Crypto Trader Suffers $50 million Loss Following Address Poisoning Attack

Markets 2025-12-22 10:04

A cryptocurrency trader lost $50 million in Tether’s USDT  after falling victim to a sophisticated “address poisoning” attack.

On December 20, blockchain security firm Scam Sniffer reported that the attack began after the victim sent a small $50 test transaction to his own address.

How The Address Poisoning Scheme Unfolded

Notably, traders use this standard precaution to confirm that they are sending funds to the correct address.

However, that activity alerted an automated script controlled by the attacker, which immediately generated a “spoofed” wallet address.

The fake address is designed to match the intended recipient’s address at the beginning and end of the alphanumeric string. The differences appear only in the middle characters, making the fraud difficult to detect at a glance.

The attacker then sent a negligible amount of cryptocurrency from the spoofed address to the victim’s wallet.

That transaction effectively placed the fraudulent address into the victim’s recent transaction history, where many wallet interfaces display only truncated address details.

Relying on that visual shorthand, the victim copied the address from their transaction history without checking the full string. So, instead of transferring funds to a secure personal wallet, the trader sent 49,999,950 USDT directly to the attacker.

After receiving the funds, the malicious attacker quickly moved to limit the risk of asset seizure, according to on-chain records. The attacker immediately swapped the stolen USDT, which its issuer can freeze, for the DAI stablecoin using MetaMask Swap.

Crypto Trader Suffers  million Loss Following Address Poisoning Attack

Attacker Moves to Obscure Transaction Trail. Source: Slowmist

The attacker then converted the funds into roughly 16,680 ETH.

To further obscure the transaction trail, the attacker deposited the ETH into Tornado Cash. The decentralized mixing service is designed to sever the visible link between sending and receiving addresses.

Victim Offers $1 Million Bounty

In an attempt to recover the assets, the victim sent an on-chain message offering a $1 million white-hat bounty in return for 98% of the stolen funds.

“We have officially filed a criminal case. With the assistance of law enforcement, cybersecurity agencies, and multiple blockchain protocols, we have already gathered substantial and actionable intelligence regarding your activities,” the message stated.

The message warned that the victim would pursue “relentless” legal action if the attacker failed to comply within 48 hours.

“If you fail to comply: We will escalate the matter through legal and international law enforcement channels. Your identity will be uncovered and shared with the appropriate authorities. We will relentlessly pursue criminal and civil action until full justice is served. This is not a request. You are being given one final chance to avoid irreversible consequences,” the victim stated.

The incident underscores a persistent vulnerability in how digital wallets display transaction information and how attackers exploit user behavior rather than flaws in blockchain code.

Security analysts have repeatedly warned that wallet providers’ practice of abbreviating long address strings for usability and design reasons creates a persistent risk.

If this problem is not solved, attackers are likely to continue exploiting users’ tendency to verify only the first and last few characters of an address.

Share to:

This content is for informational purposes only and does not constitute investment advice.

Curated Series

SuperEx Popular Science Articles Column

SuperEx Popular Science Articles Column

This collection features informative articles about SuperEx, aiming to simplify complex cryptocurrency concepts for a wider audience. It covers the basics of trading, blockchain technology, and the features of the SuperEx platform. Through easy-to-understand content, it helps users navigate the world of digital assets with confidence and clarity.

Unstaked related news and market dynamics research

Unstaked related news and market dynamics research

Unstaked (UNSD) is a blockchain platform integrating AI agents for automated community engagement and social media interactions. Its native token supports governance, staking, and ecosystem features. This special feature explores Unstaked’s market updates, token dynamics, and platform development.

XRP News and Research

XRP News and Research

This series focuses on XRP, covering the latest news, market dynamics, and in-depth research. Featured analysis includes price trends, regulatory developments, and ecosystem growth, providing a clear overview of XRP's position and potential in the cryptocurrency market.

How do beginners trade options?How does option trading work?

How do beginners trade options?How does option trading work?

This special feature introduces the fundamentals of options trading for beginners, explaining how options work, their main types, and the mechanics behind trading them. It also explores key strategies, potential risks, and practical tips, helping readers build a clear foundation to approach the options market with confidence.

What are the risks of investing in cryptocurrency?

What are the risks of investing in cryptocurrency?

This special feature covers the risks of investing in cryptocurrency, explaining common challenges such as market volatility, security vulnerabilities, regulatory uncertainties, and potential scams. It also provides analysis of risk management strategies and mitigation techniques, helping readers gain a clear understanding of how to navigate the crypto market safely.