Bofur Capital Loses $2 Million in Address-Poisoning Attack
Address poisoning exploits a wallet user’s reliance on abbreviated transaction records. An attacker sends a small “dust” transfer from a spoofed address whose opening and closing characters resemble a legitimate destination, hoping the victim later copies it without checking the full string. The $2 million loss at Bofur Capital highlights how a routine operational mistake can bypass smart-contract safeguards and expose even institutional crypto users to irreversible transfers.
Bofur Capital withdrew funds from decentralized lending protocol Compound and then mistakenly sent about $2 million to an address planted by the attacker through an earlier dust transaction. The attacker quickly converted all of the stolen USDC into DAI, reducing the risk that the assets could be frozen by a centralized stablecoin issuer. As of Aug. 23, 2026, the funds had not been transferred to a cryptocurrency mixer.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →