User loses $50 million in USDT due to address poisoning scam
- A crypto user lost $50 million in USDT after falling victim to an address poisoning scam.
- The scam involved a test transaction of $50, which led the user to copy a fraudulent address from their transaction history.
- The attacker sent a small “dust” amount to poison the user’s transaction history, facilitating the error.
- After the theft, the funds were swapped for ETH and moved through multiple wallets, including interactions with Tornado Cash.
- The victim issued an onchain message demanding the return of $49,000,000 within two days or face legal action.
This incident highlights vulnerabilities in user habits, particularly reliance on partial address matching and copy-pasting from transaction histories, rather than technical flaws in blockchain systems.
The victim’s demand for the return of nearly all stolen funds underscores the severity of this exploit that resulted in a loss of $50 million in USDT. (Source)