Address Poisoning: How to Avoid Sending USDT to a Scammer
A scammer plants a lookalike address in your history. You copy it and the money is gone. Here's how the attack works and how to stop it.
In short: address poisoning is when a scammer sends you a tiny or zero-value transaction from a wallet whose first and last characters match an address you use often. The lookalike lands in your transaction history, and next time you copy it from there without checking the middle of the string, you send funds straight to the attacker. The fix is simple: never copy an address from your history, verify the whole string, keep a real address book, and send a test transfer first. Funds sent to the wrong address on TRON are almost impossible to recover, so every safeguard only works before you hit Send.

What address poisoning is and why it works
Address poisoning attacks the habit of copying an address from your history, not your wallet or your private key. The scammer doesn't need access to your funds; they're counting on you to send the money to them, mistaking their address for a familiar one. It hinges on a single human trait: we read long strings by their beginning and end, not in full. A TRON address looks like TXYZ…long middle…AB12, and your eye locks onto the first and last few characters while the dozens in between register as noise.
That gap in attention is exactly what the con targets. Using automated scripts, the attacker generates an address whose start and end match someone you pay often — an exchange, a partner, your own second wallet. Matching the middle is computationally hard; matching the edges is easy. The result is a string that looks indistinguishable at a glance from the real one. block-chain24 (2026) describes the same mechanic: attackers create near-identical addresses and seed them into your history with small transfers.
The mechanics: how the fake address lands in your history
The core move is to drop the lookalike into your transaction list so you pull it from there yourself. It's done in one of two ways.
- A dust transfer. The scammer sends a token amount of USDT — a fraction of a cent — or a speck of TRX to your address. The transaction is real, so it shows up honestly in your wallet and in the explorer, with the lookalike address right next to it.
- A zero-value transfer. A script triggers a 0-token transfer 'from you' to the lookalike. Your balance doesn't change, but the history now shows an entry as if you'd sent funds there, making the address look 'verified.'
- A reaction to your own move. Some attacks fire right after you transact: the moment you pay the real address, the script mints a twin with the same edges and sends dust from it so it lines up right beside the genuine one.
A TRON-specific note: poisoning dust is a real Transfer, which is why it shows in your history. A separate trick — an approve prompt asking you to 'confirm' a huge token allowance — is not a deposit and never becomes a balance. We covered how to tell Transfer apart from Approve in our Tronscan guide.
Why copying an address from your history is dangerous
Your transaction history is not an address book. It's a log of everything that touched your address, including incoming transfers from anyone — the scammer included. When you copy the recipient 'like last time,' you're not picking a verified contact; you're grabbing a line from a list the attacker was free to write into.
A documented case from December 2025 shows how expensive this gets (it happened on another network, but the poisoning mechanic is identical on any chain, including TRON). As a precaution, a trader sent a $50 test to the correct recipient address. The attacker's script instantly minted a twin address with the same start and end and seeded it into the history. On the next transaction the trader copied that address without checking the middle and sent 49,999,950 USDT straight to the attacker; the victim then posted an on-chain message offering a $1 million bounty for the funds' return — as reported by crypto.news and The Block (2025). The money never came back: it was swapped almost immediately and routed through a mixer.
Verify the whole address, not the first and last characters
The rule that's worth more than any antivirus: verify the address in full. 'The start and end match' is precisely the state the scammer engineers — not a sign that the address is right. Practical habits:
- Read the middle. Run your eyes through the center of the string, not just the edges. That's where the twin diverges.
- Check by character groups, not 'by feel.' Take 3–4 characters from the middle of the real address and find them in whatever landed in the recipient field.
- Don't trust the truncated view. Many wallets and exchanges show an address as TXYZ…AB12 — in that form the twin and the real address are indistinguishable. Expand the full string before sending.
- Keep a reference elsewhere. The correct recipient address should live somewhere trusted (an address book, a secured note), not only 'somewhere in the history.'
If the recipient is an exchange or a service, pull the deposit address fresh from the deposit page each time — not from a chat, a screenshot, or a past transaction.
Address book and whitelisted addresses as a defense
The strongest structural defense is to stop typing or copying addresses by hand for recurring recipients. Build your own address book and add each address once, verifying it in full while you're calm. After that you pick a recipient by a human-readable name ('Exchange — USDT deposit') instead of a 34-character string, and there's nowhere for a swap to hide.
- Whitelisting. If your wallet or exchange supports a withdrawal allowlist, turn it on. Then funds can only go to addresses you pre-approved, and any new address requires a separate, delayed confirmation.
- Your book, not your history. keep your own list of verified addresses separate from your transaction history — the history is poisonable, the book is under your control.
- Separate addresses by purpose. A dedicated recipient per task is easier to verify and harder to confuse.
- Less manual entry, smaller attack surface. Copying from a messenger, an email, or an old transaction are the three most common sources of error.
A small test transfer before a large one
A test transfer is a healthy habit: send a small amount, wait for the recipient to confirm it arrived at the exact address they expect, and only then send the main amount. But there's a catch that undid the trader above — the test itself signals to the scammer's script that a large transfer is coming. So the test only protects you when paired with verifying the full address on the second step.
