A cryptocurrency trader lost nearly $50 million in USDT stablecoins on December 19, 2024, after falling victim to a sophisticated address poisoning scam.A cryptocurrency trader lost nearly $50 million in USDT stablecoins on December 19, 2024, after falling victim to a sophisticated address poisoning scam.

Crypto Trader Loses $50 Million in Address Poisoning Attack, Offers $1 Million Bounty

The attack marks one of the largest individual losses from this type of fraud on record.

Blockchain security firms SlowMist, Scam Sniffer, and Web3 Antivirus identified the victim as sending 49,999,950 USDT to a scammer-controlled address. The funds were withdrawn from Binance exchange just before the attack occurred.

The Attack Timeline

According to Etherscan data, the victim initially sent a small test transaction of 50 USDT to their intended destination address at 06:20:35 UTC. This is a standard security practice many crypto users follow before sending large amounts.

However, an automated script controlled by the attacker immediately created a fake wallet address. The malicious address (0xBaFF2F13638C04B10F8119760B2D2aE86b08f8b5) was designed to look nearly identical to the victim’s real destination address (0xbaf4b1aF7E3B560d937DA0458514552B6495F8b5).

The scammer made the fake address match the first three and last four characters of the legitimate address. Since most crypto wallets show only the beginning and end of addresses with dots in the middle, this trick easily fools users who don’t check every character.

Source: @lookonchain

The attacker then sent small transactions from the fake address to the victim’s wallet. This “poisoned” the victim’s transaction history with the scammer’s address. When the victim copied an address from their history 12 minutes later to send the full $50 million, they accidentally grabbed the fake one instead. The massive transfer went through at 06:32:59 UTC.

Swift Money Laundering

The attacker moved fast to hide the stolen money. Within 30 minutes of receiving the USDT, the scammer converted all of it to DAI using MetaMask Swap. This was a smart move because Tether can freeze USDT in suspicious wallets, but DAI is decentralized and cannot be frozen.

The attacker then swapped the DAI for approximately 16,690 ETH. Most of this—around 16,680 ETH—was deposited into Tornado Cash, a crypto mixing service that makes transactions nearly impossible to trace.

Security researcher Cos from SlowMist explained that “the subtlety is in the middle characters—enough to deceive even pros who rely on partial checks.”

The victim sent an on-chain message to the attacker offering a $1 million reward for returning 98% of the stolen funds. The message came with serious legal warnings.

“We have officially filed a criminal case. With the assistance of law enforcement, cybersecurity agencies, and multiple blockchain protocols, we have already gathered substantial and actionable intelligence regarding your activities,” the message stated.

The victim gave the attacker 48 hours to accept the bounty. If refused, they threatened to “escalate the matter through legal and international law enforcement channels” and pursue “relentless” criminal and civil action.

There is some hope for recovery. In May 2024, another victim lost $71 million in a similar address poisoning attack. That victim eventually recovered nearly all their funds after negotiations helped by blockchain security firm Match Systems and Cryptex exchange. However, the current case may be harder to resolve since the funds were quickly moved to Tornado Cash.

A Growing Problem

Address poisoning attacks are spreading across different blockchains. Jameson Lopp, Chief Security Officer at Bitcoin custody firm Casa, warned in April 2025 about this rising threat. His analysis found 48,000 suspected attacks on Bitcoin alone since 2023.

“[The attacks are] a result of the fact that we’re in a very low-fee environment,” Lopp said at the MIT Bitcoin Expo. Low transaction fees make it cheap for scammers to send thousands of fake transactions to potential victims.

Lopp suggested that wallet developers should add warnings when users interact with addresses that look similar to ones they’ve used before. “I think it would be easy for wallets to say ‘Oh, this came from a similar looking address,’ and throw up a big red flag: do not interact,” he explained.

According to security firms Web3 Antivirus and SlowMist, address poisoning accounted for over 10% of all wallet drains in 2025. Users of stablecoins like USDT face particular risk because their predictable transfer patterns help scammers plan attacks.

Record Theft Year

This attack adds to an already devastating year for crypto security. Chainalysis reported that cryptocurrency losses exceeded $3.4 billion in 2025, slightly higher than the $3.38 billion stolen in 2024.

The February 2025 hack of Bybit exchange was the single largest crypto theft ever recorded. North Korean threat actors stole $1.5 billion, accounting for around 44% of the year’s total losses. Security firm Elliptic called it “the largest crypto theft of all time.”

