# "address poisoning" — X 热门讨论 (2026-09-26 17:55 UTC)

## @NekiWeb3 (Neki) · 09-26 16:20 · ♥25 ↻0 💬22 the weird thing about crypto payments is that we somehow made "check the first 4 and last 4 characters" feel like normal UX

that is not really verification

it is asking a human to visually inspect a machine identifier and hope nothing went wrong

address poisoning works because attackers only need to make the address look familiar enough for that habit to fail

what @Americanfort_io is doing with Send-to-Name™ changes the interaction itself

you send to something you can actually recognize, like @name

the wallet handles the address derivation underneath and creates a fresh one-time receiving address for that payment

so the user is no longer responsible for copying, comparing and validating long strings every time money moves

and the name does not need to become a permanent public pointer to one wallet either

that is the part I find more important than making addresses "easier to read"

good payment UX should remove the dangerous step, not simply make people better at performing it

claim a free FortressName ↓ https://t.co/jjGOdK5FJB https://x.com/NekiWeb3/status/2103882438850265590

## @osint_based (VAL) · 09-26 14:08 · ♥21 ↻3 💬1 $67,588 USDT lost due to an address poisoning attack

Victim thought he was sending to his usual address, but this time looks like the address was taken from transaction history

2 days earlier there was a $567,000 transfer to the usual address, so we can say he is lucky that it wasn't that amount

Attacker already converted everything to $ETH and funding wallet shows he had several victims over the last year

Fake address: 0xca166632D25Ea74BAa93A5303Aa73F61E80fD94b Real address: 0xca16B299700674dda6941BAA1BDEEFf6d90fD94b https://x.com/osint_based/status/2103849235477156086