⌘K
🛡️ On-Chain Phishing Security Guide

Understanding & Preventing Address Poisoning Attacks

Address poisoning is one of the most stealthy attack vectors in Web3. Learn how attackers generate lookalike 64-hex addresses and typosquatted 0x... accounts to hijack your clipboard, and how PolygonScanner's automatic filtering keeps your account safe.

How the Attack Works (Step-by-Step)

1

Typosquatting & Vanity Spoofing

The scammer registers a deceptive lookalike account (e.g. al1ce.polygon instead of alice.polygon) or synthesizes a 64-hex implicit address matching your leading and trailing characters.

Real: alice.polygon (or 98f4...e10a)
Fake: al1ce.polygon (or 98f4...e10a)
2

Dust Infiltration

The attacker broadcasts an unsolicited micro-dust transfer (0.00001 POL) with a phishing memo. This pollutes your incoming transaction feed with the lookalike spoof account!

Transfer(al1ce.polygon -> you.polygon, 0.00001 POL)
3

Clipboard Hijack

When you later copy a recent account from your transaction history to send tokens, you glance quickly and paste the scammer's spoofed account.

⚠️ Funds irreversibly sent to scammer!
🛡️

PolygonScanner 3-Tier Anti-Poisoning Architecture

Automatic, real-time protection enabled on every account page

1. Typosquatting Radar

Calculates Levenshtein distance against known POL entities and verified ecosystem accounts.

2. Automatic Dust Isolation

Filters unsolicited micro-dust transfers (< 0.001 POL) and phishing memos from your primary view.

3. Clipboard Copy-Guard

Triggers an explicit security confirmation dialog before copying any address flagged as suspicious.

How to Keep Your Funds Safe (Best Practices)

POL
$5.45 0.00005 POL