Sanctuary Research

In May 2024, an address poisoning attack stole $68 million in a single transaction. The victim copied an address from their transaction history — but it was a fake, planted there by an attacker.
Most wallet interfaces truncate addresses, showing only the first 6 and last 4 characters. The attack exploits this UI pattern — if the start and end match, users assume it is the same address.
Address poisoning is not rare. Millions of dust transactions are sent daily across EVM chains and TRON. Most go unnoticed because the amounts are tiny ($0.01 or less). But each one plants a trap.
AML screening tools can flag address poisoning in two ways:
When you screen an address and see a dust attack pattern in the results, that is your early warning system.
---
Sanctuary detects dust attacks and address poisoning patterns automatically. Check any address free.