Bofur Capital loses about $2 million in address-poisoning attack
A dust transaction preceded the transfer, according to a report citing PeckShield, in another reminder that copied wallet addresses can be weaponized against active DeFi users.
By The Third AnglePublished 3 min read
Illustrative digital-security imagery; it does not depict Bofur Capital or the reported transaction. Photo: Unsplash · Unsplash License
An address labeled Bofur Capital lost about $2 million in what a current CoinNess report described as an address-poisoning attack attributed to monitoring by PeckShield. The incident followed a withdrawal from Compound, and the report said the stolen funds were later exchanged for roughly 2 million DAI.
The report said the attacker first sent a dust transaction of 0.0002 USDC to create a lookalike address in the victim's transaction history. The victim then copied the wrong address and transferred the funds to it. The exact wallet attribution and loss figure remain based on the security firm's monitoring rather than a public statement from Bofur Capital.
Why address poisoning works
Address poisoning exploits a routine habit: using the first and last characters of a wallet address to recognize a counterparty, then copying a recent transaction instead of comparing the full address. An attacker can send a tiny transfer from an address designed to resemble one the victim has used before.
The dust transfer is not the theft itself. It is a social-engineering marker that tries to place the attacker's address where the victim expects to find a trusted one. Once a larger transfer is signed, the blockchain generally does not provide a reversal mechanism.
The practical check
Users moving funds from DeFi protocols should compare the complete destination address, use a previously verified address book or hardware-wallet contact, and send a small test transaction when the amount and context justify it. A recent incoming dust transfer is not evidence that its sender is the intended recipient.
The Bofur report does not establish whether any funds can be recovered or whether the attacker has been identified. It does establish the user-side failure mode: a tiny transaction can make a malicious address look familiar at the moment a much larger transfer is made.