Scam patterns
Address poisoning and clipboard mistakes
A familiar-looking history entry can be the wrong destination.
Les enquêtes et les fiches de référence sont publiées en anglais. La navigation est disponible en sept langues.
Dans cet article
Attackers can place lookalike addresses in a user's transaction history or rely on malware replacing copied text. If the user checks only a few characters at each end, the wrong recipient can look familiar.
Verify the intended recipient
Use an address obtained through a trusted channel and compare it carefully with the transaction being signed. A previous history entry is not automatically a saved contact. For a service, verify the deposit network and any required memo or destination tag as well.
A small test can confirm that a particular route worked at that moment. It does not make a later copied address safe, and an attacker can behave differently after a test. Recheck the actual destination for the main transfer.
If a device is suspected of changing addresses, stop using it to approve transactions. Merely trying a different copy-and-paste method leaves the broader device compromise unresolved. See incident response and custody dependencies.
Sources
Recherche vérifiée le 5 septembre 2026. Historical cases retain the date and legal status of the cited record.