How to Identify Address Poisoning and Clean 0-Value Token Transfers in Ledger and Trezor

If you are a crypto user and you use a Ledger or Trezor hardware wallet, and you see a transaction in your transaction history that you did not make, or you receive an unknown token with a value of 0 USDT, don’t worry and do not interact with it.
This is a scam that many scammers are using in 2026. Interacting with these tokens can allow scammers to track you, and they may even drain your wallet.
This scam is called address poisoning or 0-value transfer scam in the crypto world. What is this scam, how can you avoid it, and what should you do if you become a victim? Everything is explained in detail in this guide. After reading it, you will understand how this scam works.
Before moving ahead, if you are a beginner in crypto and you do not know what a hardware wallet like Ledger or Trezor is, then first learn about it by clicking on this article: How to Protect Your Digital Assets: Hardware Wallet and Cold Wallet Guide.
What Is Address Poisoning?
Address poisoning is a technique where a scammer “poisons” your wallet history. This means they intentionally add a fake address to your transaction list that looks almost the same as the address of someone you have sent crypto to before.
Crypto addresses are 40+ character random hexadecimal strings (for example, (0x71C7…976F). No one can remember the full address, so most people only check the first and last few characters to identify it. Scammers take advantage of this habit.
How Does the Address Poisoning Scam Work?
This is one of the best tools scammers use to steal crypto. In this scam, the scammer gets your wallet address from blockchain data. Then, with the help of a tool, they create a fake wallet address that looks almost exactly like your real address. It matches your real address, but one or two characters are different somewhere in the full address. The rest of the address looks exactly like your real wallet address.
After creating the fake address, the scammer sends some worthless tokens to your real wallet. These tokens usually have a value of 0 USDT, but the fake wallet address gets saved in your transaction history.
Later, if someone wants to send crypto to your wallet, they may quickly copy the address from the transaction history. Most people only check the first and last few characters, which look exactly the same. But the address they copied actually belongs to the scammer. When they send crypto to that address, the funds go to the scammer instead of your wallet.
Later, when you carefully compare your real wallet address, almost every character matches. Only one or two characters are different. This is how the address poisoning scam works.
Another type of address poisoning scam happens when the scammer sends 0 USDT to your real wallet. You may think about converting that token into another token. When you try to convert it, the hacker receives a signal on their dashboard.
This tells the hacker that you have interacted with the token. After that, they start tracking your wallet activity. They can monitor how much crypto you send, how much you receive, and many other details. Using this information, the scammer may try to trick you with another type of scam.
Below, we have explained the different methods hackers use to scam crypto users. Make sure to read them because they will increase your knowledge and help you stay safe Crypto Phishing Scams & Fake Support Accounts – 6 Scam Signs.
According to report, a user lost 4,556 ETH because of this scam. At the current market value, the loss is worth more than $12 million. This is a recent case from 2026.
This Is Something That No One Tells You
Now I will tell you something that almost no one tells you. Only someone who has experienced this scam can explain it. As I told you earlier, one method scammers use is sending 0 USDT tokens to track you.
After tracking you, the scammer checks how much USDT you recently sent or received. For example, if you made a 500 USDT transaction, the scammer will send you 500 fake tokens. These tokens are worth less than 1 USDT, but the amount shown will still be 500 tokens.
When you check your transaction history, you will see that you recently made a 500 USDT transaction, so you will think that this is your own wallet address. Then you will repeat the same mistake as before, and your next transaction will be sent to the scammer’s wallet address.
How to Check in Your Wallet Whether Dust Has Arrived or Not
First you have to open your hardware wallet. After opening it you have to go to transaction history. After that you have to see such an address which is exactly like your real address. If this is the case then there is dust in your wallet.
The second method is to check your transaction history and see if there is any token which has 0-value but the quantity of those tokens is very high like 1000 or 10000. If you see this then your wallet is under hacker attack.
How to Remove This Dust?
If you want that dust should not be visible to you and you do not accidentally get scammed, you can do this very easily from your Ledger wallet.
Suggest: What is a Dusting Attack and How to Protect Yourself?
- Open the Ledger Wallet app.
- Select the account where the suspicious token is showing.
- Tap on that token, then click on the three dots (⋮) in the top-right corner.
- Select the “Hide token” option — this will remove that token from your portfolio view (it will not be deleted from the blockchain, but it will stop showing to you).
Important Notice: Please note that this data cannot be completely removed, as it is permanently recorded on the blockchain. However, the wallet provides a “hide” feature to protect you from accidentally interacting with this scam.
If You Have Already Been Scammed, What Should You Do?
If you have already become a victim of address poisoning, then what should you do now? Below are 4 simple methods which you can follow to protect yourself from it.
First of all, you should not make any new transactions. You must stop all your transactions, even test transactions. This can increase the risk of the scam.
Collect all your evidence such as screenshots of fake addresses, screenshots of fake tokens, etc. This is very important because if you go to legal action later, you must have proof.
Recheck all your saved addresses and if anything looks doubtful, update it immediately.
If you know that you have received transactions from any exchange, then immediately report it to that exchange so they can freeze the funds.
Conclusion
Address poisoning is dangerous because in this there is no malware, no hacking, and no seed phrase theft — the scam only happens because of a person’s haste or mistake. Ledger and Trezor both provide strong protections at the hardware level (Secure Screen, Clear Signing, automatic filtering), but the final decision is always in the user’s hands.






