Address poisoning scams#
Last modified: August 10, 2026
Address poisoning is a scam where an attacker sends a tiny transfer, fake token, or zero-value-looking transaction involving a wallet address that resembles one you use. The attacker wants the lookalike address to appear in your wallet or explorer history so you copy it by mistake later.
What it looks like#
You often send CTN to a trusted wallet whose address starts and ends with familiar characters. After one transfer, an attacker sends a tiny token from a lookalike address with the same first and last characters. Days later, you copy the most recent similar address from history and send CTN to the attacker instead of your trusted wallet.
How attackers make it convincing#
They may:
- Match the first and last characters of an address while changing the middle.
- Send tiny or worthless tokens so the entry appears in recent activity.
- Create a fake transfer that looks like part of your normal history.
- Target wallets that frequently send to the same contacts.
- Use token names that resemble CTN, WCTN, or known projects.
A wallet address is not verified just because it appears in your history.
Checks before sending#
- Use saved contacts or a trusted address book when possible.
- Compare the full address, not only the first and last characters.
- Verify the recipient through a separate channel before large transfers.
- Send a small test amount only when appropriate, remembering that each transfer has a network cost.
- Be cautious with copied addresses from transaction history, explorers, chat messages, or token metadata.
- Stop if the address came from an unexpected airdrop, support message, or claim page.
If you sent to the wrong address#
Confirmed blockchain transfers generally cannot be reversed by CenturionDEX or Centurion Labs. Preserve the transaction hash and address, report the incident through official channels, and warn the intended recipient if their address is being impersonated.