Binance unveils algorithm to combat spoofing
The new mechanism has already made it possible to calculate over tens of millions of fraudulent addresses
16.05.2024 - 14:42
585
2 min
0
Last updated on Aug 5, 2024
What’s new? Security experts at Binance, the largest centralized crypto exchange (CEX), have developed an algorithm to protect against address poisoning/address spoofing fraud. In this method, also known as spoofing, scammers send small amounts of digital assets to potential victims’ wallets from addresses with similar characters. Such a transaction, like any other, is recorded in the transaction history, and the next time the victim may inadvertently copy the scammer’s address from the history and send him the funds.
What else is known? Binance’s algorithm detects scammers by identifying suspicious transfers with near-zero value or unknown tokens, and matching sender addresses with those of potential victims. It then marks malicious transactions by time of execution to find a potential point of “poisoning.”
The scammers’ spoofing addresses are logged into Binance’s IS partner HashDit’s database, which can be used by other crypto projects to protect their users.
For example, many firms use the HashDit API to protect against various types of fraud, including the crypto wallet Trust Wallet, which notifies users when they are about to transfer funds to a spoofed address. The algorithm will also track fraudulent addresses in web browser extensions and MetaMask Snaps apps.
The exchange team said that the new algorithm has already helped detect over 13,4 million spoofing addresses on the BNB blockchain and over 1,68 million on the Ethereum blockchain.
The Binance algorithm was introduced shortly after a major incident involving this scheme. Thus, on May 3, an unknown trader lost $68 million in wBTC by sending it to a spoofing address. After 10 days, the fraudster returned the funds, probably fearing de-anonymization, as blockchain analysts were actively seeking to establish his identity.
This type of fraud is designed for inattention: most traders only check the first and last characters in the wallet address, which contains 42 characters. In addition, the interfaces of most platforms do not display addresses in their entirety without additional clicks.
In addition, scammers use vanity address generators to set some of the address characters themselves and make it look like the address of a potential victim or her counterparty.
Useful material?
Incidents
The company is linking the incident to a compromised private key on a service wallet, rather than a smart contract exploit
May 22, 2026
Incidents
Following the incident, the project temporarily halted trading operations and node activity.
May 15, 2026
Incidents
The user spent weeks unsuccessfully trying to guess the password until Claude helped find an old wallet backup file
May 14, 2026
Crypto regulations
Authorities are introducing mandatory registration for companies handling cross-border crypto transactions
May 8, 2026
Incidents
According to Blockaid, the attack may have been carried out by the same hacker behind the 1inch Fusion V1 exploit.
May 7, 2026
Incidents
The attacker gained administrative access and altered contracts to drain user funds
Apr 30, 2026
Telegram
Twitter