MercanPay Blog

Address Poisoning Attacks and How to Protect Your USDT Wallet

How address poisoning attacks work, why TRC20 USDT users are targeted, and the practical habits and saved addresses that keep your funds safe.

Published: October 2, 20266 min readTürkçe oku
Address Poisoning Attacks and How to Protect Your USDT Wallet

An address poisoning attack is a scam where a fraudster plants a look-alike address in your transaction history and waits for you to copy it the next time you send funds. It is common with high-volume assets like USDT on TRON (TRC20), and one careless copy-paste can send money to the wrong person with no way to reverse it.

This guide explains how the attack is set up, why it works so well, and the concrete steps you can take both in your personal wallet and when you run payments through a gateway.

How an address poisoning attack works

The trick relies on the fact that people rarely read long blockchain addresses character by character. TRON addresses are 34-character strings starting with T, and most wallets shorten them to something like TQ4k…9fQe2. Users tend to check only the first and last few characters.

A typical attack looks like this:

  1. Pick a target. The attacker watches the chain for addresses that make regular, sizeable transfers, such as a business paying the same counterparty every week.
  2. Generate a twin. Using specialised software, they create an address whose first and last characters match an address you use often.
  3. Poison the history. They send you a tiny amount, a zero-value transfer or a worthless token from the twin address, so it appears at the top of your wallet history.
  4. Wait for the slip. If you copy the recipient from "recent transactions" next time, the payment goes to the attacker.

Blockchain transfers are final. Once confirmed, neither your wallet app nor the network can undo them.

Why TRC20 USDT users are a favourite target

TRON transactions are fast and relatively cheap. That is great for legitimate users, but it also makes it economical for attackers to spray "dust" transfers across thousands of addresses. And because USDT is the most widely used stablecoin for commercial payments, the pool of potential victims is large. For background on the networks involved, see what USDT is and how TRC20, ERC20 and BEP20 differ.

Red flag What it looks like What to do
Zero or dust transfer 0 or 0.000001 USDT from an unknown address Ignore it and never reuse that address
Fake token A worthless TRC20 token with an odd name Don't interact with it or try to sell it
Look-alike address Same first and last 4–6 characters Compare the full address
Pressure to hurry "I need the payment right now" Confirm the address through a separate channel

Seven habits that stop the attack

1. Never copy an address from your transaction history

This single habit defeats most poisoning attempts. Always take the recipient from a trusted source: your own saved address book, the recipient's verified invoice, or the QR code on a payment page.

2. Check the whole address

The first and last characters are not enough, so check the middle too. For large transfers, paste the address into a text editor next to the original and compare.

3. Use saved addresses

Save the addresses you use often once, after careful verification, and pick from that list afterwards.

4. Send a small test first

For a new recipient or a large amount, send a small test transfer and wait for confirmation. It costs an extra network fee but can prevent a serious loss.

5. Leave unknown tokens alone

Unknown tokens that appear in your wallet are usually bait. Trying to sell or "claim" them on some website creates new risks.

6. Watch out for clipboard malware

Some malware swaps the address you copied for another one at paste time. Re-checking after pasting protects against this too.

7. Use four-eyes approval in teams

For company wallets, having a second person approve large transfers reduces both honest mistakes and internal misuse.

Address safety when accepting payments and withdrawing

If your business accepts crypto, poisoning has two sides: a customer paying the wrong address, and you withdrawing to the wrong one.

On the customer side, every MercanPay invoice comes with its own hosted payment page that shows the payment address with a QR code and a copy button. The customer takes the address from that invoice page, not from an old chat or message, which sharply reduces the chance of a mix-up. Our guide to accepting USDT TRC20 payments walks through the checkout flow.

On the withdrawal side the risk is usually higher, because moving your balance to your own wallet or an exchange means copying an address from somewhere. MercanPay adds several layers here:

  • Saved withdrawal addresses. You save addresses in the panel and choose from the list later.
  • Trusted addresses. An address can be marked as trusted once it is at least 7 days old and has received 3 completed withdrawals, or earlier if an early-unlock request is approved. API withdrawals can only go to trusted addresses, and anything else is rejected.
  • Two codes for every panel withdrawal. Each withdrawal from the panel needs an email code plus an authenticator (TOTP) code.
  • Lock after a password reset. Withdrawals are blocked for 24 hours after a password reset, so even a hijacked account can't be drained instantly.
  • Activity log and security emails. Sensitive actions are logged and you are notified by email.

We cover how to combine these in securing your crypto merchant account.

Tip: when you add a trusted withdrawal address, take it from the "deposit" screen of your exchange or hardware wallet, never from a transaction list. Once it is saved correctly, every later withdrawal draws from that safe source.

If you already sent funds to a poisoned address

Honestly, there is no technical way to reverse a confirmed transfer. Still, act quickly:

  1. Write down the transaction ID (TXID), amount, time and recipient address.
  2. If the recipient address belongs to an exchange, contact that exchange's support right away.
  3. Consider reporting the incident to the relevant authorities.
  4. Check whether a device or wallet of yours is compromised, for example by malware.

Be very wary of anyone who promises to "recover" your funds. Recovery scams are a common follow-up to the original theft.

FAQ

I received a zero-USDT transfer. Is that dangerous?

The transfer itself can't hurt your funds. The danger is reusing that sender's address by mistake later. Ignore it and never copy payment addresses from your history.

Does address poisoning mean my wallet was hacked?

No. The attacker never gets access to your wallet. They only add a visible entry to your public transaction history and rely on you making a mistake.

Can the address on a payment page be poisoned?

Each open invoice gets its own payment address, shown directly on that invoice's page. As long as the customer takes the address from the page rather than from a transaction history, there is no history-based confusion. It's still good practice to tell customers to always take the address from the invoice page itself.

Can someone withdraw to an arbitrary address through the API?

On MercanPay, API withdrawals only go to saved addresses you have marked as trusted in the panel. Any other address is refused, which protects your balance even if an API key leaks.

Get started with MercanPay

Accept TRX and USDT (TRC20) with a dedicated payment page per invoice, saved and trusted withdrawal addresses, and two-factor checks on every withdrawal. Apply for a merchant account and read the documentation to plan your integration.

#Security#USDT#TRC20#Wallet

Related posts

Start accepting crypto payments in minutes

Accept USDT and TRX (TRC20). Fees from 0.4%, a hosted payment page, API and webhooks.