A crypto user lost about 100,000 USDT after sending funds to a fraudulent wallet address that had been inserted into the victim’s transaction history weeks earlier, according to blockchain security firm Cyvers.
Cyvers said the malicious address was planted 66 days before the transfer and was later selected from the wallet history instead of the intended destination. The firm described the incident as an address poisoning attack, a form of social engineering rather than a failure in Tether, Ethereum, or wallet software.
How the transfer was redirected
Cyvers said the attacker first interacted with the victim’s wallet roughly 66 days before the theft, creating a transaction record that displayed a wallet address resembling one the victim had previously used. The fake entry then remained in the account’s history until the victim later prepared a 100,000 USDT payment.
When the transfer was made, the victim appears to have relied on that historical record without comparing the entire destination string. As a result, the funds were sent to the attacker’s lookalike address rather than to the intended recipient.
Why address poisoning works
Address poisoning attacks do not require private keys or direct access to a wallet. Instead, they exploit how wallet interfaces and blockchain explorers often shorten addresses in transaction lists, showing only the beginning and end of a long string.
Attackers generate addresses that match the visible characters of a legitimate destination and then use small transfers to place those addresses into a target’s recent activity. If a user later copies or selects the shortened entry without checking every character, the forged address can appear authentic enough to cause a costly mistake.
Funds were moved into Ethereum
After receiving the USDT, the attacker converted the stolen tokens into about 52.8 ETH, Cyvers said. The receiving wallet was reported to be holding that amount after the swap.
The move may have been intended to lower the chance of a freeze. USDT has an issuer that can block assets in some cases, while ETH does not have an equivalent issuer-controlled freezing function. No recovery action or return of funds was reported in this case.
Part of a wider scam pattern
The incident adds to a longer list of losses tied to poisoned wallet histories. The source article noted larger examples using the same method, including a December 2025 case in which stolen funds were also converted to ETH and then distributed across multiple wallets.
Earlier cases have reportedly led to losses in the tens of millions of dollars. The method is helped by low transaction costs and by the common practice of displaying only partial address strings, making impersonating addresses easier to pass off as genuine in recent activity logs.
What comes next and what users can verify
The source article said there was no evidence that the mistaken transfer stemmed from a technical flaw in Tether, Ethereum, or the wallet itself. Instead, the confirmed issue was the forged address record and the victim’s apparent reliance on a shortened history entry.
The article also pointed to the next practical safeguards users can take: compare full wallet addresses, verify payment details through a separate communication channel for large transfers, and consider sending a small test amount first. Some wallets and explorers now filter suspicious entries, but the level of protection still depends on the platform.
Source: crypto.news