In the latest Crypto Hack News, security firm PeckShield flagged a wallet labeled Bofur Capital for losing $2 million in an address poisoning attack right after a withdrawal from Compound.

Source: information cover by wublockchain12
A follow-up investigation later found something unusual—the same controller behind the theft ended up dusting its own wallet minutes after moving the stolen funds.
PeckShield reported that the attacker sent a tiny 0.0002 USDC dust transaction designed to mimic a real payee entry already saved in the victim's transaction history.
The victim then copied that lookalike entry crypto wallet scam for a large transfer instead of the correct one, sending 2 million USDC straight to the scammer.
Key details from this stage include:
A 0.0002 USDC dust transaction was used to spoof a trusted entry.
The victim ran a recurring $2 million payment funded by Compound withdrawals.
The same scam pattern had already been attempted once in July without success.
The stolen funds were swapped through CoW Protocol into roughly 1.999 million DAI.

Source: PeckShieldAlert on X
Investigators found the forged entries were created using homoglyph token contracts — fake tokens using Cyrillic characters and invisible symbols designed to look identical to real USDC in a wallet's transaction list.
One contract, deployed August 19, pushed 320 transactions in 60 hours, generating close to 89,000 forged history entries across many fake token contracts at once.
This is what let three separate lookalike entries appear in the victim's history well before the real theft happened.

Source: BlockWatchdog on X
Three separate operations targeted this same victim in August, each using entries that closely matched the real payee through matching prefix and suffix characters.
Two of these lookalikes were never funded and existed only as destinations for zero-value transfer calls.
The one that finally succeeded was the only entry that had moved a small non-zero balance — just 0.0002 USDC — which made it appear active and trustworthy enough to be mistaken for the real one.
Roughly 13 minutes after the stolen DAI was parked, the same controller that funded the original theft address ran its identical dust pattern against its own holding account—sending 0.0008 to a freshly mined look-alike, which then relayed 0.0002 to the target.
This is exact routine used on the original victim, just pointed inward this time.
Records show the controller has sent over 126,000 dust transfers to more than 80,000 distinct addresses since late May, with the vast majority used only once, suggesting a large-scale automated sweeping operation rather than a single targeted attack.
Wallet | Role |
0x7ba7f4773fa7890bad57879f0a1faa0edffb3520 | Victim |
0xf0e67a1896e814e30c011e36174de28caa9ab1af | Real payee |
0xf0e6a49668de1195b931a3717c9cc36fc19721af | Spoofed entry used in theft |
0x692729bcd0887b8d02b8ff3169220ba0f4e17251 | Swap account holding stolen funds |
0xe2ebfd6f329a6330ab7eee68ce1328c21d31816a | Final DAI storage entry |
0xe2ebba3e64f25f8badf35d2760473748d673416a | Self-poisoning entry (dusted the thief's own swap wallet) |
0xedda4e01669d30faa04a9cb75488abc366ee4143 | Controller |
0xde39ef679e12574279e3ed35de4b0721beae27de | Forgery contract |

Source: Etherscan Transaction Record
This case is a reminder that address poisoning attacks are becoming more automated crypto scams and organized rather than one-off attempts.
This crypto hack news story shows how a single controller ran the same dust and spoof routine against both a real victim and eventually its own funds, highlighting just how mechanical and repeatable these scams have become.
Anyone making large transfers should always verify the full destination entry character by character rather than trusting entries that already appear in wallet history.
This article is for informational and educational purposes only. It does not constitute financial, investment, trading, or legal advice. Readers should conduct their own research and consider the risks before making any financial decisions.