Personal wallet attacks have grown dramatically. In 2022, attacks on individual wallets made up just 7.3% of total stolen value. By 2024, that number jumped to 44%. Chainalysis documented 158,000 instances of personal wallet breaches affecting at least 80,000 different victims.

Mitchell Amador, CEO of blockchain security firm Immunefi, explained the shift: “The threat landscape is shifting from on-chain code vulnerabilities to operational security and treasury-level attacks. As code hardens, attackers target the human element.”

How to Stay Safe

Security experts recommend several steps to avoid address poisoning:

Check Every Character: Never trust just the first and last few characters of an address. Verify the complete address before sending any amount.

Use Address Books: Save trusted addresses in your wallet’s address book. Don’t copy addresses from your transaction history where scammers can plant fakes.

Spot Dust Attacks: Watch for tiny unexpected transactions from unknown addresses. These are red flags that your wallet might be getting poisoned.

Test and Wait: If you send a test transaction, wait and confirm it arrived at the right place before sending larger amounts.

Hardware Wallets Help: Hardware wallets with built-in screens force you to review the full address before approving transactions.

Unlike hacks that exploit code vulnerabilities, address poisoning attacks target human behavior. The blockchain itself works perfectly—scammers just trick people into making mistakes. This makes the problem harder to solve through technology alone.

Educational campaigns from industry groups stress the importance of hardware wallets with address confirmation screens. These tools force users to manually review addresses, which can prevent costly mistakes.

When Trust Becomes a Weakness

The $50 million loss shows how even experienced crypto users following security best practices can fall victim to sophisticated scams. The attacker exploited the very security measure—test transactions—that should have protected the victim.

As blockchain technology improves and becomes harder to hack directly, criminals are finding success by targeting the people using it instead. Whether through legal pressure or negotiation, the crypto community hopes this victim might join the small group who have successfully recovered stolen funds. But with the money already in Tornado Cash, the odds look challenging.

Market Opportunity
1 Logo
1 Price(1)
$0.006191
$0.006191$0.006191
-4.54%
USD
1 (1) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

CME Group to launch options on XRP and SOL futures

CME Group to launch options on XRP and SOL futures

The post CME Group to launch options on XRP and SOL futures appeared on BitcoinEthereumNews.com. CME Group will offer options based on the derivative markets on Solana (SOL) and XRP. The new markets will open on October 13, after regulatory approval.  CME Group will expand its crypto products with options on the futures markets of Solana (SOL) and XRP. The futures market will start on October 13, after regulatory review and approval.  The options will allow the trading of MicroSol, XRP, and MicroXRP futures, with expiry dates available every business day, monthly, and quarterly. The new products will be added to the existing BTC and ETH options markets. ‘The launch of these options contracts builds on the significant growth and increasing liquidity we have seen across our suite of Solana and XRP futures,’ said Giovanni Vicioso, CME Group Global Head of Cryptocurrency Products. The options contracts will have two main sizes, tracking the futures contracts. The new market will be suitable for sophisticated institutional traders, as well as active individual traders. The addition of options markets singles out XRP and SOL as liquid enough to offer the potential to bet on a market direction.  The options on futures arrive a few months after the launch of SOL futures. Both SOL and XRP had peak volumes in August, though XRP activity has slowed down in September. XRP and SOL options to tap both institutions and active traders Crypto options are one of the indicators of market attitudes, with XRP and SOL receiving a new way to gauge sentiment. The contracts will be supported by the Cumberland team.  ‘As one of the biggest liquidity providers in the ecosystem, the Cumberland team is excited to support CME Group’s continued expansion of crypto offerings,’ said Roman Makarov, Head of Cumberland Options Trading at DRW. ‘The launch of options on Solana and XRP futures is the latest example of the…
Share
BitcoinEthereumNews2025/09/18 00:56
Bipartisan Bill Targets Crypto Tax Loopholes and Stablecoin Rules: Report

Bipartisan Bill Targets Crypto Tax Loopholes and Stablecoin Rules: Report

Bipartisan House members Max Miller (R-Ohio) and Steven Horsford (D-Nev.) are moving to simplify the tax treatment of digital assets with the introduction of the
Share
Tronweekly2025/12/21 08:46
James Wynn closed his short Bitcoin position four hours ago, making a profit of $21,000, and then opened a long position.

James Wynn closed his short Bitcoin position four hours ago, making a profit of $21,000, and then opened a long position.

PANews reported on December 21 that, according to Lookonchain monitoring, James Wynn closed his short Bitcoin position four hours ago, making a profit of $21,000
Share
PANews2025/12/21 08:57