Address Poisoning Scam Drains $100K USDT From Crypto User

2–3 minutes
Fact Checked by Mazel Ventura

Last Updated:

August 13, 2026

Crypto address poisoning scam showing a 100,000 USDT transfer.

Address Poisoning Scam Drains $100K USDT From Crypto User

Crypto address poisoning scam showing a 100,000 USDT transfer.

Address Poisoning Scam Drains $100K USDT From Crypto User

A crypto user lost nearly 100,000 USDT after sending the funds to a fake wallet address that had been sitting in their transaction history for 66 days, according to blockchain security firm Cyvers Alerts. The attacker planted that address months earlier and waited for the victim to copy it out of habit instead of typing the real one again. Cyvers said the stolen stablecoins were swapped into roughly 52.8 ETH within minutes, a move that made the funds much harder to freeze.

How the 66-Day Address Trap Was Set

About 66 days before the theft, the attacker sent small transactions involving the victim’s wallet, Cyvers Alerts reported. Those transactions placed a lookalike address inside the wallet’s transaction history, right next to an address the victim had genuinely used before. Most wallets and block explorers only display the first and last few characters of a full address, so the planted entry blended right in.

When the victim later went to send 100,000 USDT, they pulled the destination from that transaction history instead of checking it character by character. The address looked correct at a glance. It wasn’t, and the payment landed in the attacker’s wallet instead of the intended one.

Tether can freeze USDT tied to a specific address through its smart contract, which sometimes gives scam victims a narrow shot at recovery. ETH carries no equivalent freeze function, so converting the stolen funds removed that option almost immediately. Cyvers has not reported any recovery, return agreement, or exchange intervention tied to this case, and the victim hasn’t been named publicly.

What This Means for Anyone Sending Stablecoins

This attack didn’t require a stolen private key, a hacked exchange, or a bug in Tether or Ethereum. It worked because the victim trusted a shortened address in their own wallet history. Anyone who regularly sends USDT, ETH, or other tokens to addresses they’ve used before is exposed to the same setup, especially beginners who assume a familiar-looking entry is safe. 

A fake Ledger app that drained $9.5 million from crypto users earlier this year shows the pattern isn’t limited to address history. Reviewing basic wallet security habits before moving large amounts is worth the extra few minutes.

The Full-Address Check That Actually Stops This

Cyvers has repeatedly told users to compare the complete address string before sending funds, not just the first and last characters most wallets show by default. For larger transfers, the security firm also recommends confirming the destination through a separate channel and sending a small test amount first. 

A test transfer alone isn’t foolproof either. In at least one earlier case, an attacker slipped in a new lookalike address between the test payment and the full transfer, so the sender still has to check that both transactions used the identical address.

What this means for you: A shortened address in your wallet history can look identical to the real one even when it isn’t, and checking the full string before sending funds is one of the few ways to catch this type of scam before it’s too late.

Join our growing community

David Constantino

Author

David is a crypto enthusiast, airdrop farmer, and blog writer with a focus on discovering and analyzing new token launches and blockchain projects. He explores the latest trends, shares actionable insights, and guides readers through opportunities in the fast-paced world of digital assets.