Scam patterns
Address poisoning and clipboard mistakes
A familiar-looking history entry can be the wrong destination.
Os artigos de investigação e as referências são publicados em inglês. A navegação está disponível em sete idiomas.
Neste artigo
Attackers can place lookalike addresses in a user's transaction history or rely on malware replacing copied text. If the user checks only a few characters at each end, the wrong recipient can look familiar.
Verify the intended recipient
Use an address obtained through a trusted channel and compare it carefully with the transaction being signed. A previous history entry is not automatically a saved contact. For a service, verify the deposit network and any required memo or destination tag as well.
A small test can confirm that a particular route worked at that moment. It does not make a later copied address safe, and an attacker can behave differently after a test. Recheck the actual destination for the main transfer.
If a device is suspected of changing addresses, stop using it to approve transactions. Merely trying a different copy-and-paste method leaves the broader device compromise unresolved. See incident response and custody dependencies.
Fontes
Investigação verificada em 5 de setembro de 2026. Historical cases retain the date and legal status of the cited record.