Crypto Influencer Loses $24 Million in Sophisticated Address-Poisoning Scam
In the fast-moving world of cryptocurrency, major hacks often make headlines. But sometimes the biggest losses don’t happen because of broken technology or hacked systems. Instead, they happen because attackers exploit human habits.
That reality became painfully clear when a crypto influencer known as Sillytuna reportedly lost around $24 million in a carefully planned address-poisoning scam.
The attack shocked the crypto community not only because of the amount stolen but also because it targeted an experienced user. The incident highlights a growing threat in the crypto space where scammers rely on psychological tricks rather than technical vulnerabilities.
According to blockchain security researchers, the stolen funds were quickly converted and moved across different wallets. In the aftermath, Sillytuna claimed the situation escalated beyond digital theft, alleging that threats followed the attack and that police were contacted. The influencer also stated they plan to leave the crypto industry entirely.
What Happened in the $24 Million Crypto Theft
The attack reportedly took place on March 5 and was quickly flagged by blockchain security firms monitoring suspicious transactions.
The victim’s Ethereum wallet address was targeted in what investigators describe as a classic address-poisoning campaign. This type of attack manipulates how users interact with wallet addresses rather than breaking into accounts.
The stolen funds consisted mainly of aEthUSDC, a bridged version of the USDC stablecoin used in decentralized finance.
After gaining control of the funds, the attacker moved quickly. The stolen tokens were first swapped into Ethereum and later converted into approximately $20 million worth of the stablecoin DAI.
Blockchain investigators tracked the funds and discovered they were split across two wallets controlled by the attacker. At the time investigators analyzed the movement, the funds had not yet been sent through cryptocurrency mixing services.
However, analysts noticed small portions of the assets being bridged to the Arbitrum network, which may indicate the attacker is preparing additional steps to hide the money trail.
Researchers also identified several intermediary wallets used as routing points to move the stolen funds more discreetly.
While large crypto hacks are not uncommon, this incident stands out because of the method used and the high-profile victim involved.
What Is an Address-Poisoning Scam?
Address poisoning is a type of scam that targets a very simple habit: copying wallet addresses.
In cryptocurrency transactions, users must send funds to long strings of letters and numbers known as wallet addresses. Because these addresses are difficult to memorize, most people copy and paste them from previous transactions.
Scammers take advantage of this behavior.
Instead of hacking a wallet directly, attackers insert a fake address into a victim’s transaction history and wait for them to accidentally copy it.
When the victim later sends funds using that copied address, the money goes straight to the attacker.
This type of attack does not require access to private keys or passwords. It works purely through deception.
How the Scam Works Step by Step
To understand why address poisoning is so dangerous, it helps to break down the process used by scammers.
Step 1: Creating a Look-Alike Wallet Address
Attackers first generate wallet addresses that resemble legitimate ones the victim has previously used.
Using special tools, they can create addresses that share the same first few characters and last few characters as trusted addresses.
Because most wallets shorten addresses for display, showing only the beginning and end, these fake addresses can appear identical at a quick glance.
Step 2: Sending a Dust Transaction
The attacker then sends a tiny transaction to the victim’s wallet. This is often called a dust transaction because it contains almost no value.
The goal is not to steal money immediately but to place the fake address into the victim’s transaction history.
Step 3: Waiting for the Mistake
Later, when the victim wants to send funds and checks previous transactions for a known address, they may accidentally copy the poisoned address instead of the real one.
Once the transaction is sent, there is no way to reverse it.
The funds immediately belong to the attacker.
Address Poisoning Is Becoming More Common
Security researchers say address-poisoning scams have exploded in recent years.
One study tracking these attacks found that scammers launched more than 270 million poisoning attempts across Ethereum and BNB Chain.
Out of those attempts, around 6,600 resulted in successful thefts, with total losses estimated at roughly $83.8 million.
The attacks are simple to execute, difficult to detect quickly, and can target anyone who regularly transfers cryptocurrency.
Because they rely on human error rather than technical vulnerabilities, even experienced traders can fall victim.
Other Major Cases of Address Poisoning
The Sillytuna incident is far from the first high-value loss linked to this tactic.
In December 2025, a trader reportedly lost about $50 million worth of USDT after copying a poisoned address that had been sitting in their wallet history for months.
Throughout 2024 and 2025, multiple large wallets belonging to DeFi investors, crypto traders, and wealthy “whales” were targeted in similar attacks.
In one coordinated campaign observed by blockchain analysts, funds sent to poisoning scams surged more than 15,000 percent in a short period.
These numbers suggest the strategy is becoming a favorite tool among cybercriminals in the crypto ecosystem.
The Personal Impact on the Victim
Beyond the financial loss, the attack had a personal impact on the victim.
Sillytuna warned followers online about the risks of address-poisoning scams and described the experience as devastating.
According to statements shared publicly, the incident reportedly led to threats that extended beyond the digital world, prompting contact with law enforcement authorities.
Following the event, the influencer announced plans to step away from the cryptocurrency space entirely.
For many observers in the community, the case serves as a reminder that the psychological stress of crypto losses can be as severe as the financial damage.
How Crypto Users Can Protect Themselves
While address-poisoning scams can be sophisticated, there are several practical steps users can take to protect themselves.
Security experts emphasize that awareness and careful transaction habits are the best defense.
Never Copy Addresses From Transaction History
Instead of copying addresses from past transactions, use trusted sources such as saved contacts or verified address books.
Check the Entire Wallet Address
Many users only look at the first and last few characters. Instead, verify the entire address before sending funds.
Send a Test Transaction First
Before transferring large amounts of cryptocurrency, send a small test transaction to confirm the address is correct.
Use Wallet Address Books
Many wallets and exchanges allow users to save verified addresses. Using this feature reduces the chance of copying a malicious address.
Enable Withdrawal Whitelists
Some platforms allow withdrawals only to approved addresses, which can prevent accidental transfers.
Ignore Dust Transactions
If a wallet receives an unexpected small transfer from an unknown address, it is often best to ignore it.
Store Large Holdings in Cold Wallets
Long-term holdings should ideally be stored in cold wallets or hardware wallets that are used less frequently for transactions.
More advanced users also rely on multisignature wallets or hardware confirmation devices to add extra layers of security.
A Reminder About Crypto Security
The $24 million Sillytuna incident highlights a difficult truth about cryptocurrency security.
Many attacks today no longer rely on hacking complex systems. Instead, they exploit everyday habits that users barely think about.
In an industry built around self-custody and personal control of assets, responsibility for security ultimately falls on the user.
As this case demonstrates, even experienced participants can make a single mistake with devastating consequences.
For anyone using cryptocurrency, vigilance remains the most important protection.
