The Anatomy of Address Poisoning on Ethereum: Funding Mechanisms, Scam Signatures, and Laundering via Tornado Cash
cs.CR
Submitted: 2026-09-20
Updated: 2026-09-20
Project page: https://berkeley-defi.github.io/assets/material/Tornado%20Cash%20Whitepaper.pdf
License: http://creativecommons.org/licenses/by/4.0/
The gist: Address-Poisoning Transfer (APT) is a prevalent blockchain phishing scam in which a scammer poisons a victim's address book by generating a transfer with a phishing address that looks similar to a
Terminology
Abstract
Address-Poisoning Transfer (APT) is a prevalent blockchain phishing scam in which a scammer poisons a victim's address book by generating a transfer with a phishing address that looks similar to a benign address that the victim has previously interacted with. Although simple, APT phishing attacks have cost users millions of dollars in recent years, which has captured the attention of the research community (Ye et al. WWW'24, Guan-Li CCS'24, Chen et al. NDSS'25, Tsuchiya et al. USENIX'25). In this work, we go beyond detection and investigate three important and underexplored aspects of APT: scam funding mechanisms, scam signatures, and scam proceeds laundering via public services. In particular, we propose five families of scam signatures that capture key aspects of APT operations, which are useful for address clustering. We also conduct the first investigation into usage of Tornado Cash for funding APTs and laundering scam proceeds.
Sources
- Resurrecting Address Clustering in Bitcoin
- Tutela: An Open-Source Tool for Assessing User-Privacy on Ethereum and Tornado Cash
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs