Web3 Share Share this article Copy linkX (Twitter)LinkedInFacebookEmail Crypto user loses $50 million in 'address poiso Web3 Share Share this article Copy linkX (Twitter)LinkedInFacebookEmail Crypto user loses $50 million in 'address poiso

Crypto user loses $50 million in 'address poisoning' scam

Share
Share this article
Copy linkX (Twitter)LinkedInFacebookEmail

Crypto user loses $50 million in 'address poisoning' scam

The scammer sent a small "dust" amount to the victim's transaction history, causing the victim to copy the address and send $50M to the scammer's address.

By Francisco Rodrigues, AI Boost|Edited by Aoyon Ashraf
Dec 20, 2025, 5:43 p.m.
(brandwayart/Pixabay/Modified by CoinDesk)

What to know:

  • A crypto user lost $50 million in USDT after falling for an "address poisoning" scam, where a scammer created a wallet address that closely resembled the intended destination address.
  • The scammer sent a small "dust" amount to the victim's transaction history, causing the victim to copy the address and send $49,999,950 USDT to the scammer's address.
  • The victim has published an onchain message demanding the return of 98% of the stolen funds within 48 hours, offering a $1 million white-hat bounty, and threatening legal escalation and criminal charges if the funds are not returned.

A crypto user lost $50 million in USDT after falling for an address poisoning scam in a massive onchain exploit.

The theft, spotted by Web3 security firm Web3 Antivirus, occurred after the user sent a $50 test transaction to confirm the destination address before transferring the rest of the funds.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the The Protocol Newsletter today. See all newsletters
Sign me up
Loading...

Within minutes, a scammer created a wallet address that closely resembled the destination, matching the first and last characters, knowing most wallets abbreviate addresses and show only prefixes and suffixes.

The scammer then sent the victim a tiny “dust” amount to poison their transaction history. Seemingly believing the destination address was legitimate and properly entered, the victim copied the address from their transaction history and ended up sending $49,999,950 USDT to the scammer’s address.

These small dust transactions are often sent to addresses with large holdings, poisoning transaction histories in an attempt to catch users in copy-paste errors, such as this one. Bots conducting these transactions cast a wide net, hoping for success, which they achieved in this case.

Blockchain data shows the stolen funds were then swapped for ether ETH$2,977.17 and moved across multiple wallets. Several addresses involved have since interacted with Tornado Cash, a sanctioned crypto mixer, in a bid to obfuscate the transaction trail.

In response, the victim published an onchain message demanding the return of 98% of the stolen funds within 48 hours. The message, backed with legal threats, offered the attacker $1 million as a white-hat bounty if the assets are returned in full.

Failure to comply, the message warns, will trigger legal escalation and criminal charges.

“This is your final opportunity to resolve this matter peacefully,” the victim wrote in the message. “If you fail to comply: we will escalate the matter through legal international law enforcement channels.”

Address poisoning exploits no vulnerabilities in code or cryptography, but instead takes advantage of user habits, namely, the reliance on partial address matching and copy-pasting from transaction history.

scamSecurityOnchain Transactions
AI Disclaimer: Parts of this article were generated with the assistance from AI tools and reviewed by our editorial team to ensure accuracy and adherence to our standards. For more information, see CoinDesk's full AI Policy.

More For You

Protocol Research: GoPlus Security

Commissioned byGoPlus

What to know:

  • As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
  • GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
  • Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.
View Full Report

More For You

Real-World Asset DeFi Moves Into Sports Finance With Tokenized Football Club Revenues

A new DeFi model is providing football clubs with faster access to liquidity by converting future media and broadcasting revenues into tokenized, onchain assets.

What to know:

  • A new protocol on Chiliz channels stablecoin liquidity toward football clubs by tokenizing future revenues like media and broadcasting rights.
  • The model aims to replace costly, slow bank financing with on-chain credit backed by real-world sports assets.
  • The initiative reflects a broader shift toward using blockchain to solve practical financing challenges in traditional industries.
Read full story
Latest Crypto News

Brazil’s Gen Z drives crypto boom as stablecoins, income tokens surge

Fidelity's Jurrien Timmer: Expect lame 2026 as four-year bitcoin cycle appears intact

Bitcoin’s quantum debate is resurfacing, and markets are starting to notice

BlackRock's Bitcoin ETF a true rarity: massive inflows even with negative performance

Gold wins the debasement trade in 2025, but it is not the full story

The UK’s crypto rulebook is finally taking shape

Top Stories

Gold wins the debasement trade in 2025, but it is not the full story

The UK’s crypto rulebook is finally taking shape

BlackRock's Bitcoin ETF a true rarity: massive inflows even with negative performance

Crypto's closest ally in Congress, Sen. Lummis, is retiring next year

Bitcoin battles $89,000 price ceiling as bulls try to break U.S. sell pattern

SBF's cohorts at FTX take last SEC hit, Ellison banned from company roles for decade

Market Opportunity
Scamcoin Logo
Scamcoin Price(SCAM)
$0.000826
$0.000826$0.000826
-1.78%
USD
Scamcoin (SCAM) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.