[ad_1]
Address poisoning relies heavily on user negligence, as a lazy or rushed user is likely to copy the crypto wallet address from transaction history to transfer funds.
Since the cryptocurrency industry is still in its early stages of development, the security that governs blockchain technology is not as advanced as it could be. As a result, hackers frequently exploit loopholes to prey on inexperienced cryptocurrency investors and traders.
While some crypto scams can be detected using automated software or on-chain trackers, a relatively new scam technique known as “address poisoning” hides itself in such a way that it is virtually impossible to detect if one is negligent.
Address poisoning, unlike phishing attacks, upgrade scams, and investment scams, is not as destructive, but it can still eat away at your resources. Let’s find out what address poisoning is and how it is performed.
What is Crypto Address Poisoning?
Address poisoning is a scam method where malicious actors send the victim a small value of crypto or NFT from an address that shares the first and last characters with the victim’s address. The scammer then hopes that the victim will mistakenly copy this fraudulent address for future transactions, thinking it is his. This would end up sending funds to the crooks address instead of the desired account.
Since crypto addresses are a hard-to-remember combination of alphanumeric characters, hackers generate similar-looking addresses using open-source tools like Profanity to scam the user.
Usually, crypto users don’t check their whole address chain but only the first and last letters. Even some crypto exchanges and providers only show the first and last characters to make work easier. This is the loophole that scammers take advantage of.
So when one checks one’s transaction history and copies an address believed to be one’s by only looking at the first and last four characters but skipping the middle section, one may fall into a trap well-planned hackers and end up sending them funds. This is how the poisoning of the address takes place.
How to avoid address poisoning?
Address poisoning relies heavily on user negligence, as a lazy or rushed user is likely to copy the crypto wallet address from transaction history to transfer funds.
The obvious and obvious way to avoid address poisoning is to double-check your address before making any transactions. These types of attacks are known to take place on Polygon, Binance smart chain, and Tron because they have relatively lower transaction fees, making it easy for scammers to send small funds cheaply.
However, an address poisoning incident also happened recently on the Ethereum blockchain. A few weeks ago, Arbitrum, an Ethereum layer 2 scaling solution, airdropped ARB tokens in which over 630 wallet addresses were poisoned, resulting in the loss of 933,365 ARB tokens.
The hackers stole funds from Arbitrum users who later complained that their ARB tokens had been self-claimed from the hackers’ wallets. In an unexpected twist, it was later revealed that 933,365 tokens had been received from a different address whose owner was tagged as Fake_Phishing18.
According to Arbitrums blockchain explorer, a user under the pseudonym Fake_Phishing18 created a malicious ARB token contract. When a user interacted with said contract, an additional transaction was created which appeared to come from the victim’s wallet. However, this was a more advanced case of address poisoning in which a hacker linked it to a phishing attack.
According to PeckShield Alert, a blockchain security firm, the hacker converted 933,375 ARB into 713 ETH worth $1.27 million and linked these tokens to the Ethereum mainnet. Reportedly, two other wallets also stole 105,000 ARB tokens, although it is unclear whether or not they belong to the same hacker.
Conclusion
Blockchain technology offers transaction transparency and traceability, but it is also vulnerable to scammers who can easily find large numbers of addresses from block explorers to carry out address poisoning attacks. The only way to avoid this attack is to always keep a secure copy of your wallet address and not interact with suspicious smart contracts shared on social media handles or Discord channels.
|
Sources 2/ https://www.cnbctv18.com/cryptocurrency/what-is-address-poisoning-and-what-can-crypto-investors-do-to-avoid-such-attacks-16365891.htm/amp The mention sources can contact us to remove/changing this article |
[ad_2]