On-chain data reveals a devastating $12.4 million Ethereum loss caused by a copy-paste error. The victim wallet 0xd674 mistakenly sent 4,556 ETH to a malicious address that mimicked Galaxy Digital's deposit address—matching both the first and last four characters.
How the Attack Worked: Poisoning 37 Hours Before the Heist
According to Lookonchain, the attacker first generated an address with identical prefix and suffix to Galaxy Digital's official address, then sent micro-ETH amounts (ranging from 0.00000001 to 0.0000005 ETH) to the victim. These tiny transactions polluted the victim's transfer history. Approximately 37 hours later, when the victim needed to send funds to Galaxy Digital, they copied the poisoned address instead. Security firm Cyvers Alerts confirmed the poisoning occurred 37 hours prior. The victim had previously transferred funds to the legitimate Galaxy Digital address, making the mistake particularly costly—4,556 ETH valued at roughly $12.4 million.
DeFi Activity Showed Sophisticated Usage
The victim wallet 0xd674 was no novice. About 17–19 hours before the incident, it executed multiple multicall transactions via Morpho's Bundler contract, paying notable gas fees for optimized DeFi interactions. It also supplied and withdrew USDC from Compound's market and converted some assets to Wrapped Bitcoin (WBTC). Analysts warn that even experienced users relying on transaction history copy-paste can fall victim to such scams. Zero-ETH and micro-ETH transfers often signal contract calls or wallet checks, not actual fund movement—yet attackers exploit this blind spot to plant deceptive addresses.

