 2026-02-09

Анотація

Cryptocurrency users are facing significant losses due to address poisoning scams, where attackers send tiny "dust" transactions from lookalike addresses. When users copy what appears to be a familiar address, they instead send funds to a fraudulent account. In January, one victim lost $12.25 million, following a $50 million loss in December. Additionally, signature phishing is rising sharply, with $6.27 million stolen from 4,741 victims in January—a 207% increase from the previous month. These scams trick users into approving malicious smart contracts. Analysts report approximately 270 million poisoning attempts across Ethereum and Binance Smart Chain, targeting 17 million addresses. Over 6,633 confirmed theft cases have resulted in more than $83.8 million in losses. The Fusaka upgrade on Ethereum, which reduced transaction fees, has made it cheaper for scammers to execute these attacks. Stablecoins like DAI are often used to move illicit funds due to a lack of cooperation with freezing mechanisms.

A simple slip of the fingers has turned into huge losses for some crypto users. One wallet lost over $12 million in January after copying the wrong address, and similar high-value mistakes were seen in December.

Reports say attackers are using tiny deposits and subtle address tweaks to trick people into sending funds to accounts they do not control.

How Copying Mistakes Turn Costly

Address lookalikes are the trick. Attackers send tiny “dust” transfers from addresses that mimic ones in a user’s history so that when someone copies an address they get the wrong string.

According to Scam Sniffer, that single mistake cost one user $12.2 million in January and followed a $50 million hit in December.

The tactic relies on people trusting what appears familiar; it works because most wallets show only the first and last few characters, and the middle can be swapped for a malicious match.

Signature Phishing Is Growing Too

Signature scams lure users into approving dangerous contract calls or broad token approvals. Reports say $6.27 million was stolen from 4,741 victims in January, a 207% rise from December.

Two wallets took the lion’s share — accounting for 65% of those signature phishing losses. Attackers increasingly mix both tricks: small deposits to get attention, followed by social engineering that convinces someone to sign a transaction.

Scale And Automation

This is not limited to a few isolated scams. Based on reports from several trackers, roughly 270 million poisoning attempts have been recorded across Ethereum and Binance Smart Chain, targeting around 17 million addresses.

Total crypto market cap at $2.35 trillion on the daily chart: TradingView

Confirmed cases leading to actual theft number about 6,633, but the confirmed loss figure already tops $83.8 million. One campaign alone created 82,030 lookalike wallets, and in September 2025 there were about 32,290 suspicious poisoning events hitting 6,516 unique victims.

The numbers show a picture of automated scripts and high-volume tactics designed to find and exploit simple human errors.

Image: Chainalysis

Why Ethereum Has Seen More Dust Activity

Analysts link part of the recent surge to the Fusaka upgrade, which lowered the cost of sending tiny transactions. Coin Metrics analyzed over 227 million stablecoin balance updates on Ethereum from November 2025 through January 2026 and found that 38% of those updates were under a single penny.

Stablecoin-related dust now makes up an estimated 11% of Ethereum transactions and touches 26% of active addresses on an average day. Lower fees make these spray-and-pray tactics cheap and efficient.

Where Stolen Funds End Up

Blockchain intelligence teams have tracked flows and noticed patterns. Whitestream reports that DAI has become a favored place to park illicit proceeds because its protocol governance does not cooperate with authorities to freeze wallets.

Web3 Antivirus has cataloged a range of large poisonings, with tracked losses spanning from $4 million to $126 million in some incidents. Once funds move through these paths they are often hard to recover.

Featured image from Arek Socha/Pixabay, chart from TradingView

Пов'язані питання

QWhat is an address poisoning scam in the context of cryptocurrency?

AAn address poisoning scam is a tactic where attackers send tiny 'dust' transfers from addresses that mimic ones in a user's transaction history. This tricks the user into copying the wrong, malicious address when they intend to send funds, resulting in the loss of their cryptocurrency.

QHow much did a single user lose in January due to copying the wrong address, and what was the larger loss reported in December?

AIn January, a single user lost $12.2 million by copying the wrong address. This followed a larger loss of $50 million from a similar mistake in December.

QBesides address poisoning, what other type of attack saw a significant increase in January, and by what percentage did it grow?

ASignature phishing attacks also saw a significant increase. $6.27 million was stolen from 4,741 victims in January, representing a 207% rise from December.

QWhat technical upgrade on the Ethereum network is linked to the recent surge in dusting activity for these scams?

AThe Fusaka upgrade on the Ethereum network is linked to the surge in dusting activity because it lowered the cost of sending tiny transactions, making these spray-and-pray tactics cheap and efficient for attackers.

QAccording to the article, which stablecoin has become a favored place for attackers to park illicit proceeds and why?

ADAI has become a favored place for attackers to park illicit proceeds because its protocol governance does not cooperate with authorities to freeze wallets, making it harder to recover stolen funds.

Пов'язані матеріали

Agent Race Ends, Super Workbench Takes Over

The era of fragmented AI agents is ending. Over the past month, China's tech giants—Tencent, Alibaba, and ByteDance—have simultaneously shifted strategy: instead of launching new, standalone AI agents, they are consolidating their various agent projects into unified "super workbenches." Tencent integrated its QClaw teams into WorkBuddy, a strategic product hailed as a potential third flagship after QQ and WeChat. Alibaba is merging its QoderWork, Wukong, and MuleRun agents into a new "Qianwen Office" platform under DingTalk's leadership. ByteDance rebranded its TRAE SOLO coding agent to TRAE Work, signaling a broader focus on workflow collaboration. This convergence marks a pivotal industry consensus. The initial exploration phase, where companies rapidly built numerous overlapping agents for different scenarios, proved costly and inefficient. With open-source tools eroding technical barriers, competition has shifted from agent creation to resource consolidation and cost control. Historically, platform wars are won not by creating more products, but by simplifying them—as seen with browsers unifying web access and super-apps consolidating services. Now, the "super workbench" aims to become the unified AI entry point for work. This reflects a deeper market realization: the primary audience for AI is no longer just programmers (a market in the tens of millions) but all knowledge workers (a market of billions). The real opportunity lies in augmenting everyday tasks—managing emails, documents, data, and meetings—across the entire workday. The core battleground is becoming control over the primary AI entry point that employees use daily. Tencent's WorkBuddy leverages WeChat and Tencent Docs; Alibaba's Qianwen Office taps into DingTalk's organizational data; ByteDance's TRAE Work integrates with Feishu's workflows. Whoever owns this "super workbench" gains strategic control over orchestrating enterprise data and APIs. This shift is redefining enterprise software. Traditional SaaS applications, valued for their user interfaces, will recede into the background. Their core functionalities will be exposed as standardized "Skills" or APIs for the super workbench's agents to invoke. Software value will shift from selling user seats to charging based on API calls and outcomes delivered. The evolution of agents is moving through clear stages: first as novel standalone products, then as consolidated primary work entry points, and finally as pervasive, invisible capabilities embedded into the digital fabric. The recent moves by major tech firms signal the transition from the first stage into the second, accelerating toward the third. In the end, the most successful agent technology may become invisible—like electricity or the HTTP protocol—a fundamental, unnamed infrastructure powering work itself.

marsbit16 хв тому

Agent Race Ends, Super Workbench Takes Over

marsbit16 хв тому

Michael Saylor: 110 Reasons to Oppose BIP-110

Michael Saylor presents 110 arguments against Bitcoin Improvement Proposal (BIP) 110, a soft fork aimed at restricting certain non-monetary data storage uses (like inscriptions) on the Bitcoin blockchain. He acknowledges the proponents' valid concerns—such as node costs, fee pressure, and preserving Bitcoin's monetary focus—but fundamentally disagrees with the proposed solution. Saylor argues that BIP 110 represents a dangerous precedent of using consensus rules to enforce value judgments on transaction validity, moving away from Bitcoin's core principles of neutrality and permissionless innovation. His key objections are organized into eleven categories: 1) It violates neutrality and hard consensus by banning currently valid transactions. 2) It fails to meet the high burden of proof required for a consensus change, lacking concrete data on the alleged crisis. 3) Its seven bundled technical restrictions are overly broad, targeting generic script functionalities and blocking future upgrade paths. 4) It sacrifices compatibility and future optionality by closing off designed upgrade hooks. 5) Its temporary rules add significant complexity (grandfathering, expiry states) without sufficient justification. 6) The economic and security impacts, particularly on miner revenue and fee markets, are uncertain and unmodeled. 7) Superior, market-based tools (fee markets, relay/mining policies) already exist to manage blockchain load. 8) It stifles innovation by creating a chilling effect for developers. 9) Its modified activation mechanism (55% threshold, forced signaling) is aggressive and risks network splits. 10) The precedent it sets—using consensus to suppress disliked but legal uses—is more dangerous than the problem it aims to solve. 11) A better path exists: improving measurements, refining resource-based policies, and allowing market forces to work. Saylor concludes that Bitcoin's strength lies in its neutral rules, open markets, and hard consensus. Changing these foundational elements to target specific use cases is an unnecessary and risky "iatrogenic" intervention. He advocates for guarding Bitcoin's neutrality rather than acting as its redeemer.

marsbit32 хв тому

Michael Saylor: 110 Reasons to Oppose BIP-110

marsbit32 хв тому

Торгівля

Спот
活动图片