Address poisoning
A fraud technique in which an attacker creates a lookalike address, typically matching the first and last characters of an address the victim has previously used, and attempts to make it appear in the victim's transaction history. Attackers can generate such addresses using vanity-address techniques, repeatedly searching candidate keys until an address with the desired pattern is found. The attacker then introduces the address into the victim's history through small transfers, counterfeit tokens or, on some token contracts, zero-value transferFrom calls that appear to show a transfer from the victim to the attacker's address. The aim is to trick the victim into copying the lookalike address for a future payment.
These transfers do not, by themselves, demonstrate any interaction between the victim and the lookalike address, even when the transaction appears to originate from the victim. Analysts should distinguish genuine user-authorised transfers from zero-value events and counterfeit-token activity. Addresses used in the same campaign may sometimes be linked through common funding sources or other on-chain patterns.