Official MASTR logo MASTR Support the work
Contents
← Wiki home

Scam patterns

Address poisoning and clipboard mistakes

A familiar-looking history entry can be the wrong destination.

Scam guide · 1 min read

Research articles and reference entries are published in English. Navigation is available in seven languages.

In this article
  1. Verify the intended recipient

Attackers can place lookalike addresses in a user's transaction history or rely on malware replacing copied text. If the user checks only a few characters at each end, the wrong recipient can look familiar.

Verify the intended recipient

Use an address obtained through a trusted channel and compare it carefully with the transaction being signed. A previous history entry is not automatically a saved contact. For a service, verify the deposit network and any required memo or destination tag as well.

A small test can confirm that a particular route worked at that moment. It does not make a later copied address safe, and an attacker can behave differently after a test. Recheck the actual destination for the main transfer.

If a device is suspected of changing addresses, stop using it to approve transactions. Merely trying a different copy-and-paste method leaves the broader device compromise unresolved. See incident response and custody dependencies.

Sources

  1. MASTR: Crypto Survival Guide, four original panels
  2. Ethereum: security and scam prevention

Research checked 5 September 2026. Historical cases retain the date and legal status of the cited record.

Related reading

scams

Search-ad poisoning

A paid search result places a clone above the real exchange or protocol.

MASTR

Support independent research

The investigations, original evidence and guides here are free to read. Voluntary donations help fund the research and keep MASTR’s tools available.

Open wallet