Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

Bitcoin miners' AI pivot faces $50 billion reality check, says VanEck

June 17, 2026

Grayscale Analysis Pegs AAVE as Undervalued, Sets $175 Bull Case Target

June 17, 2026

AAVE Price Prediction: $80 Is the Line in the Sand — Break It or Break Down

June 17, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»ZachXBT calls out Phantom Chat over address poisoning issue
Security

ZachXBT calls out Phantom Chat over address poisoning issue

February 10, 2026No Comments4 Mins Read

On-chain investigator ZachXBT warned that an advertised social feature for the Phantom wallet, “Phantom Chat,” is a new method for “investors to get drained.”

In an announcement made Sunday, multichain wallet Phantom said its new integrated social platform is a messaging tool slated for release in 2026, as part of its evolution of in-wallet interaction.

ZachXBT commented on Phantom’s X post, saying the company has not resolved the scam vector affecting its users, known as “address poisoning.” He cited a recent case in which a victim lost 3.5 wrapped bitcoin after copying a fraudulent address from the transaction history. The loss occurred last week, according to the investigator’s public post.

“A victim lost 3.5 WBTC last week since your UI still does not filter out spam txns users so they accidentally copied the wrong address from recent transactions since the first characters looked similar,” he stated.

The 2D investigator identified the address of the theft was 0x85cB…Af11D8f6, with the transaction hash 0x9f0fc3cd…267a647a4.

How does address poisoning work?

According to wallet provider MetaMask, address poisoning begins by attackers sending victims token transfers worth little or nothing. The purpose of these “useless” transfers is to add vanity addresses to a potential victim’s transaction history. But before they decide which target to go after, they first scan the blockchain for active wallets.

Vanity addresses are made to match the beginning and ending characters of a target’s address using tools such as Profanity, an open-source wallet address generator. Most users cannot memorize full wallet addresses because they are so long.

See also  Kalshi co-founder fights back against Arizona’s ‘overstep’ in what a lawyer calls a federal-state turf war

Looking at the two most popular blockchains, Bitcoin addresses have 26-35 characters, while Ethereum-style addresses have 42 characters. Instead of checking every character, a user may slightly glance at the first and last digits, unknowingly copying the wrong address. The perpetrator will purposefully design their spoofed addresses to survive that quick check.

bro i had the same issue. I was transferring my $SOL to USDC now it stuck up with this fucking wallet.
EVDheTpoa43cSgAv544qmtodriLmoV1asre5PSsPw8DT
It happened twice.
Never gonna use this fucking app again. @phantom pic.twitter.com/rubw0JhJ1k

— Kill4h (@cryptokill4h) February 10, 2026

MetaMask said spoofing crypto addresses is very similar to how hackers use phishing to steal from banking brands. Criminals clone the appearance of institutions such as Wells Fargo to steal credentials, but in crypto, the address itself is the disguise.

ZachXBT shared screenshots of several poisoning victims after an X user questioned why anyone would copy old transactions. He replied, “Convenience (thefts happen way more frequently than you’d expect)”.

Phantom previously tested in-wallet communication through a prediction markets partnership with Kalshi in December, which included a live chat feature. Wallet messaging could allow scammers to impersonate trusted contacts or send malicious links.

“Honestly, my exGF downloaded Phantom when Elon mentioned the companions I sent her like 200 bucks worth of Ani, and she said she got scammed because it went to zero … I assumed she clicked the wrong button somehow but never put the pieces together until now,” another X user complained, reacting to ZachXBT’s findings.

Phantom users struggle with phishing attacks

Last December, a Solana user named Jack reported losing $9,000 through a wallet drainer. Explaining the ordeal to several news outlets, Jack surmised that the incident began with an Instagram advertisement where $SOL holders were convinced to enter a promo offering “fast returns,” although the link shared led them to a fraudulent website.

See also  ZachXBT Accuses Tokenlon of Handling Illicit Crypto Funds

After clicking on the phishing link, he approved an incoming transfer that exposed his wallet to a malicious JavaScript called “SkyDrainer.” The code drained his wallet, and the website vanished from his browser tabs.

The victim later traced the drainer’s promotion, where he found listings on underground forums such as Cracked[.]sh and the Russian site LolzTeam. One forum post advertised “Supreme #1 Solana Drainer,” promoting security bypassing methods, hosting, and cloaking at a 10% operator fee.

Data from blockchain security firm Scam Sniffer shows wallet scams involving address poisoning and signature phishing caused the biggest losses in January. In one case, a single victim lost $12.2 million after copying a poisoned address.



Source link

Address Calls Chat issue Phantom poisoning ZachXBT

Related Posts

India’s NHRC Raises Alarm Over Digital Arrest Scams

June 16, 2026

Rokarolla Trojan Combines Banking Fraud With Device Surveillance

June 16, 2026

Pyra to Cease Operations Following Drift Hack, Launches Fund Withdrawal Portal

June 16, 2026

Oklahoma Raises Alarm Over Fake Crypto Returns

June 16, 2026
Top Posts

Veda brings the vault stack behind Kraken DeFi Earn to Privy’s 2,000-plus developer teams

June 2, 2026

Bitcoin miners saw the AI power crunch coming — and the nuclear revival

March 13, 2026

Catching Up on a Lot of Stuff

October 26, 2023

Type above and press Enter to search. Press Esc to cancel.