How the scam works
Address poisoning exploits a simple habit: people copy a recipient address from their transaction history instead of re-checking it in full. The attacker sends you a tiny (often zero-value) transfer from an address engineered to look like one you use — matching first and last characters — so it appears in your history.
Later, when you copy “your” address from history, you copy the attacker’s look-alike, and your next payment goes to them.
Why it defeats a quick glance
Wallets abbreviate addresses as 0xAB12…9F4C. The look-alike is built to match exactly those visible characters. The middle — which nobody reads — is completely different. A five-second visual check passes.
How to defend against it
Never copy an address from transaction history. Copy it from the source (the invoice, the exchange, the counterparty’s verified channel) every time, and verify the full string or a large middle segment.
Recupero flags spoofed look-alike addresses and airdrop-spam so a trace never follows a decoy, and Wallet Guard screens a recipient before you send — the same protection, applied at the moment it matters.