Crypto Hack News: Bofur Faces $2M Loss in Address Poisoning Scam In the latest Crypto Hack News, security firm PeckShield flagged a wallet labeled Bofur Capital for losing $2 million in an ad
Crypto Hack News: Bofur Faces $2M Loss in Address Poisoning Scam
In the latest Crypto Hack News, security firm PeckShield flagged a wallet labeled Bofur Capital for losing $2 million in an address poisoning attack right after a withdrawal from Compound.

Source: information cover by wublockchain12
A follow-up investigation later found something unusual—the same controller behind the theft ended up dusting its own wallet minutes after moving the stolen funds.
How The Attack Happened
PeckShield reported that the attacker sent a tiny 0.0002 USDC dust transaction designed to mimic a real payee entry already saved in the victim's transaction history.
The victim then copied that lookalike entry crypto wallet scam for a large transfer instead of the correct one, sending 2 million USDC straight to the scammer.
Key details from this stage include:
A 0.0002 USDC dust transaction was used to spoof a trusted entry.
The victim ran a recurring $2 million payment funded by Compound withdrawals.
The same scam pattern had already been attempted once in July without success.
The stolen funds were swapped through CoW Protocol into roughly 1.999 million DAI.

Source:PeckShieldAlert on X
Crypto Hack News: The Fake History Trick Behind The Scam
Investigators found the forged entries were created using homoglyph token contracts — fake tokens using Cyrillic characters and invisible symbols designed to look identical to real USDC in a wallet's transaction list.
One contract, deployed August 19, pushed 320 transactions in 60 hours, generating close to 89,000 forged history entries across many fake token contracts at once.
This is what let three separate lookalike entries appear in the victim's history well before the real theft happened.

Source:BlockWatchdog on X
Multiple Lookalikes Were Competing For The Same Target
Three separate operations targeted this same victim in August, each using entries that closely matched the real payee through matching prefix and suffix characters.
Two of these lookalikes were never funded and existed only as destinations for zero-value transfer calls.
The one that finally succeeded was the only entry that had moved a small non-zero balance — just 0.0002 USDC — which made it appear active and trustworthy enough to be mistaken for the real one.
Crypto Hack News: The Bot Behind The Theft Poisoned Itself
Roughly 13 minutes after the stolen DAI was parked, the same controller that funded the original theft address ran its identical dust pattern against its own holding account—sending 0.0008 to a freshly mined look-alike, which then relayed 0.0002 to the target.
This is exact routine used on the original victim, just pointed inward this time.
Records show the controller has sent over 126,000 dust transfers to more than 80,000 distinct addresses since late May, with the vast majority used only once, suggesting a large-scale automated sweeping operation rather than a single targeted attack.
Key Addresses Involved In This Case
Wallet
Role
0x7ba7f4773fa7890bad57879f0a1faa0edffb3520
Victim
0xf0e67a1896e814e30c011e36174de28caa9ab1af
Real payee
0xf0e6a49668de1195b931a3717c9cc36fc19721af
Spoofed entry used in theft
0x692729bcd0887b8d02b8ff3169220ba0f4e17251
Swap account holding stolen funds
0xe2ebfd6f329a6330ab7eee68ce1328c21d31816a
Final DAI storage entry
0xe2ebba3e64f25f8badf35d2760473748d673416a
Self-poisoning entry (dusted the thief's own swap wallet)
0xedda4e01669d30faa04a9cb75488abc366ee4143
Controller
0xde39ef679e12574279e3ed35de4b0721beae27de
Forgery contract

Source:Etherscan Transaction Record
Conclusion
This case is a reminder that address poisoning attacks are becoming more automated crypto scams and organized rather than one-off attempts.
This crypto hack news story shows how a single controller ran the same dust and spoof routine against both a real victim and eventually its own funds, highlighting just how mechanical and repeatable these scams have become.
Anyone making large transfers should always verify the full destination entry character by character rather than trusting entries that already appear in wallet history.
Disclaimer
This article is for informational and educational purposes only. It does not constitute financial, investment, trading, or legal advice. Readers should conduct their own research and consider the risks before making any financial decisions.