Two routine copy-and-paste actions erased $62 million in crypto over December 2025 and January 2026, exposing how basic wallet habits are becoming one of Ethereum's biggest security risks.
Two Victims, $62M Gone
ScamSniffer said in a post on X on Feb. 8 that one victim lost about $50 million in December 2025 after sending funds to a fake address copied from transaction history. In January 2026, another user lost roughly $12.25 million (about 4,556 ETH at the time) through the same mistake. “Two victims. $62M gone,” the firm wrote.
Both incidents followed the same pattern: attackers planted look-alike addresses inside the victims' recent activity records, and the victims copied those instead of verified strings.
How Address Poisoning Became Cheap to Deploy
Address poisoning exploits how most users interact with wallets. Attackers monitor transactions, generate vanity addresses resembling real ones, and send tiny “dust” transfers to targets. These near-zero transactions place fake addresses into transaction histories. Later, when users copy from past activity instead of verifying the full string, money goes to scammers.
Security firms say this tactic expanded rapidly after Ethereum's Fusaka upgrade in late 2025 lowered transaction fees. What was once expensive to run at scale has become cheap. Blockchain security researchers report millions of dust transactions are now sent daily, many designed only to prepare future thefts. This activity also distorts network data — rising transaction counts and active wallet numbers increasingly include spam.
Several investigations have linked address poisoning campaigns to organized groups that recycle infrastructure across thousands of wallets.
Signature Phishing Surge Adds Pressure
Alongside address poisoning, ScamSniffer recorded a sharp rise in signature-based phishing in January: $6.27 million lost across 4,741 victims, up 207% from December in value terms. Two wallets caused about 65% of the total damage. The biggest cases included $3.02 million stolen from SLVon and XAUt tokens via malicious permit and increaseAllowance approvals, and $1.08 million taken from aEthLBTC using similar techniques.
These attacks rely on deceptive prompts that appear routine. Once users sign, scammers gain long-term token access and can drain funds without further approval. Security analysts say these schemes succeed because they target habits formed during everyday trading, not technical weaknesses.
“Most victims are not careless,” one researcher said privately. “They are doing what they’ve done hundreds of times before.”
ScamSniffer and other firms urge users to avoid copying addresses from transaction history, verify full wallet strings manually, and use saved contacts for frequent transfers. With transaction costs staying low and automation improving, analysts expect address poisoning and signature phishing to remain persistent threats until better tools and habits take hold.

