A single address poisoning operator has drained about $9.4 million from 15 victims on the Tron network over the past four weeks, using fake wallet addresses designed to look like ones the victims had previously used.
The stolen assets were quickly converted into USDD, a Tron-based stablecoin, before being sent to a single consolidation wallet, according to on-chain investigator Specter.
One Operator Drained $9.4 Million From 15 Tron Users
Specter, who posts on X as SpecterAnalyst, disclosed the losses on 27 August 2026.
The two largest victims each lost $2.5 million, while another victim lost about $2 million.
After the funds were taken, the attacker converted the stolen assets into USDD and moved them to one main wallet, where the funds remain.
Specter has called on wallet providers in the Tron ecosystem to introduce stronger measures to detect and block address poisoning attacks.
How Address Poisoning Tricks Users Into Sending Money
The scam relies on a small transaction that can be easy to overlook.
According to analyst Stacy Muur, the attacker first sends a tiny amount of crypto from a fraudulent address that closely resembles a legitimate address previously used by the victim.
These small transfers are known as dust transactions.
Because blockchain addresses contain long strings of letters and numbers, users often identify wallets by checking only the first and last few characters shown by their wallets.
That creates an opening for scammers.
If a victim later copies an address from their transaction history without checking the full address, they may unknowingly select the attacker's lookalike wallet.
The victim then sends the intended payment directly to the scammer.
Bofur Capital Lost About $2 Million In A Similar Attack
The same technique was used against Bofur Capital on 22 August 2026, resulting in a loss of around $2 million.
In that case, the attacker sent 0.0002 USDC from a fake address roughly 20 hours before the genuine transfer took place.
When Bofur withdrew funds from the lending platform Compound, the firm copied the fraudulent address from its transaction history and sent the funds to the attacker.
The stolen USDC was subsequently exchanged for DAI, apparently to reduce the risk of the assets being frozen.
Can Wallets Stop Address Poisoning On Tron?
Some major wallets have already introduced protections against address poisoning, although their coverage is mainly focused on EVM-compatible networks such as Ethereum, BNB Smart Chain and Polygon rather than Tron.
MetaMask now warns users when an address has the same first and last four characters as a previous recipient but differs in the middle.
Trust Wallet introduced its Address Poisoning Protection feature in March, checking addresses against a database of known scam wallets and displaying a comparison when a suspected match is found.
The recent Tron attacks show why similar safeguards could be important for users holding or transferring large amounts on the network.
Users are also advised to verify the complete recipient address, use saved trusted contacts where possible and send a small test transaction before transferring large sums.