Token Approval Scams & Address Poisoning
Token approval scams and address poisoning are among the most technically sophisticated forms of crypto fraud. They exploit how blockchain transactions and wallet interactions work to drain funds or redirect payments — often without the victim noticing until it's too late.

What Are Token Approval Scams?
When you interact with a decentralised application (dApp) or DeFi platform, you're often asked to approve a smart contract to access the tokens in your wallet. This is a standard part of how blockchain transactions work.
A token approval scam occurs when you're tricked into granting unlimited or excessive approval to a malicious smart contract. Once approved, the attacker's contract can drain your wallet of the approved tokens at any time — without any further action required from you.
The approval itself may seem routine. It might appear as part of a fake airdrop claim, a fraudulent DeFi platform, a malicious link on social media, or a transaction on a compromised website. By the time you realise what's happened, your funds may already be gone.
What Is Address Poisoning?
Address poisoning is a separate but equally dangerous attack that exploits a common habit: copying and pasting wallet addresses from transaction history.
In an address poisoning attack, the attacker sends a small or zero-value transaction from an address that looks almost identical to one you've previously transacted with. The goal is to insert their fraudulent address into your transaction history — so the next time you copy a wallet address, you accidentally copy the attacker's instead of the legitimate one.
Because wallet addresses are long strings of characters, most users only check the first and last few digits. Attackers create addresses that match these visible portions exactly, while the middle characters are entirely different. A single moment of inattention can result in sending significant funds directly to the attacker.
How These Attacks Unfold
Token Approval Scam:
You encounter a fake airdrop, a fraudulent DeFi platform, or a suspicious link that prompts you to connect your wallet and approve a transaction. The approval request mimics a legitimate interface. You approve it without realising you've granted unlimited access to your tokens. The attacker's contract drains the approved tokens immediately — or at a later time of their choosing.
Address Poisoning:
The attacker sends a tiny transaction to your wallet from an address that closely resembles one you've previously used. It appears in your transaction history alongside legitimate transactions. The next time you go to send funds, you open your history, glance at the familiar-looking address, and copy it without checking every character. You send funds to the attacker's address. Blockchain transactions are irreversible.
Types of Token Approval Scams
Fake Airdrop Approvals — You're told you've qualified for a free token airdrop but must connect your wallet and approve a transaction to claim it. The approval grants the attacker access to your tokens.
Malicious DeFi Platforms — Fraudulent platforms request unlimited token approvals as part of standard interaction, allowing them to drain your wallet at any time.
NFT Scam Approvals — Malicious NFTs sent to your wallet that, when interacted with, prompt an approval transaction designed to grant access to your other tokens.
Compromised Website Approvals — Legitimate-looking websites that serve malicious approval requests to unsuspecting users.
Unlimited Approval Exploits — Even on legitimate platforms, granting unlimited token approvals rather than transaction-specific ones creates ongoing risk if the platform is later compromised.
Warning Signs
- You're asked to approve a token transaction to claim a free airdrop or reward
- An approval request asks for unlimited or very high token access rather than a specific amount
- You've received a small or zero-value transaction from an address that looks similar to one you've used before
- A wallet address in your transaction history looks familiar but you didn't initiate the transaction
- A dApp is asking for approvals that seem excessive for the service it provides
- You're directed to connect your wallet through a link received via social media, email, or messaging apps
- A smart contract approval request comes from a platform you haven't independently verified
Example — Token Approval: You see a post on social media claiming you've qualified for a token airdrop from a well-known DeFi protocol. You click the link, connect your wallet, and approve a transaction to claim your tokens. Within minutes, your entire token balance is drained. The approval granted the attacker's contract unlimited access to your wallet.
Example — Address Poisoning: You regularly send funds to a business partner using the same wallet address. An attacker sends you a dust transaction from an address with the same first and last four characters as your partner's. The next time you send funds, you copy from your history without checking every character. The funds go to the attacker.
How to Protect Yourself From Token Approval Scams
- Always review approval requests carefully before signing — check exactly what permissions you're granting and to which contract address
- Never grant unlimited approvals unless you fully understand and trust the platform. Set specific approval amounts where possible
- Regularly audit and revoke token approvals using tools such as revoke.cash or etherscan.io
- Only interact with dApps you've independently verified through official channels
- Never approve transactions to claim airdrops or rewards from unsolicited links
- Use a hardware wallet for significant holdings — it adds a critical layer of verification before approvals
How to Protect Yourself From Address Poisoning
- Always verify the complete wallet address before sending funds. Check every single character — not just the first and last few
- Use your wallet's address book rather than copying from transaction history. Save verified addresses directly
- Send a small test transaction before sending a large amount to an address you haven't used recently
- Be suspicious of unsolicited small transactions arriving from addresses that resemble ones you've used before
What Ndax Will Never Do
Ndax will never ask you to approve a smart contract transaction to access your account or funds, send you unsolicited transactions to your personal wallet, direct you to connect your personal wallet to a third-party dApp, or ask you to interact with a smart contract to claim a reward, airdrop, or promotion.
If you receive any request to approve a token transaction or connect your wallet that appears to come from Ndax through any channel other than ndax.io, do not proceed and report it immediately.
Found a Suspicious Approval Request or Address Poisoning Attempt?
Reject the approval request immediately without signing. Don't interact with the suspicious address or any platform that prompted the request. Audit your existing token approvals at revoke.cash and revoke any you don't recognise. Add the legitimate address you intended to use directly to your wallet address book. Report the suspicious contract or address and contact Ndax support if the request appeared to be associated with Ndax.
Already Approved a Malicious Contract or Sent Funds to a Poisoned Address?
Go to a trusted token approval management tool, such as revoke.cash, immediately and revoke permissions granted to the malicious contract. Do not send any further funds to the compromised or suspicious address.
Document everything, including the contract address, wallet address, transaction hash, platform details, screenshots, URLs, and any communications related to the scam.
If you transferred crypto from your Ndax account, contact [email protected] right away. Cryptocurrency transfers are generally irreversible, but the information you provide may help us review the activity and protect other users.
If fiat funds, bank transfers, credit cards, debit cards, or payment services were used, notify the financial institution where the funds originated.
How to Report
- Report to Ndax at [email protected] if your Ndax account was involved or crypto was transferred from your Ndax account
- Report to the CAFC at antifraudcentre.ca
- Report to the RCMP at reportcyberandfraud.canada.ca
- Notify the financial institution where the funds originated, such as your bank, card provider, or payment service provider
- Report the malicious contract or transaction to the relevant blockchain explorer, such as etherscan.io
Don't forget to follow us on social media for more updates and join the conversation on our forums.
Disclaimer: This article is not intended to provide investment, legal, accounting, tax or any other advice and should not be relied on in that or any other regard. The information contained herein is for information purposes only and is not to be construed as an offer or solicitation for the sale or purchase of cryptocurrencies or otherwise.