Binance co-founder, Changpeng Zhao (CZ), published a blog post this Wednesday, December 24, saying that crypto wallets need to take a more active role in stopping poisoning scams.
Address poisoning is one of the most damaging phishing tactics in crypto, and it is drawing renewed attention from industry leaders as losses continue to pile up. The scam does not rely on breaking protocols or targeting exploits in smart contracts. Instead, it targets wallet interfaces and user habits, essentially exploiting the way people copy and reuse addresses.
In his blog post, Zhao argued: “Our industry should be able to completely eradicate this type of poison attacks, and protect our users.”
He said that wallets need to take a more active role in stopping these attacks before funds are sent. “All wallets should simply check if a receiving address is a “poison address”, and block the user. This is a blockchain query.”
CZ further noted that spam transactions with negligible value should be hidden from wallet histories entirely.
The way address poisoning works is fairly simple. Bad actors send small transactions from addresses that were crafted to resemble legitimate ones. So, when users later copy an address from their transaction history, they will often check only the first and last characters. In doing so, they can easily mistake the real address with the one created by the attacker, and send their funds to the scammer.
Address Poisoning Is Becoming A Priority Threat
It is worth noting that the fault does not lie with the blockchain – the flaw happens at the interface. Zhao also said that security alliances in the industry should maintain a real-time blacklist of these addresses, so that wallets can check before they send a transaction.
He said that Binance Wallet already does this, and users receive a warning if they try to send to a poison address.
Zhao’s decision to address the situation comes at a time when the financial impact has already grown quite quickly. Phishing scams drained over $7.7 million from 6,344 victims in November alone, and December losses are expected to be even higher after a single address poisoning incident led to around $50 million in USDT being transferred out of one wallet.
Incidents like that clearly show why address poisoning is becoming a priority threat, as these scams can scale easily, unlike more complex exploits.
Attackers can simply create thousands of lookalike transactions across wallets at low cost, and just wait for a single mistake to make it all worth the effort. Zhao’s recommendations focus on preventing the matter, rather than recovery from such incidents.

