Skip to content
Sat, Jul 25, 2026
BTC $00,000 ETH $0,000 SOL $000
Your keys are yours — we never ask for them Live
SCAM ALERT

Address Poisoning and Clipboard Hijacking: When the Wrong Address Slips In

Attackers plant look-alike addresses in your history or swap your clipboard to redirect payments. Learn how address poisoning works and how to verify sends.

TokenSpin will never ask you to connect a wallet or enter a seed phrase — and we never link to the scam itself. This is a safety explainer, not a warning about any one named company.

Crypto addresses are long strings of characters that most people never read in full. Scammers exploit that habit with two related tricks: address poisoning, which plants a look-alike address into your transaction history, and clipboard hijacking, which silently swaps the address you copied for one the attacker controls. Both aim to make you send funds to the wrong place.

What the scams are

Address poisoning seeds your wallet’s history with a transaction from an address engineered to resemble one you use. Later, when you copy an address from your own history, you may grab the impostor by mistake. Clipboard hijacking is malware on your device that watches for a copied crypto address and instantly replaces it with the attacker’s, so you paste the wrong destination without noticing.

How they work, step by step

1. Address poisoning

The attacker generates an address whose first and last characters match one you frequently interact with, since those are the parts people glance at. They send you a tiny or zero-value transaction so their look-alike address appears in your history. When you later reuse an address by copying it from that history, you risk copying theirs. You then send real funds straight to the attacker.

2. Clipboard hijacking

Malware, often bundled with a shady download or a fake app, runs quietly on your device. It monitors your clipboard, and the instant it detects a crypto address, it substitutes one of the attacker’s. You copy the correct address, paste it, and the field now shows a different one you may not scrutinize. Confirm the transaction, and the funds go to the thief.

The exact red flags

  • Tiny or zero-value transactions from unfamiliar look-alike addresses appearing in your history.
  • A pasted address whose middle characters differ from what you copied, even when the start and end match.
  • Reusing addresses by copying from transaction history instead of a verified source.
  • Recent installation of unofficial software or wallet tools before addresses started behaving oddly.
  • Any mismatch, however small, between the destination you intended and the one displayed.

How to avoid it

Never copy an address from your transaction history to reuse it, because that is exactly where poisoning hides. Instead, get the address from the recipient through a trusted channel each time, or use a verified, saved contact in your wallet that you set up carefully once.

Always verify the entire address before sending, not just the first and last few characters. Check several characters in the middle too, since look-alikes are built to fool the ends. For large transfers, send a small test amount first and confirm it arrives correctly before sending the rest. Keep your device clean by installing wallet software only from official sources, and be suspicious if a pasted address ever differs from what you copied, as that points to clipboard malware.

These two tricks are dangerous precisely because they exploit convenience rather than fear. There is no urgent message and no emotional pressure; you are simply doing something routine, like paying a wallet you have used before, and the attack rides along on your own good habits gone slightly careless. That is why the defenses are about process rather than vigilance in the moment. If you always source addresses from a verified contact or the recipient directly, always read the full string, and always test large sends, you remove the opportunity these scams depend on. Building those steps into a fixed routine means you stay protected even on the days you are tired, distracted, or moving quickly.

What to do if you are affected

  • If you sent funds to a poisoned or swapped address, understand that the transfer is likely irreversible, and stop any further sends immediately.
  • If you suspect clipboard hijacking, disconnect from the internet, run a reputable malware scan, and do not make transactions until the device is clean. Consider moving funds to a wallet on a device you trust, using a fresh seed phrase if the wallet itself may be exposed.
  • Remove suspicious software and any recently installed unofficial apps or browser extensions.
  • Report the theft to your local police and national cybercrime or fraud reporting service, and preserve the transaction details for investigators. Reputable on-chain security firms sometimes track poisoning campaigns.

A promise from us: TokenSpin will never send you a wallet address to pay, nor ask you to connect a wallet or share a seed phrase. Always verify any address through a trusted, direct channel before sending.

Frequently asked questions

Why do look-alike addresses only match at the start and end?

Because that is what people check. Most of us glance at the first few and last few characters of an address and assume the rest is correct. Attackers generate look-alike addresses that match exactly those visible parts while differing in the middle. That is why the defense is to verify several characters throughout the whole address, and ideally to send a small test transaction first, rather than trusting the ends alone.

How would clipboard-hijacking malware get onto my device?

It usually arrives bundled with software from unofficial sources: cracked programs, fake wallet apps, dubious browser extensions, or downloads from untrusted links. Once installed, it runs quietly and watches your clipboard for anything that looks like a crypto address, swapping it the moment you copy one. Installing wallet and other software only from official sources, and being cautious about downloads, dramatically lowers the risk. If pasted addresses ever change, scan for malware immediately.

I always copy the address from my last transaction. Is that safe?

It is risky, because transaction history is precisely where address poisoning hides. A single look-alike entry seeded by an attacker can be copied by accident on your next send. Instead, obtain the address fresh from the recipient through a trusted channel each time, or use a carefully verified saved contact. Whichever method you use, check the full address before confirming, and consider a small test transfer for anything significant.