Cyvers Alert has flagged a fresh address poisoning attack that drained roughly $100,000 in USDT from a victim's wallet.
According to the monitoring data, the attacker seeded the victim's wallet with a poisoned address about 66 days ago — sending a transaction that planted a lookalike address in the victim's interaction history. The trick exploits a habit many users have: copying previously used addresses from transaction logs instead of verifying the full string each time.
The victim made the transfer today without fully checking the wallet address, sending the funds straight to the attacker. After the theft, the attacker moved quickly to convert the stolen USDT into ETH, likely to dodge potential freezing by issuers or exchanges. The wallet now holds approximately 52.8 ETH.
Cyvers warns users to always verify the complete wallet address before any on-chain transfer, and not to rely on address records shown in transaction history. Security firms also recommend AI-based on-chain security tools that can flag anomalous transactions in real time, reducing exposure to address poisoning and phishing schemes.
Address poisoning has become one of the more common scams in crypto in recent years. Attackers typically rely on users' habit of copying addresses from past transactions, planting fake but visually similar addresses to trick them into sending assets to the wrong destination.

