A single address poisoning operator stole a combined $9.4 million from 15 victims on the Tron network over the past four weeks, according to the source report. The two largest losses were $2.5 million each, and the stolen assets were later swapped into USDD and routed to one main wallet.

The case has renewed attention on a scam method that exploits how wallet interfaces display blockchain addresses. While some major wallet providers have added defenses against this tactic, the protections highlighted in the report do not currently cover Tron.

How the scam works

Address poisoning starts with an attacker sending very small amounts of crypto from a fake address designed to resemble one a victim has used before. These so-called dust transactions are meant to place the lookalike address into a user’s transaction history.

The risk arises when a user later copies that address from recent activity and sends funds to it, believing it belongs to a legitimate contact or destination. Because wallet apps often display only the first and last characters of a long address string, users may rely on those visible fragments rather than checking the full address.

Losses traced to one operator

The report attributes the recent Tron thefts to a single scammer who drained 15 users in roughly a month. Total losses reached $9.4 million, with the two biggest victims each losing $2.5 million.

After the thefts, the funds were converted into USDD, a stablecoin on Tron, and then moved into one consolidation wallet. The report did not suggest that current wallet protections on Tron stopped the activity.

Wallet defenses exist, but not for Tron

MetaMask, owned by Consensys, has introduced a warning system for address poisoning, but the feature works mainly on EVM-compatible chains. According to the report, MetaMask flags cases where the first and last four characters of an address match a previous recipient while the middle characters differ.

Trust Wallet has also rolled out what it calls Address Poisoning Protection. Launched in March, the feature checks addresses against a database of known scam addresses and, when a match is found, presents a side-by-side comparison for the user.

Trust Wallet says it has identified more than 225 million poisoning attempts and that more than $500 million has been confirmed stolen, a rate the report equates to roughly 34,000 attacks per hour. Those protections, however, were described as not working on Tron.

What remains the practical safeguard

Until wallet security tools are implemented across more blockchains, Tron users who self-custody assets remain exposed to this type of attack if they rely on transaction history alone. The practical defense described in the report is to verify every character of a destination address before sending funds.

The source also points to two additional precautions: saving trusted recipient addresses in a wallet address book instead of copying them from recent transfers, and using a small test transaction before moving larger sums. For now, broader wallet-side protection on Tron appears to be the next missing step.

Source: Cryptopolitan