Skip to main content

What Is an Address-Poisoning Scam?

How Address Poisoning Works​

An address-poisoning scam attempts to place a look-alike address in your public transaction history. The attacker hopes you will later copy that address instead of the legitimate recipient and send funds to the attacker.

A typical attempt follows this pattern:

  1. The attacker reviews public blockchain activity.
  2. They create or select an address whose beginning and ending resemble an address you previously used.
  3. They send a small or zero-value transaction involving your address.
  4. The look-alike address appears in a wallet or explorer history.
  5. The attacker waits for you to copy it into a future transaction.

The unexpected transaction does not necessarily mean the attacker controls your wallet. The loss occurs if you send assets to the poisoned address.

danger

Never select a recipient only because its shortened form looks familiar. Verify the complete address using a trusted source before every transfer.

Why Shortened Addresses Can Look Identical​

Wallets and explorers often shorten long addresses for readability by showing their beginning and ending. Two different addresses can therefore look similar in a transaction list.

Gem Wallet copies the complete receive address even when a shortened version is displayed. It also validates whether a recipient has a valid format for the selected blockchain. Format validation does not prove that the address belongs to the intended person.

Inspect a Suspected Poisoning Transaction Safely​

Do not send a test transaction or interact with an unexpected token. Use public transaction information:

  1. Open the affected asset in Gem Wallet.
  2. Select the unexpected transaction from the activity list.
  3. Check its status, direction, amount, participant, and network.
  4. Select View on explorer name.
  5. Compare the complete suspicious address with the legitimate address from your trusted source.
  6. Record the public transaction ID if you need to report it.

Different complete addresses confirm that the history entry must not be used as the recipient.

caution

Do not visit websites, call phone numbers, approve contracts, or follow instructions contained in unexpected token names or transaction data.

Enter a Recipient Safely in Gem Wallet​

Use one of these trusted sources:

  • Copy the address directly from the recipient's current receive screen.
  • Scan a QR code displayed by the recipient or their official deposit page.
  • Select one of My Wallets when transferring between your own Gem Wallet wallets.
  • Use a Gem Wallet contact that you previously created and independently verified.

Then:

  1. Open the asset and select Send.
  2. Enter the address in Address or Name or use the QR scanner.
  3. Confirm that the asset and network match the recipient's instructions.
  4. Compare the complete address with the trusted source.
  5. Review the recipient again on the confirmation screen.
  6. For a large or first-time transfer, send a small amount and confirm receipt before sending the remainder.

Do not copy the address from a previous transaction, an unexpected incoming transfer, or an explorer search result.

Respond to a Suspicious Activity Warning​

Gem Wallet scans supported transactions before confirmation. If the destination is linked to suspicious or harmful activity, the app can display Suspicious Activity and prevent the transaction from completing.

Cancel the transaction and obtain the recipient address again from a trusted source. Do not alter a few characters or attempt to bypass the warning.

Transaction scanning is an additional safeguard, not a substitute for checking the recipient. A new poisoning address may not yet be identified as harmful.

If You Have Not Sent Funds​

No asset recovery is necessary if the attacker only placed a transaction in your history and you did not send to the look-alike address.

  • Do not interact with the suspicious address or token.
  • Obtain future recipient addresses from a trusted source.
  • Keep the public transaction ID if you want to report the attempt.
  • Continue monitoring the wallet for unauthorized outgoing transactions.

You do not need to expose, replace, or import your Secret Phrase merely because someone sent an unsolicited transaction to your public address.

If You Sent Funds to the Poisoned Address​

Blockchain transactions are generally irreversible. Gem Wallet cannot cancel a successful transaction or move funds from an address controlled by an attacker.

  1. Open the transaction and select View on explorer name.
  2. Save the transaction ID, destination address, asset, amount, network, and time.
  3. Confirm whether any other unauthorized outgoing transactions exist.
  4. Report the address and transaction to the relevant exchange, service, or authorities.
  5. Open Settings > Support in Gem Wallet for help understanding the public transaction.

Sending to a poisoned address does not by itself reveal your Secret Phrase. However, if you also entered the phrase into a website or app, follow What to Do If Your Secret Phrase Is Exposed immediately.

Prevent Address-Poisoning Losses​

  • Never reuse an address by copying it from transaction history.
  • Compare more than the first and last few characters.
  • Verify the complete address through a trusted channel.
  • Confirm the blockchain network as well as the address.
  • Use My Wallets, verified contacts, or a trusted QR code when appropriate.
  • Review the recipient on the final confirmation screen.
  • Send a small test transfer before a large first-time payment.
  • Stop if Gem Wallet displays Suspicious Activity.

For other recipient mistakes, see What to Do After Sending Crypto on the Wrong Network and Send Issues.