Address Poisoning on TRON
A tiny, almost worthless transaction lands in your history from an address that looks nearly identical to one you've genuinely used before — and it's there to trick your next copy-paste.
How the lookalike gets planted
An attacker generates an address that shares the same first and last few characters as an address you've previously sent to or received from, then sends you a near-zero-value transaction from it. It now sits in your transaction history, visually almost indistinguishable from the real one at a glance.
Where the mistake happens
The attack only works if you later copy an address from your history instead of your actual saved contacts or the recipient's real receive screen. A quick glance at the first and last characters isn't enough — poisoned addresses are built specifically to pass that check.
How to avoid it
Always copy addresses from a verified source — your own saved address book or the recipient's current receive screen — never from transaction history. For large transfers, verify the full address, not just the ends, or confirm it with the recipient through a separate channel.