Characterizing Ethereum Address Poisoning Attack
Shixuan Guan, Kai Li
摘要
This paper presents the first comprehensive analysis of the address poisoning attack surged on the Ethereum blockchain. This phishing attack typically exploits the address shortening feature of Ethereum explorers and digital wallets (e.g., Etherscan and MetaMask) by crafting token transfer events with a seemingly correct address to poison victims' transfer history, waiting for them to mistakenly transfer assets to the attacker's address. To systematically detect and characterize the address poisoning attack, we developed a detection system named Poison-Hunter, which can recognize the attacker's crafted transfers and detect the phishing addresses controlled by the attacker. By applying Poison-Hunter to Ethereum blocks produced from Nov. 2022 to Feb. 2024, we have detected millions of phishing transfers and phishing addresses. Our analysis shows that the attacker has predominantly targeted USDC and USDT token holders and used a phishing address that looks highly similar to a benign one. We also find that the sender of legitimate transfers was the primary target of this attack. Furthermore, by tracing the transaction history of the detected phishing addresses, we reveal that over 1,800 victim addresses have lost crypto assets, with a potential financial loss of up to 90 million of loss are confirmed by this work. Finally, our analysis suggests that 98% of phishing addresses are controlled by four entities, which collected nearly 92% of the total profits. Overall, this paper sheds light on the tactics utilized in the address poisoning attack and its scale and impact on the Ethereum blockchain, emphasizing the urgent need for an effective detection and prevention mechanism against such a phishing activity. CCS Concepts • Security and privacy → Distributed systems security.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- Serial Scammers and Attack of the Clones: How Scammers Coordinate Multiple Rug Pulls on Decentralized ExchangesPhuong Duy Huynh, Son Hoang Dau, Nicholas Huppert, Joshua Cervenjak 等WWW 2025 · 被引用 6 次
- Insecurity Through Obscurity: Veiled Vulnerabilities in Closed-Source ContractsSen Yang, Kaihua Qin, Aviv Yaish, Fan ZhangCCS 2026 · 被引用 3 次
- Evasion Under Blockchain SanctionsEndong Liu, Mark Ryan, Liyi Zhou, Pascal BerrangWWW 2026 · 被引用 1 次
- Meme Coin Factories: Uncovering Large-Scale Manipulations on pump.funNicolas Szwajcok, Taro Tsuchiya, Enze Liu, Kyle Soska 等CCS 2026
- Lost in Blockchain Address Misuse: Hidden Cross-Platform Risks and Their Security ImpactZhenzhe Shao, Jiashuo Zhang, Zihao Li, Daoyuan Wu 等USENIX Security 2026
它引用的顶会 Paper3
- The Art of The Scam: Demystifying Honeypots in Ethereum Smart ContractsChristof Ferreira Torres, Mathis Steichen, Radu StateUSENIX Security 2019 · 被引用 239 次
- iBatch: saving Ethereum fees via secure and cost-effective batching of smart-contract invocationsYibo Wang, Qi Zhang, Kai Li, Yuzhe Tang 等FSE 2021 · 被引用 15 次
- Double and Nothing: Understanding and Detecting Cryptocurrency Giveaway ScamsXigao Li, Anurag Yepuri, Nick NikiforakisNDSS 2023
相关 Paper
- Blockchain Address PoisoningTaro Tsuchiya, Jin-Dong Dong, Kyle Soska, Nicolas ChristinUSENIX Security 2025
- Dissecting Payload-based Transaction Phishing on EthereumZhuo Chen, Yufeng Hu, Bowen He, Dong Luo 等NDSS 2025
- TxPhishScope: Towards Detecting and Understanding Transaction-based Phishing on EthereumBowen He, Yuan Chen, Zhuo Chen, Xiaohui Hu 等CCS 2023 · 被引用 38 次
- Interface Illusions: Uncovering the Rise of Visual Scams in Cryptocurrency WalletsGuoyi Ye, Geng Hong, Yuan Zhang, Min YangWWW 2024 · 被引用 7 次
- TTAGN: Temporal Transaction Aggregation Graph Network for Ethereum Phishing Scams DetectionSijia Li, Gaopeng Gou, Chang Liu, Chengshang Hou 等WWW 2022 · 被引用 156 次
