Address poisoning & dust
You send to the same exchange address every month. One day you open your history, copy “the address you used last time”, and paste it. It was the attacker’s.
How address poisoning works
- An attacker watches the blockchain and sees you send to an address.
- They generate a lookalike that shares its first and last few characters. Address grinders like Profanity can do this in minutes.
- They send you a tiny or zero-value transfer from the lookalike, so it appears in your history right next to the real one.
- Later, you copy from history and pick the wrong line.
Nothing is stolen until you send. The whole attack depends on copying from history and checking only the ends.
What “dust” is
Dust is a very small amount of crypto, or an unrequested token, that shows up in your wallet. It’s how poisoning transfers arrive, and dust is also used to:
- Lure you to a scam site. Token names like “Visit site-name to claim” are advertising a phishing site. Don’t visit it, and don’t try to sell or “claim” unknown tokens there.
- Track you. On Bitcoin, spending dust together with your other coins can link your addresses.
KeepKey Desktop filters these out of your token list: tokens it doesn’t recognize from its known-token catalog, and tokens with no value, are tucked behind a Show filtered tokens toggle. You can’t stop anyone from sending to your address, but you don’t have to touch what they send.
How to avoid it
- Never copy a recipient from your transaction history. Copy from the source (the exchange’s deposit page, the receiver’s own device) or pick from your Address Book.
- Save addresses you reuse, with a clear label, after one careful full-line check. At send time, the label confirms you picked the right entry.
- Read the whole address on the KeepKey screen, the middle included, before you approve.
- Ignore unknown tokens and airdrops. Leave them where they are.
Related
- Clipboard swapping — the same lookalike trick, delivered through your clipboard.
- Staying Safe
Last updated on