Criptor

An RSS reader for cryptocurrency news

About
BeInCryptoBeInCryptoBitcoin MagazineBitcoin MagazineCrypto PotatoCrypto PotatoCrypto SlateCrypto SlateThe DefiantThe DefiantForkastForkastProtosProtos
Browse all

Criptor

Your comprehensive RSS reader for all things cryptocurrency. Stay updated with the latest news from around the globe.

Quick Links

  • About
  • Privacy Policy
  • Terms of Service
  • Cookie Policy

Resources

  • Disclaimer
  • Blog
  • Help Center
  • Contact

© 2025 Criptor. All rights reserved.

Built with ♥ for crypto enthusiasts

Home›BeInCrypto›Crypto Trader Suffers $50 million Loss Following Address Poisoning Attack
BeInCrypto

BeInCrypto

Original publisher

Share:

Crypto Trader Suffers $50 million Loss Following Address Poisoning Attack

December 20, 2025
3 min read
Crypto Trader Suffers $50 million Loss Following Address Poisoning Attack

A cryptocurrency trader lost $50 million in Tether’s USDT after falling victim to a sophisticated “address poisoning” attack.

On December 20, blockchain security firm Scam Sniffer reported that the attack began after the victim sent a small $50 test transaction to his own address.

How The Address Poisoning Scheme Unfolded

Notably, traders use this standard precaution to confirm that they are sending funds to the correct address.

However, that activity alerted an automated script controlled by the attacker, which immediately generated a “spoofed” wallet address.

🚨💔 A victim lost ~$50M after copying the wrong address from contaminated transfer history. https://t.co/ur4SJ0cvN0 pic.twitter.com/6K5ftJzC1G

— Scam Sniffer | Web3 Anti-Scam (@realScamSniffer) December 20, 2025

The fake address is designed to match the intended recipient’s address at the beginning and end of the alphanumeric string. The differences appear only in the middle characters, making the fraud difficult to detect at a glance.

The attacker then sent a negligible amount of cryptocurrency from the spoofed address to the victim’s wallet.

That transaction effectively placed the fraudulent address into the victim’s recent transaction history, where many wallet interfaces display only truncated address details.

Relying on that visual shorthand, the victim copied the address from their transaction history without checking the full string. So, instead of transferring funds to a secure personal wallet, the trader sent 49,999,950 USDT directly to the attacker.

After receiving the funds, the malicious attacker quickly moved to limit the risk of asset seizure, according to on-chain records. The attacker immediately swapped the stolen USDT, which its issuer can freeze, for the DAI stablecoin using MetaMask Swap.

Attacker Moves to Obscure Transaction Trail.
Attacker Moves to Obscure Transaction Trail. Source: Slowmist

The attacker then converted the funds into roughly 16,680 ETH.

To further obscure the transaction trail, the attacker deposited the ETH into Tornado Cash. The decentralized mixing service is designed to sever the visible link between sending and receiving addresses.

Victim Offers $1 Million Bounty

In an attempt to recover the assets, the victim sent an on-chain message offering a $1 million white-hat bounty in return for 98% of the stolen funds.

“We have officially filed a criminal case. With the assistance of law enforcement, cybersecurity agencies, and multiple blockchain protocols, we have already gathered substantial and actionable intelligence regarding your activities,” the message stated.

The message warned that the victim would pursue “relentless” legal action if the attacker failed to comply within 48 hours.

“If you fail to comply: We will escalate the matter through legal and international law enforcement channels. Your identity will be uncovered and shared with the appropriate authorities. We will relentlessly pursue criminal and civil action until full justice is served. This is not a request. You are being given one final chance to avoid irreversible consequences,” the victim stated.

The incident underscores a persistent vulnerability in how digital wallets display transaction information and how attackers exploit user behavior rather than flaws in blockchain code.

Security analysts have repeatedly warned that wallet providers’ practice of abbreviating long address strings for usability and design reasons creates a persistent risk.

If this problem is not solved, attackers are likely to continue exploiting users’ tendency to verify only the first and last few characters of an address.

The post Crypto Trader Suffers $50 million Loss Following Address Poisoning Attack appeared first on BeInCrypto.

RELATED TOPICS

addressaddress poisoningvictimlaw enforcementattacktetherrsquos usdtattackercryptocurrency traderblockchaintransactioncriptorfundswalletscam snifferusdtbeincryptotradertrader lostaddress victimrsquosusdt fallinglost tetherrsquostransaction history

More From BeInCrypto

HBAR Price Looks Closely Tried to Bitcoin, What’s Next?

HBAR Price Looks Closely Tried to Bitcoin, What’s Next?

2 hours ago

Cooling Inflation, Weak Confidence: What the Michigan Consumer Data Means for Bitcoin

Cooling Inflation, Weak Confidence: What the Michigan Consumer Data Means for Bitcoin

22 hours ago

3 Altcoins To Watch This Weekend | December 20 - 21

3 Altcoins To Watch This Weekend | December 20 - 21

20 hours ago

View All Articles

Market Overview

BitcoinBitcoin
88,205.510.078%
EthereumEthereum
2,977.26-0.075%
Binance CoinBinance Coin
853.15-0.353%
RippleRipple
1.92130.634%
SolanaSolana
125.88-0.309%

You May Also Like

Will Zcash (ZEC) Price Rally Beyond $500? Here’s What the Charts Say
BeInCrypto

Will Zcash (ZEC) Price Rally Beyond $500? Here’s What the Charts Say

4 hours ago
Crypto Trader Suffers $50 million Loss Following Address Poisoning Attack
BeInCrypto

Crypto Trader Suffers $50 million Loss Following Address Poisoning Attack

5 hours ago
US Dollar Price Annual Forecast: Will 2026 be a Year of Transition?
BeInCrypto

US Dollar Price Annual Forecast: Will 2026 be a Year of Transition?

15 hours ago
Ethereum Developers Plan 'Glamsterdam’ and ‘Hegota’ Upgrades for 2026
BeInCrypto

Ethereum Developers Plan 'Glamsterdam’ and ‘Hegota’ Upgrades for 2026

3 hours ago