# "address poisoning" — X 热门讨论 (2026-09-23 13:55 UTC)
## @KeystoneWallet (Keystone Hardware Wallet) · 09-23 12:00 · ♥22 ↻3 💬2 ⚠️ In May 2024, someone lost 1155 WBTC in one of the most regrettable ways possible:
By copying an address from the transaction history.
A scammer had already slipped a look-alike address into that history. One wrong copy-paste, one confirmation, and it was over. On-chain transactions don't have an undo button.
This is called address poisoning, and it works because most people only glance at the first and last few characters before sending. That's the whole attack.
What actually keeps you safe: → Never pull an address from your transaction history. Go back to the original source every time. → Check the full address. Every character. → Keystone paired with Rabby & MetaMask will flag any new address before you sign. That warning exists for a reason.
Keystone 3 Pro shows the complete address on its air-gapped screen so you can verify exactly what you're signing before anything moves.
1155 WBTC lost over a 10-second shortcut. Learn the lesson now before it costs you. https://x.com/KeystoneWallet/status/2102729700879802495