A single copy-and-paste action was all it took for one crypto user to lose nearly $50 million in USDt. The incident, now widely cited by blockchain security analysts, underscores how even experienced users can fall victim to address poisoning — a low-tech but highly effective scam that exploits routine behavior rather than technical vulnerabilities.
According to onchain investigators, the loss occurred when the user copied a wallet address from their transaction history and unknowingly sent funds to a malicious lookalike address. The transaction was final, irreversible, and completed within minutes. No protocol was breached, no private keys were compromised, and no smart contracts failed. Instead, the attack relied entirely on subtle visual deception and human habit.
Earlier coverage: Breez Launches ‘Time2Build’ to Accelerate Real-World Bitcoin Lightning Network Integration
Understanding Address Poisoning
Address poisoning is a scam technique where attackers send small transactions from wallets that closely resemble legitimate addresses a victim frequently uses. These “poisoned” addresses are crafted to match the first and last characters of the real wallet, increasing the chance that a user will later copy the wrong address from their transaction history.
In this case, the attacker sent a small transfer to the victim’s wallet, ensuring the malicious address appeared alongside legitimate ones in recent activity. When the victim later initiated a large USDt transfer, they copied the poisoned address rather than the intended recipient.
Blockchain data shows the victim first sent a small test transaction to the correct address — a common safety practice. However, the follow-up transfer of nearly $50 million was mistakenly sent to the scam address minutes later, highlighting how quickly errors can compound once trust in a copied address is assumed.
Why Even Advanced Users Are at Risk
Security researchers noted that the malicious address was nearly indistinguishable from the legitimate one at a glance. The first few characters and the last several characters matched exactly, which is often enough for users to assume correctness when scanning quickly.
Importantly, the wallet involved was not new or dormant. It had been active for roughly two years and was primarily used for stablecoin transfers. Shortly before the incident, the funds had been withdrawn from a major centralized exchange, suggesting the wallet owner was actively managing significant balances.
This reinforces a key point frequently raised by security professionals: address poisoning does not target ignorance. It targets muscle memory. The scam succeeds because it aligns with how users naturally interact with wallets — copying past addresses, relying on visual familiarity, and assuming recent history is safe.
What Happens After the Funds Are Sent
Once the transfer was confirmed, the attacker rapidly moved the funds. Onchain tracking shows the stolen USDt was swapped into Ether and distributed across multiple wallets, a common obfuscation technique. Portions of the funds were later routed through Tornado Cash, further complicating recovery efforts.
Because blockchain transactions are final and pseudonymous, recovering funds after such an error is extremely difficult. Unlike exchange hacks, where legal or custodial intervention may be possible, address poisoning losses typically offer no recourse unless the attacker voluntarily returns funds.
A Broader Security Trend
This incident is part of a wider pattern of escalating crypto losses in 2025. Industry reports estimate that crypto-related hacks and scams have resulted in $3.4 billion in losses so far this year, marking the highest annual total since 2022.
Notably, the majority of losses have come from a small number of large incidents rather than widespread low-level attacks. Address poisoning fits within this trend: it is simple to execute, inexpensive for attackers, and capable of producing outsized gains if it succeeds once.
The appeal for attackers is clear. Address poisoning does not require exploiting software bugs, bypassing audits, or deploying complex malware. It only requires patience, precision, and the expectation that users will trust what looks familiar.
Implications for Wallet Design and User Behavior
The $50 million mistake has renewed calls for better wallet-level protections. Security experts argue that interfaces should discourage copying addresses from transaction history without additional verification, especially for large transfers. Others advocate for address whitelisting, name-based address books, and clearer visual warnings when sending funds to previously unseen recipients.
For users, the incident reinforces long-standing advice that remains inconsistently followed: always verify the full wallet address, use saved contacts where possible, and avoid relying solely on transaction history for destination addresses.
As stablecoins and onchain payments continue to scale, these human-layer risks are becoming just as important as smart contract security. The lesson from this case is not that crypto systems are broken, but that usability and safety remain deeply intertwined — and costly when overlooked.
