# "address poisoning" — X 热门讨论 (2026-09-26 05:18 UTC)

## @elcord0 (eL Cord) · 09-26 04:06 · ♥54 ↻10 💬53 One of the easiest ways to lose money in crypto is also one of the easiest mistakes to make.

Address poisoning works by sending a tiny transaction from an address that looks almost identical to one you have used before. Later, you check your transaction history, copy what looks like the right address, and send the real funds to the attacker.

In January 2026, one wallet lost 4,556 ETH, worth about $12.4 million at the time, after copying a lookalike address. Bitquery also identified 1,319 victims who lost around $22.26 million to address poisoning over the 12 months it analyzed.

This is where @Americanfort_io takes a different approach.

Instead of making users depend on copying and pasting long hexadecimal addresses, Fortress lets you send crypto using a human readable FortressName.

That changes the interaction completely.

You are not trying to compare a long string of random characters and hoping you copied the correct one. You can send to a name you actually recognize.

The bigger point is that a FortressName does not publicly resolve to one permanent wallet address. That also helps reduce the amount of financial information that can be exposed through a single public address.

Crypto should not require users to play detective every time they make a payment.

@Americanfort_io makes the payment experience easier while addressing one of the risks created by copy and paste transactions. https://x.com/elcord0/status/2103697571189235742

## @refrip98 (refky.eth) · 09-26 04:32 · ♥51 ↻6 💬44 Address poisoning works because crypto trained people to trust a shortcut. Check the first and last characters, then paste.

Attackers generate look-alike addresses that match those characters. The official creator brief cites $50M lost to addresses matching just seven characters.

The vulnerability isn’t simply users being careless. It’s the copy-paste surface itself.

@Americanfort_io attacks that surface at the addressing layer.

With live Send-to-Name™, you send to a FortressName instead of a reusable hex address. The wallet generates a fresh one-time stealth address for each payment.

Only the sender and recipient can derive it, and only the recipient can spend it. Settlement still happens on the native chain.

To an outside observer, there is no public directory mapping the @ name to one permanent wallet, balance, or payment history.

A supported recipient wallet can still see that the payment came from @ you.

Private to the public. Accountable to the person you paid.

One FortressName currently works across 13 integrated networks.

SafeSend™ is a separate sender-side layer and isn’t live yet.

Claim a free FortressName here

https://t.co/FYQFImkWH2 https://x.com/refrip98/status/2103704295250301284

## @aquilaneratr (AquilaNera) · 09-25 08:00 · ♥30 ↻1 💬35 Have a great Friday morning fam, good morning for each and every one of you☀️

One thing @Americanfort_io keeps making me question is why crypto still treats copy and paste as part of the security model.

Think about the normal flow for sending funds.

You copy a long wallet address.

You paste it.

Then you look at the first few characters.

Maybe you check the last few too.

And somehow we have convinced ourselves that this is enough to protect a transaction that might be worth thousands of dollars.

That has always felt strange to me.

Because humans are simply not built to compare long hexadecimal strings.

We recognize names, words, faces and patterns much better than sequences like:

0x71A4...9F2C

And that weakness is exactly what address poisoning attacks try to exploit.

An attacker does not necessarily need to create something completely different.

They only need an address that looks familiar enough at a glance.

If the beginning looks right and the ending looks right, the middle can easily disappear from your attention.

That is why I think the interesting part of FortressName and Send to Name™ is not just that sending crypto with an @name looks cleaner.

It changes the surface where the mistake can happen.

Instead of:

copy address paste address compare characters hope you selected the right one

the idea becomes much more human:

choose the person send to their FortressName

Under the hood, the wallet can derive a fresh one time address for that payment, while the user interacts with a readable identity instead of a string they were never realistically going to verify character by character.

For me, that distinction matters.

Good crypto UX is not only about making something faster or prettier.

Sometimes better UX is security.

If a system depends on humans carefully checking tiny differences inside long random strings every single time they move money, maybe the user is not the weak point.

Maybe the interface is.

That is what makes Send to Name™ interesting to me.

It tries to remove one of the most fragile habits in crypto from the payment flow instead of simply telling users to be more careful.

I would rather verify who I am paying than pretend I verified forty characters of an address. > 引用 @Americanfort_io: The industry just spent a year adding privacy to the send button.

Good. A toggle that hides one payment is still a toggle on top of a public life.

Your ENS-style name is still a permanent map. Your reused address is still a catalog of counterparties. Your balance is still a billboard. Your AI agent is still pasting hex and hoping.

Private send hides a wallet behind a payment. A FortressName means there was never a public wallet to find.

Recipient sees who paid them. On-chain observers see a fresh address. No pool. No mixer. No viewing-key back door.

Privacy from observers. Proof between parties.

Your money. Your @name. Nobody else's business. https://x.com/aquilaneratr/status/2103394313744920636