Bofur Capital lost $2M in an address-poisoning attack where a phisher sent dust USDC to spoof a legitimate address, leading to user error in fund withdrawal.
Security & Exploits ·
Bofur Capital experienced a loss of $2 million in an address-poisoning attack following a withdrawal from Compound. The attacker deployed a dust transaction of 0.0002 USDC to create a spoofed address that closely mimicked the legitimate recipient, and the user mistakenly copied the wrong address when initiating the fund transfer, resulting in the complete drain of funds.
The attack highlights a critical vulnerability in manual address handling during high-value transactions. Address poisoning exploits the visual similarity between addresses and user inattention during copy-paste operations. Security researchers noted that defensive practices like whitelisting addresses and avoiding transaction history as a source for address copying can reduce exposure to this vector, while small test transactions alone do not provide reliable protection against the technique.
The incident underscores that even established entities remain susceptible to social engineering attacks targeting operational security. Whether additional safeguards were in place at Bofur Capital at the time of the attack, or whether the loss has prompted protocol changes, remains unclear.