An illustration (figures chosen for clarity, not a real case). Say you're about to send 5,000 USDT to a partner. Before: you send a 10 USDT test, see 'received,' come back the next day, copy 'that same' address from history, and send 5,000 — but you grab the twin the script slid in right after your test. After: once the test clears you don't touch the history — you open your address book, where the partner's address sits verified, send 5,000 there, and match 4 characters from the middle. The difference is one habit; the stakes are the whole amount.
One more thing about TRON and energy: for the test and the main USDT TRC-20 transfer to go through without a fee crunch, you need energy. A single USDT transfer burns roughly 65,000 energy (a network figure that depends on contract state on the day), and sending to a new, not-yet-activated address costs more because activation is charged on top. Without energy, the network burns your TRX at the current getEnergyFee rate (100 sun per unit right now, a network parameter). We covered how to move USDT without a TRX buffer separately.
What to do the moment you send to the wrong address
Honestly and without false hope: TRON transactions are irreversible. There is no 'bank' to reverse the transfer and no undo button — once funds reach a stranger's address and confirm in a block, it can't be rolled back. Even so, right after a mistake it's worth doing a few things — not for a magic refund, but to limit the damage and lock in the facts.
- Stop and don't send a 'chaser.' Panic-sending more to the same address only grows the loss.
- Record the TXID and the twin address. Save the transaction hash and both addresses (the correct one and where it actually went) — you'll need them for any follow-up.
- If the recipient is an exchange or a large service, contact their support with the TXID. If the address belongs to a centralized platform, there's sometimes a chance of a review — but it's not a guarantee and not a 'refund button.'
- Report the scam address. The USDT issuer and analytics services keep scam-address lists; an issuer-side freeze is possible in some cases, but you can't rely on it.
- Screen the address. Before your next transactions, run an AML check on it — we explain how in our guide.
- Don't fall for 'recovery services.' Anyone who DMs you promising to recover misdirected funds for an upfront fee is a second layer of fraud. On-demand recovery does not exist.
The takeaway from this section is singular: all real protection happens before you press Send. After the block confirms, only damage control remains.
Related reading on our blog: how to read transactions and addresses in Tronscan, what to do when USDT is sent but not received, how to check an address and USDT TRC-20 for AML and freeze risk, and how to send USDT without a TRX buffer.
External sources: the documented $50M case — crypto.news (2025) and The Block (2025); the address-substitution mechanic — block-chain24 (2026).
Where Overtron fits in
Overtron can't undo an on-chain mistake — irreversibility is the same for everyone. But we're on the side of sending deliberately: verify the full address, keep trusted recipients in an address book instead of your history, and test before a large transfer. So the transfers themselves don't stall on fees, the @overtronbot bot lets you rent energy for the number of transfers you need: pick the amount and term, pay, and the delegated energy usually appears on your address within a few minutes. Start in the bot at https://t.me/overtronbot or on the site at /en/.
Читайте также
What is address poisoning in plain terms?
A scammer sends you a transaction from an address whose start and end match an address you pay often. The lookalike sits in your wallet history, and next time you copy it from there without noticing the middle of the string is different — and send the money to the scammer.
Can poisoning drain my wallet without me doing anything?
No. It's not a key compromise and not access to your funds. The attack only works if you yourself send a transfer to the twin address. Until you hit Send on the swapped address, your funds are safe.
Why shouldn't I copy an address from my transaction history?
The history is a log of all activity, including incoming dust and zero-value transfers from scammers. Copying from it risks grabbing a twin string. Pull the address from your address book or from the recipient's deposit page fresh each time instead.
How can I verify an address quickly without wasting time?
Don't look only at the first and last characters — those are exactly what gets faked. Take 3–4 characters from the middle of the reference address and find them in the recipient field. If the middle doesn't match, it's a twin.
Does a test transfer help?
It helps, but not on its own. Send a small amount, wait for the recipient to confirm, and still verify the full address before the main transfer — because the test itself can prompt a scammer to slip a twin into your history right after it.
Can I recover USDT sent to the wrong address on TRON?
Practically no. TRON transactions are irreversible: a transfer confirmed in a block can't be undone. If the address belongs to an exchange there's a slim chance of a review through its support, but it's not a guarantee. Never trust services that promise recovery for an upfront fee — that's a separate scam.
What is a zero-value transfer in this attack?
It's a 0-token transaction a script triggers to look as if you sent funds to the twin address. Your balance doesn't change, but a history entry appears, creating the false impression that the address is already 'verified.'
How do an address book and whitelisting protect against swaps?
You add an address to the book once, verifying it carefully, and afterward pick recipients by name rather than by string. Whitelisting only allows withdrawals to pre-approved addresses, and any new address needs a separate confirmation. There's nowhere for a swap to appear.
What do TRON energy and USDT transfers have to do with this?
Every USDT TRC-20 transfer consumes roughly 65,000 energy (a network figure that depends on contract state on the day), and sending to a new address costs more because of activation. Without energy the network burns your TRX at the current rate. Renting energy lets you make both the test and the main transfer without overpaying on fees.

