USENIX Security2025Top-tier venue
Blockchain Address Poisoning
Taro Tsuchiya, Jin-Dong Dong, Kyle Soska, Nicolas Christin
Abstract
In many blockchains, e.g., Ethereum, Binance Smart Chain (BSC), the primary representation used for wallet addresses is a hardly memorable 40-digit hexadecimal string. As a result, users often select addresses from their recent transaction history, which enables blockchain address poisoning. The adversary first generates lookalike addresses similar to one with which the victim has previously interacted, and then engages with the victim to ``poison''their transaction history. The goal is to have the victim mistakenly send tokens to the lookalike address, as opposed to the intended recipient. Compared to contemporary studies, this paper provides four notable contributions. First, we develop a detection system and perform measurements over two years on both Ethereum and BSC. We identify 13 times more attack attempts than reported previously -- totaling 270M on-chain attacks targeting 17M victims. 6,633 incidents have caused at least 83.8M USD in losses, which makes blockchain address poisoning one of the largest cryptocurrency phishing schemes observed in the wild. Second, we analyze a few large attack entities using improved clustering techniques, and model attacker profitability and competition. Third, we reveal attack strategies -- targeted populations, success conditions (address similarity, timing), and cross-chain attacks. Fourth, we mathematically define and simulate the lookalike address generation process across various software- and hardware-based implementations, and identify a large-scale attacker group that appears to use GPUs. We also discuss defensive countermeasures.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ae8e7b14-de87-4fe1-a221-e5c7f73dca96Cited by top-tier papers3
- Insecurity Through Obscurity: Veiled Vulnerabilities in Closed-Source ContractsSen Yang, Kaihua Qin, Aviv Yaish, Fan ZhangCCS 2026 · 3 citations
- Meme Coin Factories: Uncovering Large-Scale Manipulations on pump.funNicolas Szwajcok, Taro Tsuchiya, Enze Liu, Kyle Soska et al.CCS 2026
- Lost in Blockchain Address Misuse: Hidden Cross-Platform Risks and Their Security ImpactZhenzhe Shao, Jiashuo Zhang, Zihao Li, Daoyuan Wu et al.USENIX Security 2026
Builds on17
- Quantifying Blockchain Extractable Value: How dark is the forest?Kaihua Qin, Liyi Zhou, Arthur GervaisS&P 2022 · 336 citations
- Hiding in Plain Sight: A Longitudinal Study of Combosquatting AbusePanagiotis Kintis, Najmeh Miramirkhani, Charles Lever, Yizheng Chen et al.CCS 2017 · 166 citations
- The Anatomy of a Cryptocurrency Pump-and-Dump SchemeJiahua Xu, Benjamin LivshitsUSENIX Security 2019 · 146 citations
- Cognitive Triaging of Phishing AttacksAmber van der Heijden, Luca AllodiUSENIX Security 2019 · 100 citations
- Catching Phishers By Their Bait: Investigating the Dutch Phishing Landscape through Phishing Kit DetectionHugo L. J. Bijmans, Tim M. Booij, Anneke Schwedersky, Aria Nedgabat et al.USENIX Security 2021 · 61 citations
Related papers
- Characterizing Ethereum Address Poisoning AttackShixuan Guan, Kai LiCCS 2024 · 4 citations
- Interface Illusions: Uncovering the Rise of Visual Scams in Cryptocurrency WalletsGuoyi Ye, Geng Hong, Yuan Zhang, Min YangWWW 2024 · 7 citations
- Dissecting Payload-based Transaction Phishing on EthereumZhuo Chen, Yufeng Hu, Bowen He, Dong Luo et al.NDSS 2025
- TxPhishScope: Towards Detecting and Understanding Transaction-based Phishing on EthereumBowen He, Yuan Chen, Zhuo Chen, Xiaohui Hu et al.CCS 2023 · 38 citations
- TTAGN: Temporal Transaction Aggregation Graph Network for Ethereum Phishing Scams DetectionSijia Li, Gaopeng Gou, Chang Liu, Chengshang Hou et al.WWW 2022 · 156 citations
