Security and scams

What is address poisoning?

Address poisoning is a scam in which an attacker sends you a tiny amount, or a fake token transfer, from an address that starts and ends like one you use. The hope is that you will later copy it from your history and send funds to it.

Why it matters

Most people check only the first and last few characters of an address. Attackers generate addresses that match exactly those characters, so the poisoned entry looks right at a glance.

How Locker Protocol Wallet handles it

When you send, Locker Protocol Wallet compares the recipient with the addresses you have used and warns you if it looks like one of them but differs, asking you to check every character. The Vault shows the full recipient again before you sign.

Get the extension

Questions

Has my wallet been hacked if I receive a poisoned transfer?

No. Receiving it does no harm. The danger is only in copying that address later: ignore it, or hide the fake token.

How do I protect myself from address poisoning?

Keep the addresses you use in your contacts, never copy a recipient from your transaction history, and compare the full address on the signing device.