How a single copy-paste mistake cost a user $50M in USDt
Summary
A user recently suffered a loss of approximately $50 million in USDt after mistakenly sending the funds to a malicious, look-alike wallet address inserted into their transaction history via an address poisoning attack. The victim first sent a small test transaction to the correct address, but minutes later, sent the full amount to the poisoned address, which shared the same first three and last four characters as the intended recipient, fooling even experienced users. Security experts noted this attack exploits human habits rather than system vulnerabilities. The attacker has since converted the stolen USDt into Ether, fragmented it across multiple wallets, and partially moved funds through Tornado Cash.
(Source:Cointelegraph)