← All articles
SCREENING · 4 MIN

Sibling and shadow addresses in address-poisoning scams

One of the most effective scams doesn’t hack anything — it just tricks you into copying the wrong address.

How the scam works

Address poisoning exploits a simple habit: people copy a recipient address from their transaction history instead of re-checking it in full. The attacker sends you a tiny (often zero-value) transfer from an address engineered to look like one you use — matching first and last characters — so it appears in your history.

Later, when you copy “your” address from history, you copy the attacker’s look-alike, and your next payment goes to them.

Why it defeats a quick glance

Wallets abbreviate addresses as 0xAB12…9F4C. The look-alike is built to match exactly those visible characters. The middle — which nobody reads — is completely different. A five-second visual check passes.

How to defend against it

Never copy an address from transaction history. Copy it from the source (the invoice, the exchange, the counterparty’s verified channel) every time, and verify the full string or a large middle segment.

Recupero flags spoofed look-alike addresses and airdrop-spam so a trace never follows a decoy, and Wallet Guard screens a recipient before you send — the same protection, applied at the moment it matters.

Protect your wallet with Recupero

Screen an address before you send, or trace stolen funds to a freeze target.