← Radar

Incident case file

Sign in to watch

Ethereum Address Poisoning — $100K USDT 82-Day Lookalike Preparation

Incident date 2026-08-10Last updated Aug 20, 2026

1 views

ActiveEthereum L1Social engineering — Address poisoning (82-day lookalike preparation)Cluster: APO-PHI-2026-08

Estimated loss

$100.0K

Victims identified

1
Victim group joining is coming soon.

Investigation

75%

Facts and investigation

Ledger

Attacker

0xae7c08afad91db18666eeac055d7562c9f4e2c85 (labeled Fake_Phishing3121369 on Etherscan — confirmed). Lookalike of legitimate counterparty: 0xae7c0ffab6e77be2d7d7880a4ce433f59a4e2c85. Grinding effort: 16^11 ≈ 2^44 keys (5 leading + 6 trailing hex chars matched — 4,096× the cost of a standard 4+4 attack). Fake USDT token contract used in preparation: 0x435638925879ab8fc2ee874d123fc1b01ce8d159.

Funds moved to

100,100 USDT ($100,012.89) received by attacker at 09:13:47 UTC. 72 seconds later (09:14:59 UTC): attacker approves USDT and routes through Uniswap V3 USDT/WETH pool via UniversalRouter → 52.9090 ETH received across 6 blocks. Tether freeze window closed before first public alert (alert came 4h 21min after swap). 52.9091 ETH sitting in attacker wallet 0xae7c08af... as of Aug 11 15:07 UTC — immobile at time of last confirmed check.

Linked

Victim: 0x9B4Ded0ab7754428F7eC0f63a42bAe70D2f51D83 (confirmed Etherscan) | Attacker: 0xae7c08afad91db18666eeac055d7562c9f4e2c85 (confirmed Etherscan — Fake_Phishing3121369 label) | Exploit tx (victim → attacker USDT): 0x2add15a3cc21d794e6b1db9fee32d6c3bbb1a55f7f452135d9f9520a2ae94ece (block 25730791, 09:13:47 UTC — confirmed Etherscan) | Fake token contract (200K 'USDT' preparation): 0x435638925879ab8fc2ee874d123fc1b01ce8d159 | Legitimate counterparty being impersonated: 0xae7c0ffab6e77be2

Chronology

10 beats
  1. August 11, 2026, 09:13:47 UTC — A victim lost 100,100 USDT ($100,012.89) to an address poisoning attack that had been prepared over 82 days across three simultaneous layers.

  2. Preparation Layer 1 — Dust (starting May 21, 2026): Attacker sends 416 micro-transactions of 0.001 USDT and 0.0001 USDT to the victim from the lookalike address (0xae7c08af...). This plants the attacker address in the victim's transaction history, making it appear as a known recipient.

  3. Preparation Layer 2 — Zero-value forgery: Attacker submits zero-value transferFrom calls (which require no token approval) that generate outgoing events appearing to come from the victim's own address to three additional lookalike addresses. This simulates the victim having previously sent to these addresses.

  4. Preparation Layer 3 — Counterfeit USDT (June 3, 2026, 07:41–07:58 UTC): Using fake token contract 0x435638...8d159, attacker sends nine transfers of 200,000 fake 'USDT' to the victim (total: 1.8M counterfeit USDT). This makes the lookalike address appear as a high-value trusted counterparty — not a new address, but one the victim has apparently paid 1.8M USDT to.

  5. Attack context: The legitimate counterparty (0xae7c0f...) had received 900,000 real USDT from the victim across 3 prior transactions. The lookalike shares 5 leading and 6 trailing hex characters — grinding cost: ~2^44 keys, 4,096× the standard 4+4 match cost.

  6. 09:13:47 UTC, Aug 11, block 25730791: Victim sends 100,100 USDT to the attacker's lookalike address, believing it is the legitimate counterparty. Tx: 0x2add15a3...

  7. 09:14:59 UTC (72 seconds later): Attacker approves USDT and routes through Uniswap V3 USDT/WETH UniversalRouter. 52.9090 ETH received across 6 blocks. Tether can freeze USDT but cannot freeze ETH — the swap permanently closes the freeze window.

  8. ~13:35 UTC: @CyversAlerts publishes first public alert (tweet 2087172620328243330) — 4 hours 21 minutes after the swap.

  9. ~18:17 UTC: @BlockWatchdog publishes detailed forensic analysis (tweet 2087196724175470650) with all addresses, preparation timeline, and 72-second swap window.

  10. As of Aug 11, 15:07 UTC: 52.9091 ETH remains in attacker wallet — immobile at last check. No recovery.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)