🛡️ On-Chain Phishing Security Guide

Understanding & Preventing Address Poisoning Attacks

Address poisoning is one of the most stealthy and damaging attack vectors in decentralized finance. Learn how attackers generate lookalike addresses to hijack your clipboard, and how XMRScan's automatic filtering keeps your transactions clean.

How the Attack Works (Step-by-Step)

1

Vanity Address Generation

The scammer uses GPU vanity tools (e.g. monero-vanity) to generate a 95-character address with the same initial and trailing characters as your Monero wallet or regular counterparty.

Real: 888tNkZrPN...5CPgC9
Fake: 888tNk77b1...5CPgC9
2

Dust Infiltration

The attacker broadcasts an unsolicited micro-nanonero dust output directly to your stealth keys. This pollutes your incoming transaction ledger with the lookalike spoof address!

dust_output(888tNk... -> 888tNk..., 0.000001 XMR)
3

Clipboard Hijack

When you later copy a recent address from your transaction history to send tokens, you verify only the first and last few characters, inadvertently pasting the scammer's lookalike address.

⚠️ Funds irreversibly sent to scammer!
🛡️

XMRScanner 3-Tier Anti-Poisoning Architecture

Automatic, real-time protection enabled on every address page

1. Vanity Matcher

Calculates 8-character (prefix + suffix) entropy overlaps to instantly identify lookalikes.

2. Automatic Dust Isolation

Hides zero-value transfers and unsolicited micro-dust from your primary transaction list by default.

3. Clipboard Copy-Guard

Triggers an explicit security confirmation warning before copying any address flagged as suspicious.

How to Keep Your Funds Safe (Best Practices)

Monero
$172.50 0.00005 XMR