# "address poisoning" — X 热门讨论 (2026-09-25 09:38 UTC)

## @Victor_Obinna1 (Deluffy 🎮) · 09-25 08:31 · ♥39 ↻0 💬46 Address poisoning works because it targets something embarrassingly human:

we trust patterns faster than we verify them.

A scammer does not need to break your wallet. They only need to make the wrong address look familiar enough.

That is why this attack is so effective.

A bot watches active wallets, creates a lookalike address with matching first and last characters, then sends a tiny transaction so the fake address appears in your recent history.

Later, you copy what looks familiar, glance at a few characters, and send.

That is the trap.

What I find interesting about @Americanfort_io is that Send-to-Name™ attacks the behavior the scam depends on.

Instead of copying a long hex address, you send to a readable handle.

Behind the scenes, the wallet can generate a fresh one-time stealth address for the payment.

So the flow changes from:

find address → copy → compare characters → send

to:

choose name → send

That removes a big part of the attack surface created by address reuse and transaction history poisoning.

The broader point is simple:

security is not always about making users more careful.

Sometimes the better design is removing the dangerous step entirely.

That is the direction I like here. https://x.com/Victor_Obinna1/status/2103402018568069283

## @Wilsonpablo108 (Wilson) · 09-25 08:14 · ♥36 ↻0 💬47 $50M lost because people copied the wrong wallet address.

That’s the scary part about address poisoning. An attacker creates a lookalike address that starts and ends with characters similar to the one you normally use. You copy the wrong address without noticing, send the funds, and there’s usually no way to get them back.

The problem is that long wallet addresses are difficult to check properly every single time. Most people look at the first few characters, maybe the last few, and move on. That small habit can be enough for an attacker to trick you.

With Send to Name from @Americanfort_io , you can send to a FortressName instead of copying a long wallet address. The wallet creates a fresh one time address for that payment, while the transaction still settles on the native blockchain.

There is no permanent public wallet address attached to the name for someone to monitor or copy.

One FortressName already works across 13 integrated networks.

I like the idea because it removes one of the easiest mistakes people make when sending crypto. You don’t have to rely on checking a long string of characters perfectly every time.

Sometimes better security is simply removing the thing people keep getting wrong. @Americanfort_io https://x.com/Wilsonpablo108/status/2103397596702101880

## @zkxwallet (ZKX Wallet | The Secure and Private Wallet 🗽) · 09-25 07:00 · ♥21 ↻2 💬0 FIELD MANUAL #3: VERIFY THE FULL ADDRESS, EVERY TIME. Counters: address poisoning. 🛡️

Never copy an address from your own transaction history to reuse it —

Always pull it fresh from a source you actually trust: the recipient telling you directly, a verified contract listing, or a QR code you scan yourself. ⚠️

When you do check an address, read the full string, not just the first and last few characters; that's specifically the part poisoning attacks are designed to exploit. ✅

It takes ten extra seconds and closes off one of the sneakiest exploits from earlier this month. https://x.com/zkxwallet/status/2103378978371207420