Understanding & Preventing Address Poisoning Attacks
Address poisoning is one of the most stealthy and damaging attack vectors in decentralized finance. Learn how attackers generate lookalike addresses to hijack your clipboard, and how XMRScan's automatic filtering keeps your transactions clean.
How the Attack Works (Step-by-Step)
Vanity Address Generation
The scammer uses GPU vanity tools (e.g. monero-vanity) to generate a 95-character address with the same initial and trailing characters as your Monero wallet or regular counterparty.
Dust Infiltration
The attacker broadcasts an unsolicited micro-nanonero dust output directly to your stealth keys. This pollutes your incoming transaction ledger with the lookalike spoof address!
Clipboard Hijack
When you later copy a recent address from your transaction history to send tokens, you verify only the first and last few characters, inadvertently pasting the scammer's lookalike address.
XMRScanner 3-Tier Anti-Poisoning Architecture
Automatic, real-time protection enabled on every address page
Calculates 8-character (prefix + suffix) entropy overlaps to instantly identify lookalikes.
Hides zero-value transfers and unsolicited micro-dust from your primary transaction list by default.
Triggers an explicit security confirmation warning before copying any address flagged as suspicious.
How to Keep Your Funds Safe (Best Practices)
-
✓
Never copy addresses from transaction history: Use OpenAlias (e.g. donate.getmonero.org), address books, or QR codes instead of copy-pasting from recent transfers.
-
✓
Verify middle characters: Always verify characters in the middle of the address, not just the first 4 and last 4 characters.
-
✓
Whitelist contacts in your wallet: Use hardware wallet address books (e.g. Ledger, Trezor) or wallet contact lists to ensure accurate destinations.
-
✓
Keep XMRScanner protection active: Leave the "Poisoning & Dust Protection" filter turned ON when inspecting your wallet.