# "address poisoning" — X 热门讨论 (2026-09-26 09:07 UTC)
## @IViktohh (Viktohh🔮 🕹️) · 09-26 07:59 · ♥39 ↻0 💬43 december 2025, a trader lost $50m in USDT to address poisoning.
sent a test transaction first like you're supposed to. an attacker saw it, generated a lookalike address matching the first and last characters, and planted it in the tx history. 26 minutes later the trader copied that poisoned address and sent 49,999,950 USDT straight to it.
a USENIX study tracked 270m poisoning attempts across Ethereum and BNB Chain, hitting 17m wallets, $83.8m in confirmed losses. and that's only what got reported.
it works because long addresses aren't really verifiable by eye, most wallets hide the middle behind "...".
@Americanfort_io Send-to-Name skips that entirely. you send to a name and the wallet generates a fresh one-time address per payment that only sender and recipient can derive.
no copy-paste step means no window for a lookalike address to slip in. https://x.com/IViktohh/status/2103756262781374785
## @Realboybr (Realboy) · 09-26 06:58 · ♥35 ↻0 💬45 Address poisoning is still one of the cleanest attacks in crypto because it exploits something people do automatically.
Copy an address. Glance at the first and last few characters. Assume it matches. Send.
A look-alike address with seven matching characters has drained large sums from people who checked carefully. The attack works because the copy-paste step exists at all.
@Americanfort_io removes that step. Send-to-Name means you’re paying @name, not matching hex. The wallet computes a fresh one-time stealth address for each payment only sender and recipient can derive it, only recipient can spend from it. Nothing about the FortressName publicly resolves to a fixed wallet, balance, or payment history.
One name across 13 integrated networks. The name is readable. The money trail doesn’t accumulate the way a static address does when reused across dozens of payments.
SafeSend is still in development that’s the sender-side shielding with ZK proofs and selective disclosure of source of funds. What’s live today is already a fundamentally better payment flow than the one most people haven’t questioned yet. https://x.com/Realboybr/status/2103740945761997013
## @Aliba_79 (Aliba) · 09-26 08:43 · ♥28 ↻2 💬29 I used to think crypto privacy meant a mixer . That was the wrong problem
The real leak is the public wallet Anyone with the address can read the balance , counterparties , and spending rhythm ENS makes sending easier , but an name still points to one reused wallet Nicer label . Same open ledger
That’s why @Americanfort_io is more interesting than another privacy layer incoming thread
What’s actually usable today is FortressName + Send-to-Name You claim an name . The sender types the name instead of pasting hex The wallet computes a one-time stealth address for that sender–recipient pair Only those two can derive it Funds still settle on the native chain No pool . No tumble . No mixer
Outsiders see a fresh receiving address They don’t get a public directory that says name = this wallet = this entire on-chain life
The usual pushback : doesn’t that become a laundering tool ? They split two things people keep mixing up Private from the crowd . Still provable when it matters A compatible receiving wallet still knows who paid SafeSend is the sender-side ZK layer with selective disclosure , in development , not fully live Don’t sell it as shipped.
Quick map : FortressName = pay and get paid by name Send-to-Name = fresh stealth address per send SafeSend = sender-side ZK ( roadmap )
Crypto already won self-custody . It’s losing the use money without becoming a target fight . Address poisoning , salary doxxing , an agent pasting the wrong 0x…30f same disease Static addresses are too easy to hunt
What scares you more when you get paid in USDC on-chain ?
A. People can Google your salary B. Poisoned / mistyped address C. An exchange can’t tell a later wallet is still you
Reply A, B, or C https://t.co/pbdABG2tjt > 引用 @Aliba_79: I used to think crypto privacy was only for people with something to hide
Then I noticed the contradiction . We redact bank statements . We paste wallet addresses into bios , invoices , and group chats Anyone can look up a balance , a history , and every counterparty . Not because we want to flex Because public chains work that way , and the UX still asks us to copy a hex string and hope we didn’t get poisoned
That’s when @Americanfort_io became more than another privacy by default line
FortressName is not a nickname for your wallet Most readable names still resolve to one fixed address Easier than hex Same open window into the wallet FortressName splits the layers : the @-name is what you share Underneath , it is not supposed to be one permanent public wallet glued to that name
Send-to-Name is the layer that is actually usable now . You type an @-name The wallet computes a one-time address for that sender–recipient pair On-chain observers see a fresh address A compatible recipient wallet can still show who paid No pool . No mixer Phishing and address poisoning live on a simple fact : people reuse addresses and trust the clipboard Remove the hex-paste step and half those attacks lose their favorite door
SafeSend is the part campaigns usually get wrong It is not a cute hide button The design is a ZK layer on the transaction itself : less public exposure of balances and source of funds , without pooling money , without a viewing-key back door You choose what to disclose , to whom , and when Their site frames it as a one-toggle Untraceable Quantum Send Credit where it’s due : this layer is still being built , and the wallet is in beta Don’t write it as if every chain already has the switch on
Three layers , three different holes A public name without one-time addresses becomes a map of the wallet One-time addresses without a sender-side layer still leak the tap Hide everything with no selective disclosure and counterparties can’t verify anything That’s the bind the industry keeps hitting
I’m not selling a finished product . macOS beta . SafeSend is roadmap Quantum-resistant work is research , not a spell The product question is still the right one : sending money should feel like sending money , not like publishing a financial map
Which one are you actually willing to live with ?
A. Public @-name , wallet not on display B. Hide everything , even from the counterparty C. Public chain , accept being watched
Reply with a letter . Mechanism : https://t.co/expH2a0YjX
claim a name : https://t.co/pbdABG1VtV https://x.com/Aliba_79/status/2103767481299124629