The post ZachXBT goes after Phantom Chat as address poisoning troubles users appeared on BitcoinEthereumNews.com. On-chain investigator ZachXBT warned that an advertisedThe post ZachXBT goes after Phantom Chat as address poisoning troubles users appeared on BitcoinEthereumNews.com. On-chain investigator ZachXBT warned that an advertised

ZachXBT goes after Phantom Chat as address poisoning troubles users

2026/02/10 17:19
Okuma süresi: 4 dk
Bu içerikle ilgili geri bildirim veya endişeleriniz için lütfen crypto.news@mexc.com üzerinden bizimle iletişime geçin.

On-chain investigator ZachXBT warned that an advertised social feature for the Phantom wallet, “Phantom Chat,” is a new method for “investors to get drained.” 

In an announcement made Sunday, multichain wallet Phantom said its new integrated social platform is a messaging tool slated for release in 2026, as part of its evolution of in-wallet interaction.

ZachXBT commented on Phantom’s X post, saying the company has not resolved the scam vector affecting its users, known as “address poisoning.” He cited a recent case in which a victim lost 3.5 wrapped bitcoin after copying a fraudulent address from the transaction history. The loss occurred last week, according to the investigator’s public post.

“A victim lost 3.5 WBTC last week since your UI still does not filter out spam txns users so they accidentally copied the wrong address from recent transactions since the first characters looked similar,” he stated.

The 2D investigator identified the address of the theft was 0x85cB…Af11D8f6, with the transaction hash 0x9f0fc3cd…267a647a4.

How does address poisoning work?

According to wallet provider MetaMask, address poisoning begins by attackers sending victims token transfers worth little or nothing. The purpose of these “useless” transfers is to add vanity addresses to a potential victim’s transaction history. But before they decide which target to go after, they first scan the blockchain for active wallets. 

Vanity addresses are made to match the beginning and ending characters of a target’s address using tools such as Profanity, an open-source wallet address generator. Most users cannot memorize full wallet addresses because they are so long. 

Looking at the two most popular blockchains, Bitcoin addresses have 26-35 characters, while Ethereum-style addresses have 42 characters. Instead of checking every character, a user may slightly glance at the first and last digits, unknowingly copying the wrong address. The perpetrator will purposefully design their spoofed addresses to survive that quick check. 

MetaMask said spoofing crypto addresses is very similar to how hackers use phishing to steal from banking brands. Criminals clone the appearance of institutions such as Wells Fargo to steal credentials, but in crypto, the address itself is the disguise.

ZachXBT shared screenshots of several poisoning victims after an X user questioned why anyone would copy old transactions. He replied, “Convenience (thefts happen way more frequently than you’d expect)”.

Phantom previously tested in-wallet communication through a prediction markets partnership with Kalshi in December, which included a live chat feature. Wallet messaging could allow scammers to impersonate trusted contacts or send malicious links.

“Honestly, my exGF downloaded Phantom when Elon mentioned the companions I sent her like 200 bucks worth of Ani, and she said she got scammed because it went to zero … I assumed she clicked the wrong button somehow but never put the pieces together until now,” another X user complained, reacting to ZachXBT’s findings.

Phantom users struggle with phishing attacks

Last December, a Solana user named Jack reported losing $9,000 through a wallet drainer. Explaining the ordeal to several news outlets, Jack surmised that the incident began with an Instagram advertisement where SOL holders were convinced to enter a promo offering “fast returns,” although the link shared led them to a fraudulent website.

After clicking on the phishing link, he approved an incoming transfer that exposed his wallet to a malicious JavaScript called “SkyDrainer.” The code drained his wallet, and the website vanished from his browser tabs.

The victim later traced the drainer’s promotion, where he found listings on underground forums such as Cracked[.]sh and the Russian site LolzTeam. One forum post advertised “Supreme #1 Solana Drainer,” promoting security bypassing methods, hosting, and cloaking at a 10% operator fee.

Data from blockchain security firm Scam Sniffer shows wallet scams involving address poisoning and signature phishing caused the biggest losses in January. In one case, a single victim lost $12.2 million after copying a poisoned address.

Source: https://www.cryptopolitan.com/zachxbt-phantom-chat-address-poisoning/

Piyasa Fırsatı
Notcoin Logosu
Notcoin Fiyatı(NOT)
$0.0003616
$0.0003616$0.0003616
-3.85%
USD
Notcoin (NOT) Canlı Fiyat Grafiği
Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen crypto.news@mexc.com ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

Ayrıca Şunları da Beğenebilirsiniz

Original Penguin Sues Pudgy Penguins Over Trademark Dispute

Original Penguin Sues Pudgy Penguins Over Trademark Dispute

TLDR Original Penguin sues Pudgy Penguins for alleged trademark misuse. PEI targets crypto brand over penguin-themed apparel and headwear. Lawsuit demands stop
Paylaş
Coincentral2026/03/06 21:09
Exclusive interview with Smokey The Bera, co-founder of Berachain: How the innovative PoL public chain solves the liquidity problem and may be launched in a few months

Exclusive interview with Smokey The Bera, co-founder of Berachain: How the innovative PoL public chain solves the liquidity problem and may be launched in a few months

Recently, PANews interviewed Smokey The Bera, co-founder of Berachain, to unravel the background of the establishment of this anonymous project, Berachain's PoL mechanism, the latest developments, and answered widely concerned topics such as airdrop expectations and new opportunities in the DeFi field.
Paylaş
PANews2024/07/03 13:00
American Manufacturing Has A Private Equity Problem

American Manufacturing Has A Private Equity Problem

The post American Manufacturing Has A Private Equity Problem appeared on BitcoinEthereumNews.com. Private equity would seem to be a natural fit for SME manufacturers’ increasing needs for growth and buyout capital. But there’s a problem. getty Baby Boom owners of small- and medium-sized enterprise manufacturing companies, which comprise about 98% of American industry, are reaching retirement age in droves, with Generation X not far behind. Those without relatives or partners to take over the businesses need to find buyers so they can exit. Private equity investors would seem to be the natural answer. Unfortunately, there exists a critical distrust of PE among industrial owners. Matt Guse is president of MRS Machining in Augusta, Wisconsin, a family-owned machine shop established by his dad in 1986. Author of the new book MRS Machining: A Manufacturing Story, Guse published an article on LinkedIn last week giving one reason for that great level of distrust among owners looking to sell. There’s a gap right now in manufacturing that mostly gets swept under the rug—a real disconnect between buyers and sellers that goes way deeper than price. Almost every week, I hear from private equity firms or buyers circling manufacturing businesses, coming in with their own playbooks. But let’s be honest: most buyers still approach business owners like they’re handing them a favor, tossing out the same tired 2x–4x multiples, assuming owners are desperate to cash out. That attitude misses the point entirely. Manufacturing business owners aren’t just selling off machines and real estate. They’re putting decades of hard work, community, and identity on the line. These are their legacies, not just another transaction to check off a spreadsheet. Treating these deals as cold, purely financial moves ignores everything that actually makes these businesses valuable in the first place. There’s a much deeper level of distrust that dates back about as long as MRS Machining has been…
Paylaş
BitcoinEthereumNews2025/09/18 05:05