A user lost about 100,000 USDT after copying a malicious lookalike wallet address from transaction history and sending funds without fully verifying the destination, according to Lookonchain, Cyvers Alert and GoPlus. Cyvers said the attacker planted the deceptive address 66 days before the mistaken transfer, while GoPlus said the victim wallet received more than 400 poisoning transactions after the user's last transaction 69 days earlier. Cyvers also said the attacker later swapped the stolen USDT into ETH and now holds about 52.8 ETH, apparently to reduce freezing risk. The firms said the case highlights the threat of automated address-poisoning campaigns and the need to verify full wallet addresses before on-chain transfers.