The attack costs the attacker almost nothing. They generate an address whose beginning and end match an address you have used, send you a tiny amount from it, and wait. Weeks later you copy an address out of your own history, check the first four and last four characters as everyone does, and send to them.
What the wallet does
Smartable marks lookalike and poisoning-pattern addresses in your history and warns before a send to one. The warning is the cheap part; the habit is what saves you.
What to do
- Never copy a recipient out of transaction history. History records who sent to you, and anybody can send to you.
- Keep recipients in the address book. Save an address once, from a source you trust, and pick it by name after that.
- Check the whole address, not its ends — or check the middle, which is the part these attacks do not match.
- Send a test amount when the sum is large and the recipient is new.
Dust you did not ask for is not a gift and does not need to be moved. Leave it where it is.
Related
Still stuck?
The address in our Privacy Policy reaches a person — use it for privacy requests, security reports and anything this page could not answer.
One rule
Support will never ask for your recovery phrase, private key or password, and never messages you first. Anyone who does is not us — whatever address, avatar or logo they use.