Connect with us

Crypto World

Address poisoning attack drains $100K USDT

Published

on

Address poisoning attack drains $100K USDT

A crypto user has lost approximately 100,000 USDT after transferring the funds to a lookalike wallet address planted in the victim’s transaction history 66 days earlier.

Summary

  • A victim has lost approximately 100,000 USDT in an address poisoning attack.
  • The attacker planted the fake address in the wallet’s history 66 days before the transfer.
  • The stolen USDT was converted into about 52.8 ETH, according to Cyvers.
  • Address poisoning exploits users who copy addresses without checking the complete character string.

Cyvers Alerts reported on Aug. 11 that its monitoring system detected the loss after the victim sent funds to an address controlled by an attacker.

How the $100K address poisoning attack unfolded

About 66 days before the theft, the attacker sent transactions involving the victim’s wallet, according to Cyvers. The activity placed a malicious address in the wallet’s transaction history, where it appeared similar to an address the victim had used for a normal transfer.

When the victim later prepared the 100,000 USDT payment, Cyvers said the user relied on the historical record without comparing the complete destination address. The funds consequently went to the lookalike address rather than the intended recipient.

Address poisoning does not require an attacker to obtain a private key, compromise a smart contract, or take control of the victim’s wallet. Instead, the method depends on the length and format of blockchain addresses, which many wallets and block explorers shorten by displaying only their first and last characters.

Advertisement

Attackers generate addresses that match the visible parts of a recipient’s genuine address and then use small or zero-value transfers to place the imitation in a target’s transaction record. A user who checks only the opening and closing characters can therefore select the attacker’s wallet even though the complete strings are different.

In the latest case, Cyvers attributed the loss to the victim’s failure to check the full address. The security company advised users not to treat transaction history as a trusted address book and recommended verifying every character before approving an on-chain payment.

Attacker converts stolen USDT into 52.8 ETH

Following the transfer, the attacker exchanged the stolen USDT for Ethereum, Cyvers reported. The receiving wallet held approximately 52.8 ETH when the security company published its alert.

Advertisement

Cyvers said the conversion appeared designed to reduce the risk that the stolen stablecoins could be frozen. USDT is issued by Tether through smart contracts that allow specific addresses to be blocked, while native ETH does not have an issuer with an equivalent freezing function.

The conversion also means the value of the attacker’s holdings can change with the ETH market price. Cyvers did not report any recovery, return agreement, or exchange intervention in its initial alert, nor did the company identify the victim publicly.

No evidence cited in the alert suggested that a flaw in Tether, Ethereum, or the victim’s wallet software caused the transfer. Cyvers instead described the incident as a social-engineering attack that used a forged address record to exploit the victim’s payment habits.

Address poisoning losses have reached millions

The $100,000 incident follows several larger cases involving the same method. In February, crypto.news previously reported that two users had lost a combined $62 million after copying fraudulent addresses from their transaction histories.

Advertisement

Scam Sniffer attributed about $50 million of that total to a December 2025 incident, while another victim lost approximately $12.25 million, or around 4,556 ETH at the time, in January 2026. The security company said attackers had quietly inserted lookalike addresses into both victims’ recent activity records.

During the December case, a stablecoin holder first sent a 50 USDT test payment to the correct destination. An attacker then inserted a fraudulent address into the history with a 0.005 USDT dust transaction, after which the victim mistakenly sent 49,999,950 USDT to the poisoned address.

The stolen assets were converted into ETH and spread across several wallets, according to an earlier report on the theft. The victim later offered the attacker a $1 million bounty for the return of the remaining funds and threatened to involve international law enforcement.

Low transaction costs have also made automated poisoning campaigns cheaper to operate. Scam Sniffer said in February that millions of dust transactions were being sent each day, with many created to prepare for possible future thefts rather than move funds between genuine users.

Advertisement

In March, a stablecoin user reported receiving 89 poisoning alerts within 30 minutes after completing only two legitimate transfers. Former Binance CEO Changpeng Zhao subsequently criticized transaction explorers that continued to display the malicious entries.

US lawmakers have proposed a crypto fraud task force

For U.S. users, address poisoning falls within a growing category of digital-asset fraud that lawmakers have sought to address through interagency coordination. Senators Elissa Slotkin and Jerry Moran introduced the bipartisan Strengthening Agency Frameworks for Enforcement of Cryptocurrency Act, known as the SAFE Crypto Act, in 2025.

According to the bill’s sponsors, the proposed legislation would establish a federal task force focused on identifying, monitoring, and preventing cryptocurrency scams. Its members would include representatives from government agencies, law enforcement, digital-asset companies, stablecoin issuers, blockchain intelligence firms, and consumer-protection organizations.

The proposal covers several forms of crypto crime, including investment fraud, money laundering, Ponzi schemes, rug pulls, and fraudulent token sales. Sponsors said the task force would examine scam patterns and improve coordination between federal authorities and private-sector specialists.

Advertisement

The bill does not create a reimbursement program for users who mistakenly authorize irreversible transfers. As earlier coverage explained, its proposed task force would focus on detection, disruption and cooperation among agencies and industry participants.

Full address checks can expose poisoned records

Cyvers advised users to compare complete wallet addresses rather than relying on shortened records in transaction histories. For large transfers, security specialists also recommend confirming the destination through a separate communication channel and sending a small test amount before moving the remaining balance.

A test payment alone may not prevent a poisoning attack, as the December 2025 theft demonstrated. Because an attacker can insert a lookalike address immediately after the test, the sender must verify that the address used for the main transfer is identical to the one used for the test transaction.

Address whitelists can add another check by limiting withdrawals to destinations approved in advance. Hardware wallets can also display transaction details before signing, though users must still read and compare the destination shown on the device.

Advertisement

Wallet interfaces and blockchain explorers have started filtering suspicious entries, but the protections vary by platform. A March report found that Etherscan hid zero-value transfers by default, while BscScan and Basescan required users to activate a “hide 0 amount tx” option to remove such records from view.

Source link

Advertisement
Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Crypto World

eToro to Buy US Brokerage TradeZero for Up to $231M as Crypto Revenue Shrinks

Published

on

Allbridge Halts Core Bridge After $1.65M Flash Loan Exploit


eToro Group agreed to buy TradeZero, a U.S.-focused online brokerage for active traders, for up to $231 million in cash plus up to 2.5 million newly issued Class A shares, the Nasdaq-listed company said in a release filed with the U.S. Securities and Exchange Commission on Tuesday. The purchase… Read the full story at The Defiant

Source link

Continue Reading

Crypto World

Riot Signs $9.1B, 20-Year AI Data Center Lease at Its Texas Bitcoin Mine

Published

on

Riot Signs $9.1B, 20-Year AI Data Center Lease at Its Texas Bitcoin Mine


Riot Platforms has leased 191 megawatts of computing capacity at its Rockdale, Texas, bitcoin mining campus to an unnamed artificial intelligence company under a 20-year agreement the miner says will generate roughly $9.1 billion in revenue, according to an exhibit filed with the U.S. Securities… Read the full story at The Defiant

Source link

Continue Reading

Crypto World

CFTC Sues Goliath Ventures Over Alleged $397M DeFi Liquidity Pool Ponzi

Published

on

CFTC Sues Goliath Ventures Over Alleged $397M DeFi Liquidity Pool Ponzi


The U.S. Commodity Futures Trading Commission sued Goliath Ventures Inc. and its chief executive, Christopher Delgado, on Tuesday, alleging the Florida company raised at least $397 million from roughly 1,600 customers by promising to place their bitcoin and ether in decentralized exchange liquidity… Read the full story at The Defiant

Source link

Continue Reading

Crypto World

'We Are Lady Parts' Is One of TIME's 50 Most Underappreciated TV Shows

Published

on

'We Are Lady Parts' Is One of TIME's 50 Most Underappreciated TV Shows
—Laura Radford—Peacock

Source link

Continue Reading

Crypto World

SEC to Unveil Alternative Crypto Plans to the CLARITY Act

Published

on

SEC to Unveil Alternative Crypto Plans to the CLARITY Act

The US Securities and Exchange Commission (SEC) votes Friday, August 14, on proposing Regulation Crypto. The purpose-built offering regime would mark the agency’s first major crypto rulemaking under Chair Paul Atkins.

The Senate left for its August recess without passing the CLARITY Act. That bill would divide digital asset oversight between the SEC and the Commodity Futures Trading Commission (CFTC).

