In a chilling incident, an Ethereum holder has lost approximately $12.3 million in a cunning address poisoning attack. The incident was detected and reported by Cyvers, a leading Web3 security firm, highlighting the ongoing threats to digital asset users. The incident h as sent shockwaves in the whole crypto community. Cyvers urged users to enhance their security measures.
🚨ALERT🚨Our systems detected a $12.3M ETH address poisoning attack approximately more than one hour ago.
The victim was initially poisoned 37 hours earlier. Today, when attempting to send funds to
0x6D90CC8C…7eDdD2E48, the victim instead sent the transaction to the malicious… pic.twitter.com/zUN3N5GMvG— 🚨 Cyvers Alerts 🚨 (@CyversAlerts) January 30, 2026
Details of the Ethereum Wallet Incident
According to Cyvers Alerts, the attack was identified more than an hour after it occurred, with the victim’s wallet being initially “poisoned” 37 hours prior. The scam involved the attacker creating a fake wallet address that closely resembled one the victim intended to use. When attempting to transfer funds to the legitimate address 0x6D90CC8C…7eDdD2E48, the victim inadvertently sent 4,556 ETH to the malicious look-alike address 0x6d9052b2…34e592e48.

What is Address Poisoning?
Address poisoning is a deceptive tactic where scammers send small, unsolicited transactions to a target’s wallet from an address designed to mimic legitimate ones in the victim’s transaction history. This poisons the history, tricking users into copying and pasting the wrong address during future transfers. The similarity between the addresses, often relying on visual confusion with hexadecimal characters, led to the catastrophic error.
The transaction hash associated with the exploit is 0x7acade9d4731a6…b72cd66817a8ac7, resulting in the attacker gaining control of ETH valued at over $12.3 million based on current market prices around $2,700 per ETH. Cyvers’ dashboard screenshot, shared in their alert, shows the attacker address as 0x6909052b2…4e592e48 and the victim as 0xd6741220…Bae4a7da. Clear balance changes confirm the transfer.
How to Avoid Address Poisoning Attacks?
This incident adds to a growing list of address poisoning scams, which have plagued the crypto ecosystem. Experts recommend always double-check addresses manually. It is also recommended to use hardware wallets with address verification features. Moreover, it is better to enable transaction simulations or alerts from security tools like those offered by Cyvers.
As Ethereum continues to dominate decentralized finance DeFi, such exploits serve as a stark warning. In the world of blockchain, where transactions are irreversible, caution is the ultimate currency. Users are advised to stay vigilant and leverage advanced monitoring systems to protect their assets.

