Requires from youNothing. The dust arrives unsolicited
ExploitsCopying an address out of your own transaction history
DefenceAddress book entries, full-string verification, test transfers
FBT Swap
What you should know
Address poisoning requires no permission, no signature and no interaction from you. The attacker simply sends something to your address from a lookalike, and waits for you to copy the wrong entry out of your own history.
It works because almost everyone verifies addresses by checking the first and last few characters, and vanity-generation makes matching those trivially cheap.
How the lookalike is made
Generating keys until the address starts and ends with chosen characters takes minutes on ordinary hardware. The middle is different, but almost nobody reads the middle.
The attacker then sends a tiny amount, a worthless token, or a zero-value transfer that still appears in your history. Some wallets display these indistinguishably from your real transactions.
The moment it pays off
Weeks later you send to that destination again and copy the address from your recent activity rather than from the original source. The first six and last four characters match, so it looks right.
The transfer is valid, irreversible and goes to the attacker. There is no contract involved and nothing for a security tool to flag.
Defending against it
Never copy an address from transaction history. Use a saved address book entry you created deliberately, or re-obtain the address from its original source each time.
When you do verify, check characters from the middle as well as the ends. And for any first transfer to a new destination, send a small test amount and confirm receipt before the real one.
Why wallets struggle to stop it
The dust transfer is a valid transaction to your address. A wallet can hide zero-value transfers and flag unknown senders, and good ones increasingly do, but it cannot refuse to display your own history.
This is a human-interface attack rather than a cryptographic one, which is why the countermeasure is a habit rather than a setting.
At a glance
At a glance
01
Requires from you
Nothing. The dust arrives unsolicited
02
Exploits
Copying an address out of your own transaction history
03
Defence
Address book entries, full-string verification, test transfers
04
Reversibility
None. It is an ordinary valid transfer to the wrong place
FAQ
Frequently asked questions
Clear answers before you decide.
Is receiving dust dangerous by itself?+
No. Receiving a token cannot compromise a wallet. The danger is entirely in what you do afterwards — copying the sender's address, or interacting with a token contract the dust points you toward.
Should I send the dust back?+
No. It costs gas, confirms your address is active, and interacting with an unknown token contract can expose you to further tricks. Ignore and hide it.
Do address books fully solve this?+
They solve the copy-from-history problem, which is the main one. You still need to verify the address correctly the first time you save it.
Risk notice
Crypto assets are volatile and on-chain transactions cannot be reversed. You can lose money, including all of it. Nothing here is financial advice.