The attack costs the attacker almost nothing. They create an address whose first and last characters match an address you have used, send you a transfer of nothing — or of dust — from it, and wait. Later you copy an address out of your own history, check the first four and last four characters as most people do, and pay the attacker.
What Smartable does
- In your history, a transfer that arrived carrying nothing from an address you have never used is marked as a planted lookalike.
- Before you send, the recipient is compared with every address you have paid and every address in your address book. If it imitates one of them, the review says This address imitates one you have paid and shows both, so you can see the difference.
- A new recipient is marked First time sending here, with a reminder to check every character.
- The address book refuses to save an address that imitates one you have already paid or named.
These checks catch the common pattern. They cannot know which address you meant, so the habits below still matter.
What to do
- Never copy a recipient out of your transaction history. History records who sent to you, and anybody can send to you.
- Keep regular recipients in the address book. Save each address once, from a source you trust, and choose it by name after that.
- Check the whole address, or at least its middle — the part these attacks do not match.
- Send a small test amount when the sum is large and the recipient is new.
A transfer you did not ask for does not need an answer. Leave it where it is.
What the app shows
- “This arrived carrying nothing, from an address you have never used. That is how a lookalike address is planted in your history. Never pay it.”
- “This address imitates one you have paid”
- “First time sending here”
Security note
Never share your recovery phrase, private key, password or device PIN. Smartable will never ask for them or ask you to sign a transaction to “verify” or “recover” your wallet.
Related