نسخهٔ فارسی

Transparent, non-custodial, yours

Why your transaction history is an attack surface

An attacker sends a dust transfer from an address resembling one you use, so it appears in your history. Later you copy theirs by mistake.

Requires from you Nothing. The dust arrives unsolicited
Exploits Copying an address out of your own transaction history
Defence Address book entries, full-string verification, test transfers

FBT Swap

What you should know

Address poisoning requires no permission, no signature and no interaction from you. The attacker simply sends something to your address from a lookalike, and waits for you to copy the wrong entry out of your own history.

It works because almost everyone verifies addresses by checking the first and last few characters, and vanity-generation makes matching those trivially cheap.

How the lookalike is made

Generating keys until the address starts and ends with chosen characters takes minutes on ordinary hardware. The middle is different, but almost nobody reads the middle.

The attacker then sends a tiny amount, a worthless token, or a zero-value transfer that still appears in your history. Some wallets display these indistinguishably from your real transactions.

The moment it pays off

Weeks later you send to that destination again and copy the address from your recent activity rather than from the original source. The first six and last four characters match, so it looks right.

The transfer is valid, irreversible and goes to the attacker. There is no contract involved and nothing for a security tool to flag.

Defending against it

Never copy an address from transaction history. Use a saved address book entry you created deliberately, or re-obtain the address from its original source each time.

When you do verify, check characters from the middle as well as the ends. And for any first transfer to a new destination, send a small test amount and confirm receipt before the real one.

Why wallets struggle to stop it

The dust transfer is a valid transaction to your address. A wallet can hide zero-value transfers and flag unknown senders, and good ones increasingly do, but it cannot refuse to display your own history.

This is a human-interface attack rather than a cryptographic one, which is why the countermeasure is a habit rather than a setting.

At a glance

At a glance

Requires from you

Nothing. The dust arrives unsolicited

Exploits

Copying an address out of your own transaction history

Defence

Address book entries, full-string verification, test transfers

Reversibility

None. It is an ordinary valid transfer to the wrong place

FAQ

Frequently asked questions

Clear answers before you decide.

Is receiving dust dangerous by itself?

No. Receiving a token cannot compromise a wallet. The danger is entirely in what you do afterwards — copying the sender's address, or interacting with a token contract the dust points you toward.

Should I send the dust back?

No. It costs gas, confirms your address is active, and interacting with an unknown token contract can expose you to further tricks. Ignore and hide it.

Do address books fully solve this?

They solve the copy-from-history problem, which is the main one. You still need to verify the address correctly the first time you save it.

Risk notice

Crypto assets are volatile and on-chain transactions cannot be reversed. You can lose money, including all of it. Nothing here is financial advice.