Binance Flags ‘Address Poisoning’ as a Growing Threat to Crypto Wallet Users

binance flags address poisoning as a growing threat to crypto wallet users Your private keys stay untouched. Nobody cracks your wallet, and nobody phishes your seed phrase. The scammer just waits for you to copy the wrong address, and the whole scheme depends on that one moment.

Your private keys stay untouched. Nobody cracks your wallet, and nobody phishes your seed phrase. The scammer just waits for you to copy the wrong address, and the whole scheme depends on that one moment.

Binance, one of the biggest crypto exchanges, has put out a warning about address poisoning. The scam doesn’t break into anything. It works with lookalike wallet addresses and ordinary human error. “Not every crypto scam involves hacking,” the exchange wrote in its post.

A single wrong paste can cost you

The scheme exploits a habit that most active crypto users have. Because they keep sending funds to the same small set of addresses, they stop typing them out. They scroll through their transaction history, pick the entry that looks correct and copy it.

Address poisoning turns that convenience into a weakness. “A single copy-paste mistake can send funds to a scammer — and blockchain transactions can’t be reversed,” Binance warned.

The second part of that warning is the one that counts. No bank will cancel the payment, and no support request will return the funds. Money sent to a poisoned address may never be recovered.

How the fake address gets planted

The attackers are patient and work step by step. They start by picking a target wallet that shows recurring transactions. Binance says the usual targets are active crypto users holding larger balances.

Next, automated tools create a lookalike address whose first and last few characters match an address the victim sends to often. The attacker is counting on how wallets display addresses: shortened, with the middle removed, so the user only sees the beginning and the end.

Then the poisoning happens. From the fake address, the scammer sends the target wallet a tiny transaction, typically zero-value or a dust amount. It shows up in the victim’s transaction history right beside the legitimate entries.

When the victim later wants to send funds, they scroll back, see what looks like the familiar address and copy it. If they pick the poisoned entry, the funds go straight to the attacker.

Which blockchains are at risk

Address poisoning has been reported on many blockchains, including Ethereum, BNB Smart Chain and other networks that use long hexadecimal addresses. Binance’s logic is straightforward: any chain with long addresses that are usually displayed in shortened form is exposed.

That includes most of the places where people keep tokens and in-game assets. If your wallet shows you something like “0x1a2b…9f8e” and you trust it after a quick look, this scam was designed with you in mind.

Binance’s advice

The exchange keeps its guidance brief and practical. Send only to full addresses, and only once you’ve verified them. Use address book allowlists so you pick from a saved list rather than your transaction history. And before moving any meaningful amount, send a small test transfer first.

None of these tips are new, and each one slows you down. But the attack relies entirely on people skipping those steps. Check every character of an address, not only the first four and last four, because matching those eight characters is exactly what the scammer paid a script to do.