SEC Crypto Plans Take Shape Before Friday Vote

Congressional inaction hands regulators the near-term initiative. Official notices confirm the open meeting for 10 a.m. ET at the agency’s Washington headquarters, with a live webcast. The agenda lists a single item from the Division of Corporation Finance.

Commissioners will decide whether to propose rules that give token offerings a dedicated legal path. Qualifying projects could raise capital under exemptions instead of completing full securities registration. The vote covers a proposing release only, so the text remains under wraps until Friday.

The proposal grew out of Project Crypto, the regulatory package Atkins placed on the SEC’s 2026 agenda. Its planks include registration exemptions for token sales, safe harbors for decentralizing projects, and custody standards for broker-dealers.

Atkins told CNBC in late July that the agency stands ready to act alone, even though he still prefers legislation.

“Statute is the way to future-proof something,” Atkins said in the interview.

Follow us on X to get the latest news as it happens

Advertisement

Senate Recess Leaves Regulators in the Lead

Democrats blocked floor action over an ethics carve-out tied to President Trump’s crypto holdings, according to American Banker. Republicans Josh Hawley and Jerry Moran also objected to the bill’s stablecoin yield language, siding with community banks.

Senate Majority Leader John Thune says the measure will move first when lawmakers return, teeing up a possible September vote. However, the bill still needs 60 votes, and Thune’s cloture strategy depends on Democratic support that has yet to materialize.

Meanwhile, some analysts argue the industry can advance without the bill. Grayscale research head Zach Pandl said passage looks unlikely in 2026 either way.

CFTC Signals the Same Playbook

The SEC is not acting in isolation. CFTC Chair Michael Selig issued a parallel warning in a July Fox Business interview. Regulators would end up writing all the crypto rules if Congress fails to deliver, he cautioned. He still urged senators to pass the bill, calling federal certainty critical for business.

Advertisement

Both agencies already coordinate closely. Their March joint interpretive rule classified most tokens outside securities law and carved out staking, mining, and airdrops.

Still, Atkins concedes that agency action lacks permanence. A future administration could reverse rules that Congress never wrote into statute. That caveat also applies to the March guidance itself.

A yes vote on Friday would open a public comment period, not finalize anything. The proposal’s exemption thresholds and eligibility tests will reveal how far the SEC intends to go without Congress. September’s Senate return will then show whether lawmakers reclaim the pen.

The post SEC to Unveil Alternative Crypto Plans to the CLARITY Act appeared first on BeInCrypto.

Advertisement

Source link

Continue Reading

Crypto World

'Such Brave Girls' Is One of TIME's 50 Most Underappreciated TV Shows

Published

on

'Such Brave Girls' Is One of TIME's 50 Most Underappreciated TV Shows
—Vishal Sharma—Disney

Source link

Continue Reading

Crypto World

MoneyGram Brings Cash-To-Crypto Ramps To Solana

Published

on

MoneyGram Brings Cash-To-Crypto Ramps To Solana


MoneyGram has extended MoneyGram Ramps, its cash-to-crypto and crypto-to-cash API, to Solana, the company said Tuesday. Rift, a self-custody trading app, is the first Solana wallet to integrate it. Until now, Solana wallets that wanted to route users into MoneyGram's retail cash network had to… Read the full story at The Defiant

Source link

Continue Reading

Crypto World

CT3 begins preparations for CT3GB token listing

Published

on

CT3 begins preparations for CT3GB token listing - 3

Disclosure: This article does not represent investment advice. The content and materials featured on this page are for educational purposes only.

CT3 is preparing for the CT3GB token listing by expanding storage infrastructure, building reserves, upgrading smart contracts, and planning an independent audit.

Advertisement

Summary

  • CT3 is expanding storage capacity and reserves before launching its CT3GB token on public markets.
  • CT3GB will support storage payments, infrastructure settlements, rewards, and other internal transactions across the ecosystem.
  • An independent smart contract audit will review security, business logic, and industry standards before launch.

CT3 begins preparations for CT3GB token listing - 3

CT3 has started comprehensive preparations for the future CT3GB token listing as it expands the CT3 Cloud ecosystem. The company is scaling data storage infrastructure, building financial and infrastructure reserves, and preparing CT3GB to become its primary settlement asset. It is also moving to a new smart contract architecture and plans an independent audit before the token reaches the public market. CT3 says these steps are intended to support further platform growth and prepare its tokenized economy before the listing.

