Crypto wallet scams accelerated in January. Blockchain security firm Scam Sniffer said address poisoning and signature phishing were the main attack vectors behind losses that reached tens of millions of dollars during the month. Attackers took advantage of lower transaction costs and routine user mistakes to scale these schemes.
A single address poisoning case wiped out $12.2 million
One of the clearest examples involved a victim who lost $12.2 million after copying a malicious wallet address from transaction history. The case came after a similar address poisoning incident in December that led to roughly $50 million in losses.
Scam Sniffer said address poisoning remains a dependable way to drain large amounts from crypto wallets. Attackers create wallet addresses that match the first and last characters of a trusted address while changing the middle section, making the fake version easy to miss during a quick check.
Signature phishing losses hit $6.27 million
Signature phishing also jumped in January. Scam Sniffer estimated that 4,741 victims lost a combined $6.27 million through malicious signature requests, a 207% increase from December. Just two wallets accounted for 65% of all signature phishing losses recorded during the month.
This method works differently from address poisoning. Instead of tricking users into copying a wrong destination, it pushes them to sign harmful blockchain actions, including unlimited token approvals or fund transfer authorizations they may not fully understand.
Lower transaction costs may have made campaigns cheaper to run
Analysts said the recent increase in attacks may be partly connected to Ethereum’s Fusaka upgrade, introduced in December. By cutting transaction costs, the upgrade made it cheaper to send large volumes of dust transactions, reducing the cost of running address poisoning campaigns at scale.
Security firms continue to urge users to verify wallet addresses carefully, avoid copying addresses directly from transaction records, and inspect every signature request before approving it. January’s figures show these two attack patterns are still active.

