Understanding & Preventing Address Poisoning Attacks
Address poisoning is one of the most stealthy attack vectors in Web3. Learn how attackers generate lookalike 64-hex addresses and typosquatted 0x... accounts to hijack your clipboard, and how PolygonScanner's automatic filtering keeps your account safe.
How the Attack Works (Step-by-Step)
Typosquatting & Vanity Spoofing
The scammer registers a deceptive lookalike account (e.g. al1ce.polygon instead of alice.polygon) or synthesizes a 64-hex implicit address matching your leading and trailing characters.
Dust Infiltration
The attacker broadcasts an unsolicited micro-dust transfer (0.00001 POL) with a phishing memo. This pollutes your incoming transaction feed with the lookalike spoof account!
Clipboard Hijack
When you later copy a recent account from your transaction history to send tokens, you glance quickly and paste the scammer's spoofed account.
PolygonScanner 3-Tier Anti-Poisoning Architecture
Automatic, real-time protection enabled on every account page
Calculates Levenshtein distance against known POL entities and verified ecosystem accounts.
Filters unsolicited micro-dust transfers (< 0.001 POL) and phishing memos from your primary view.
Triggers an explicit security confirmation dialog before copying any address flagged as suspicious.
How to Keep Your Funds Safe (Best Practices)
-
✓
Use verified Named Accounts (0x...): Human-readable accounts (e.g. alice.polygon) eliminate 64-hex clipboard errors.
-
✓
Never copy addresses from random incoming transfers: Always obtain the account ID directly from your intended recipient.
-
✓
Save contacts in PolygonScanner Watchlist: Star your favorite accounts and hardware vaults to transfer with 1-click confidence.
-
✓
Inspect contract verification on PolygonScanner: Verify Wasm bytecode and access keys before interacting with new DApps.