Incident case file
Sign in to watchEthereum Address Poisoning — $100K USDT 82-Day Lookalike Preparation
1 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Ledger
Attacker
Funds moved to
Linked
Chronology
10 beatsAugust 11, 2026, 09:13:47 UTC — A victim lost 100,100 USDT ($100,012.89) to an address poisoning attack that had been prepared over 82 days across three simultaneous layers.
Preparation Layer 1 — Dust (starting May 21, 2026): Attacker sends 416 micro-transactions of 0.001 USDT and 0.0001 USDT to the victim from the lookalike address (0xae7c08af...). This plants the attacker address in the victim's transaction history, making it appear as a known recipient.
Preparation Layer 2 — Zero-value forgery: Attacker submits zero-value transferFrom calls (which require no token approval) that generate outgoing events appearing to come from the victim's own address to three additional lookalike addresses. This simulates the victim having previously sent to these addresses.
Preparation Layer 3 — Counterfeit USDT (June 3, 2026, 07:41–07:58 UTC): Using fake token contract 0x435638...8d159, attacker sends nine transfers of 200,000 fake 'USDT' to the victim (total: 1.8M counterfeit USDT). This makes the lookalike address appear as a high-value trusted counterparty — not a new address, but one the victim has apparently paid 1.8M USDT to.
Attack context: The legitimate counterparty (0xae7c0f...) had received 900,000 real USDT from the victim across 3 prior transactions. The lookalike shares 5 leading and 6 trailing hex characters — grinding cost: ~2^44 keys, 4,096× the standard 4+4 match cost.
09:13:47 UTC, Aug 11, block 25730791: Victim sends 100,100 USDT to the attacker's lookalike address, believing it is the legitimate counterparty. Tx: 0x2add15a3...
09:14:59 UTC (72 seconds later): Attacker approves USDT and routes through Uniswap V3 USDT/WETH UniversalRouter. 52.9090 ETH received across 6 blocks. Tether can freeze USDT but cannot freeze ETH — the swap permanently closes the freeze window.
~13:35 UTC: @CyversAlerts publishes first public alert (tweet 2087172620328243330) — 4 hours 21 minutes after the swap.
~18:17 UTC: @BlockWatchdog publishes detailed forensic analysis (tweet 2087196724175470650) with all addresses, preparation timeline, and 72-second swap window.
As of Aug 11, 15:07 UTC: 52.9091 ETH remains in attacker wallet — immobile at last check. No recovery.
Sources and coverage
- Articlex.comhttps://x.com/CyversAlerts/status/2087172620328243330
- Articlex.comhttps://x.com/BlockWatchdog/status/2087196724175470650
- Articleetherscan.iohttps://etherscan.io/tx/0x2add15a3cc21d794e6b1db9fee32d6c3bbb1a55f7f452135d9f9520a2ae94ece
- Articleetherscan.iohttps://etherscan.io/address/0xae7c08afad91db18666eeac055d7562c9f4e2c85
- Articleetherscan.iohttps://etherscan.io/address/0x9B4Ded0ab7754428F7eC0f63a42bAe70D2f51D83
- Articleambcrypto.comhttps://ambcrypto.com/crypto-address-poisoning-costs-user-100k-usdt-how-the-trap-worked/
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)