How the scam works
Most people verify addresses by looking at just the first and last few characters. Attackers exploit that. Using software they generate an address whose start and end match one you regularly send to, then send you a worthless transaction (often zero-value or a dust amount) so their look-alike appears in your transaction history or recent list.
Later, when you go to pay your usual recipient, you copy "their" address from your history — but you copy the attacker's. The funds go to the scammer, and because blockchain transfers are irreversible, they're gone.
Why it works
- Wallets and explorers often shorten addresses when displaying them
- Recent history feels trustworthy because it "came from" your own activity
- Attackers can produce matching prefixes and suffixes cheaply at scale
How to protect yourself
- Never copy a recipient from your history. Take the address from the original source — the invoice, the person, a saved contact
- Compare the entire address, not just the ends
- Use saved contacts or human-readable names so you're not pasting long strings at all
- Send a small test transaction before a large transfer
- Ignore unsolicited tiny incoming transactions — they may be bait
What to do if it happens
Funds sent to an attacker generally can't be recovered. Report it and stop sending to any address that resulted from history-copying until you've verified the original.
Why the ends of an address aren't enough
An address on many chains is about 34 to 42 characters. Matching just the first and last four leaves attackers only a few characters of work to imitate, which modern hardware can grind out quickly. Comparing the full string, or better, avoiding manual comparison entirely by using saved contacts or names, removes the weakness the scam depends on.