GoPlus Security: A user lost approximately 305,000 USD DAI due to an address poisoning attack
According to GoPlus Security monitoring, a user lost approximately $305,000 DAI due to an "address poisoning" attack. The attacker generated fake addresses that matched the prefix and suffix of the victim's expected transfer address, sending small "dust" amounts to the victim to lure the user into mistakenly copying the fake address from their transaction history.
GoPlus Security reminds users that such attacks have become fully automated, including target discovery, address forgery, and laundering through mixers. Users should never copy addresses directly from their transaction history; they must verify the complete address and conduct small tests before making large transfers.