YFarmX

Tools Crypto Exploit Tracker exploit-0081

Exploit record

Address Poisoning Attack

Loss
$50M
Attack vector
Phishing
Chain
Ethereum
Sector
Wallet

What happened

On December 20, 2025, a victim lost almost $50M in USDT after copying a poisoned lookalike address from transaction history.

This was pure human-interface exploitation. The attacker exploited how people rely on recent transaction history and glance at the first and last few characters of an address instead of verifying the whole thing. After the victim sent a small test amount, the poisoned address appeared in their history and the main transfer followed. The attacker then started laundering almost immediately through stablecoin swaps and Tornado.

On-chain references

One record from the Crypto Exploit Tracker, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 15 September 2026