CT3GB token listing preparations expand

Over recent months, CT3 has expanded the capabilities of its platform, according to the CT3 official website. One key milestone was the introduction of automatic backup technology. CT3 said demand for data storage services rose after that feature was implemented, while growing data volumes showed the platform could support continuous storage use cases.

The company said the next stage requires both technical and economic preparation. CT3 is expanding its storage network, adding available computing capacity, and building reserves intended to support further scaling. The Storage Contracts program forms part of that effort. CT3 views the program as a way to increase network capacity while maintaining commercial use and creating a resource buffer for future growth.

CT3GB to become primary settlement asset

Most internal CT3 operations currently use Polygon infrastructure. After CT3GB launches, the company plans to move major financial processes within the platform to its own token. CT3GB is expected to handle payments for storage services, settlements with infrastructure owners, reward distribution, and other internal transactions.

Advertisement

The token is designed to connect users, storage infrastructure, and services across the CT3 Cloud ecosystem. CT3 plans to use CT3GB as the primary settlement asset for internal operations. The company presents this utility as a central part of its tokenized economy, rather than positioning the token only as another payment option.

New smart contract architecture takes shape

CT3 is also changing the structure of its storage technology. The company is segmenting storage infrastructure into separate specialized smart contracts. Different products will gradually receive their own contracts, with independent limits for capacity and separate resource accounting.

According to CT3, this structure should make scaling more efficient and improve visibility into infrastructure use. It is also intended to give the company more flexibility when developing new services. Separate contracts could allow new products to grow without changing services that are already operating within the platform.

Independent audit planned before public launch

Before CT3GB enters the public market, CT3 plans to complete an independent audit of the core smart contract infrastructure. The review will cover the contracts supporting the token and key platform services. It will examine contract security, business logic, and alignment with industry standards.

Advertisement

CT3 considers the audit a required part of preparing its economy for public launch. The company says the review can support trust among users, partners, and cryptocurrency exchanges. Together with storage expansion, reserve building, and the new contract structure, the audit forms part of a broader plan to launch CT3GB within an ecosystem prepared for continued growth.

CT3 describes itself as a company focused on decentralized data storage. Its platform combines a distributed storage network, NFT-based access keys, automatic backup tools, and scalable smart contract architecture for individual and corporate users seeking long-term storage and digital information protection.

The company’s solutions are designed for individuals and corporate users, with services focused on secure long-term storage, backup, and protection of digital information across its decentralized infrastructure network.

Advertisement

Disclosure: This content is provided by a third party. Neither crypto.news nor the author of this article endorses any product mentioned on this page. Users should conduct their own research before taking any action related to the company.

Source link

Advertisement
Continue Reading

Crypto World

'Slip' Is One of TIME's 50 Most Underappreciated TV Shows

Published

on

'Slip' Is One of TIME's 50 Most Underappreciated TV Shows
—Courtesy of NBCUniversal

Source link

Continue Reading

Crypto World

Trump’s Secret Plane Trip Not Unprecedented, Former Agents Say

Published

on

Trump’s Secret Plane Trip Not Unprecedented, Former Agents Say

McDonald described the decision-making process around such operations as a joint effort among the Secret Service, the White House Military Office and White House staff, with “no one entity” holding more authority than the others.

The Department of Defense has referred questions from TIME to the White House. TIME has reached out to the White House for comment.

McDonald pushed back on the idea that Air Force One and the people still aboard it, including journalists, were left exposed. “I would find it incredibly hard to believe that those two planes weren’t escorted or with other assets from allies or the U.S. Air Force in the area,” he said, adding that he doubted the people on the aircraft “were dangled out there and left to fend for themselves.”

The operation broke a White House tradition that presidents rarely travel without a group of reporters known as the White House pool, to ensure the public has an independent account of the president’s activities. Former President Barack Obama broke the tradition in 2010 by leaving the White House to attend his daughter’s soccer game without telling reporters.

Advertisement

In 2000, President Bill Clinton secretly switched to an unmarked plane for a trip to Pakistan. At least one member of the White House pool, a reporter covering the trip for USA Today, was briefed on the operation beforehand, according to The Washington Post.

Source link

Continue Reading

Trending

Copyright © 2025