Someone generates an address whose first and last characters match one you send to regularly, then sends you a worthless transaction so it appears in your history. Next time you copy from your own transaction list, you copy theirs. This compares full addresses and shows exactly where they differ.
The attack this catches. Someone watches your wallet, generates an address whose first and last characters match one you send to regularly, and sends you a worthless transaction from it. It then sits in your history looking familiar. Next time you copy an address from your own transaction list, you copy theirs.
It works because wallets abbreviate addresses to the first and last few characters, and those are exactly the parts the attacker matched. Everything you paste here stays on your device.
Every wallet shows addresses shortened, something like 0x71C7…976F. Two addresses can share those visible characters and be entirely different, and generating a match for a given prefix and suffix is cheap. The characters in the middle, which no interface shows you, are the ones that differ.
This compares full addresses character by character and shows you exactly where they diverge. If two addresses look identical when abbreviated and differ in the middle, one of them was made to be mistaken for the other.
It is gone. A confirmed transaction cannot be reversed and the recipient has no obligation, or usually any interest, in returning it. Anyone who contacts you afterwards offering recovery is running a second scam, which the recovery scam checker covers. What is worth doing is removing the poisoned entries from your habits: clear the address book, stop copying from history, and treat every future paste as needing verification.
An attacker watches your wallet, generates an address whose first and last characters match one you send to regularly, and sends you a zero value or dust transaction from it. That entry then sits in your transaction history looking familiar. The next time you go to send and copy an address from your own history, you copy theirs. It works because wallets abbreviate addresses to the first and last few characters, and those are precisely the parts that were matched.
They do not, in full. They look the same abbreviated. Your wallet shows something like 0x71C7…976F, and generating an address matching a given prefix and suffix is computationally cheap. The characters in the middle differ, and the middle is the part no interface shows you. That is why this tool aligns the full addresses and colours every character that differs.
No. A confirmed transaction cannot be reversed, and the recipient has no obligation and usually no interest in returning it. If the address belongs to an exchange there is a very small chance their support can help, which is worth trying and worth not expecting. Anyone who contacts you afterwards offering to recover it is running a second scam.
One habit fixes almost all of it: never copy an address from your transaction history. Use your wallet\u2019s address book, add entries once from a verified source, and send from there. For any large transfer, send a small test first and confirm it arrived before sending the rest.
No. The comparison runs entirely in your browser. Nothing is transmitted, stored or logged, which matters here more than on most pages because you are pasting addresses you have used. You can disconnect from the internet and it will still work.
We seal the list every week and keep re-checking every token on it, so you can see what actually happened to them rather than only what is trading today.