HTX is investigating a coordinated address-poisoning campaign targeting exchange-linked wallets, after users reported receiving unsolicited small transfers appearing to originate from HTX addresses. Address poisoning is an on-chain attack where a bad actor sends tiny amounts of crypto from a wallet with an address visually similar to a known, trusted address—the goal is to get the victim to copy that lookalike address from their transaction history and accidentally send funds to the attacker instead of the intended recipient.

The exchange said an internal review found it had not initiated any of the transfers or conducted any testing activity that would explain the transactions. HTX said it is examining the source and cause of the transfers, including the possibility of address-labeling errors or on-chain attribution mistakes, and committed to disclosing its findings once confirmed.

The poisoning reports arrive as HTX already faces pressure from account freezes hitting users across multiple platforms. HTX said some users moving funds to and from the exchange have encountered frozen accounts and transfer restrictions on certain third-party platforms, which it attributed to automated risk-control systems flagging wallets associated with HTX as suspicious. HTX spokesperson Molly Fu said on X that the affected assets "are not assets belonging to any sanctioned entity" but rather "assets legally purchased and owned by individual users."

The freeze problem has a documented backdrop. Investigative reporting has linked accounts on HTX—formerly known as Huobi—to alleged Russian money launderers and an organization tied to funding Russian military entities. European sanctions and evidence that the platform began routing activity through hundreds of newly identified central wallets drew the scrutiny that now feeds into third-party risk systems, causing downstream account blocks for ordinary users.

Binance announced it will halt transactions involving HTX starting Aug. 23, citing recent regulatory developments. HTX is one of 11 platforms named in that action, alongside EXMO and nine others. When the largest exchange by volume cuts transaction access to a platform, users holding assets there face reduced exit options and tighter liquidity pathways.

The timing of the address-poisoning reports inside this environment raises a specific concern: if an attacker is seeding HTX-lookalike addresses into users' transaction histories right now, users already anxious about fund accessibility are more likely to act quickly—and less likely to verify a withdrawal address character by character before sending. That is precisely the psychology a poisoning attack exploits.

HTX also recently delisted the USD1 stablecoin, a token linked to World Liberty Financial, after accusing World Liberty Financial of freezing exchange-held addresses. Fu made the same asset-ownership argument in that dispute—that the frozen holdings belonged to individual users, not to any sanctioned party. The USD1 delisting and the address-poisoning investigation are separate events, but both land in the same week, compressing the exchange's credibility window with its user base.

The on-chain mechanics of a poisoning attack require no exploit of exchange infrastructure. An attacker needs only a vanity-address generator and a small amount of gas to send negligible transfers to thousands of wallets. The cost is low; the potential payoff—one large misdirected withdrawal—can be substantial. HTX's acknowledgment that it is looking at attribution errors as a possible explanation suggests the exchange has not ruled out that its own address labels in block explorers or wallet interfaces may have been incorrectly associated with the attacker's wallets, compounding user confusion.

HTX has not disclosed how many addresses received the suspicious transfers or the total transaction count under review. It has not named a specific chain or chains where the transfers occurred. Until HTX publishes its findings, users with HTX-linked wallets face a direct operational risk: any withdrawal address pulled from recent transaction history should be verified in full, not by matching the first and last few characters, which is the exact shortcut poisoning attacks are designed to exploit.