Ethereum Crypto Wallets under Address Poisoning: How Usable and Secure Are They?
Shixuan Guan, Kai Li

TL;DR
This study systematically evaluates the usability and security of 53 popular Ethereum wallets against address poisoning attacks, revealing significant vulnerabilities and gaps in phishing detection and user warnings.
Contribution
It provides the first comprehensive assessment of Ethereum wallets' defenses against address poisoning, highlighting critical security flaws and areas for improvement.
Findings
12 wallets cannot download transaction history due to communication failures.
16 wallets display fake token phishing transfers, posing high risks.
Only 3 wallets warn users about phishing addresses during transfers.
Abstract
Blockchain address poisoning is an emerging phishing attack that crafts "similar-looking" transfer records in the victim's transaction history, which aims to deceive victims and lure them into mistakenly transferring funds to the attacker. Recent works have shown that millions of Ethereum users were targeted and lost over 100 million US dollars. Ethereum crypto wallets, serving users in browsing transaction history and initiating transactions to transfer funds, play a central role in deploying countermeasures to mitigate the address poisoning attack. However, whether they have done so remains an open question. To fill the research void, in this paper, we design experiments to simulate address poisoning attacks and systematically evaluate the usability and security of 53 popular Ethereum crypto wallets. Our evaluation shows that there exist communication failures between 12 wallets and…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsDigital and Cyber Forensics · Advanced Malware Detection Techniques · Information and Cyber Security
