Investor loses 386,000 USDT due to address substitution attack., 2026/04/11 10:05:16

24

Investor loses 386,000 USDT due to address spoofing attack0

An investor has lost 386,300 after sending funds to an address that was visually similar to the legitimate one. This information was reported by analysts from the cybersecurity firm Antivirus.

The incident pertains to an attack known as “address poisoning.” Experts explained that the authentic address began with “0xb302” and concluded with “cf88.” The attacker created a nearly identical address “0xb302c716…cf88,” to which the victim sent the funds. 

“The essence of the method is that the fraudster substitutes an address in the wallet history that shares the same starting and ending characters as the genuine recipient. Users often only check the beginning and end of the string and copy the address from their recent transactions,” the analysts noted.

The stolen coins were converted by the perpetrators into DAI stablecoins and Ether. The system assigned the hackers’ wallet a maximum risk level of 100 points. According to experts, this address is used as an intermediary for distributing the stolen assets.

Analysts added that such attacks are becoming less expensive due to decreasing fees in blockchain networks. This enables criminals to automate the process and send thousands of fraudulent transactions in hopes of exploiting user inattention.

Previously, specialists from ScamSniffer reported that in January, a user lost $12.2 million after sending funds to a counterfeit address copied from transaction history.