You didn't click anything. You didn't sign anything strange. You copied an address you'd sent to before, and the money went somewhere else.
How it works
The scammer watches for wallets that send regular transfers. They generate an address whose first and last few characters match one you've sent to before, then send you a tiny or zero-value transaction from it. Now that lookalike sits in your history, right next to the real one.
Most wallets shorten addresses to the first and last few characters. At a glance, these two look identical:
Real: 0x7a3F9c2e41d8b05f6e1a9c73b0d2e8f41c6a91Be
Poison: 0x7a3F0b18ce77a2f94d3be60c15a8f27d93e091Be
The next time you go to send, you copy from your history, pick the wrong one, and the transfer can't be reversed.
Never copy a destination address from your transaction history. Copy it from the source, every time.
The habits that stop it
- Save addresses you use regularly in your wallet's address book, and send only from there.
- Check the middle of the address, not just the ends. That's the part scammers can't cheaply match.
- Send a small test first for any large transfer, and confirm it arrived before sending the rest.
- Ignore unexpected tiny deposits. They're usually the bait, not a gift.
If it's already happened
Write down the transaction ID, both addresses and the time, and report it to ReportCyber. Then read our Recover page before anyone offers to get the funds back for a fee.
More from the blog
General information only. Orange Brick Road Pty Ltd (ABN 92 655 540 480) does not hold an Australian Financial Services Licence and nothing here is financial product advice.

