Scam patterns
Address poisoning and clipboard mistakes
A familiar-looking history entry can be the wrong destination.
Los artículos de investigación y las referencias se publican en inglés. La navegación está disponible en siete idiomas.
En este artículo
Attackers can place lookalike addresses in a user's transaction history or rely on malware replacing copied text. If the user checks only a few characters at each end, the wrong recipient can look familiar.
Verify the intended recipient
Use an address obtained through a trusted channel and compare it carefully with the transaction being signed. A previous history entry is not automatically a saved contact. For a service, verify the deposit network and any required memo or destination tag as well.
A small test can confirm that a particular route worked at that moment. It does not make a later copied address safe, and an attacker can behave differently after a test. Recheck the actual destination for the main transfer.
If a device is suspected of changing addresses, stop using it to approve transactions. Merely trying a different copy-and-paste method leaves the broader device compromise unresolved. See incident response and custody dependencies.
Fuentes
Investigación revisada el 5 de septiembre de 2026. Historical cases retain the date and legal status of the cited record.