The practice of "address poisoning" in the Ethereum network is becoming widespread. Following the Fusaka upgrade, the number of "dust" transactions involving USDT surged by 612%, according to data from Etherscan. 

https://t.co/SBZoEtLqM0

— etherscan.eth (@etherscan) March 12, 2026

The reduction in network fees due to the upgrade has triggered a new wave of fraudulent activity. Malicious actors are sending millions of zero-value microtransactions to clutter the transaction history in victims' wallets. 

Their main goal is to trick users into copying a fake address from their recent transactions.

Source: X/Etherscan. 

In the 90 days following the activation of the upgrade on December 3, 2025, the number of "dust" transactions—those involving amounts less than $0.01—skyrocketed compared to the same period before the upgrade: 

  • USDT: +612% (from 4.2 million to 29.9 million);
  • USDC: +473% (from 2.6 million to 14.9 million);
  • DAI: +470% (from 142,000 to 811,000);
  • ETH: +62% (from 104.5 million to 169.7 million). 

Meanwhile, the number of regular transactions above $0.01 remained stable, indicating a spike in fraudulent activity rather than organic growth in the network.

How It Works 

Fraudsters monitor large transfers on the blockchain. Automated systems generate duplicate addresses that mimic the first and last characters of addresses recently interacted with by the victim. 

Then, the scammers send "dust" transactions to ensure the fake address appears in the transaction history. They hope the victim will mistakenly copy the fake details and send funds to it.

Sometimes, multiple hacker groups compete to "poison" a wallet. One of the screenshots from Etherscan shows that within minutes of a legitimate USDT transfer, up to 13 fake transactions from different attackers appear in the victim's transaction history.

Source: X/Etherscan. 

Analysts also noted a complaint from a user named Nima. He reported receiving over 89 emails alerting him to activity on his address after sending two stablecoin transfers.

Address poisoning attacks are getting out of hand. I just sent two stablecoin transactions and received +89 emails from my Etherscan address watch alert notifications.

It took them <30 mins to create all of these on mainnet.

So many will fall victim to this. pic.twitter.com/H1nGaMMprE

— Nima 👁️ (@0xNimaRa) February 13, 2026

The Scale of the Problem

From July 2022 to June 2024, experts from Blockchain Address Poisoning recorded around 17 million attempts to deceive users through address substitution. Approximately 1.3 million individuals were targeted, with total losses exceeding $79 million.

The issue is more acute in networks with lower fees. For instance, on Binance Smart Chain, the number of fake transfers is 1355% higher than on Ethereum.

Source: X/Etherscan. 

Only a small fraction of attacks—about 0.01%—are successful. However, the sheer volume of these attempts makes the scheme highly profitable.

“Instead of targeting individual addresses, campaigns often send out thousands or even millions of fake transfers. With enough attempts, even a tiny success rate can yield significant profits,” Etherscan noted. 

It’s worth noting that in December 2025, an investor lost nearly $50 million due to an address poisoning attack. Binance founder Changpeng Zhao proposed additional security measures to "eradicate" this practice.