DFNS introduces Transaction Screening, which catches address poisoning attacks before transfers. Address poisoning exploits wallet copy-paste: attackers generate lookalike addresses matching visible characters, then plant them in transaction history via dust transfers. A Carnegie Mellon study found 270 million such attacks draining $83.8 million, often targeting institutional wallets. DFNS's lookalike detection flags addresses with matching visible prefixes or suffixes, informed by Carnegie Mellon research. The feature scopes per wallet, warns without blocking, and keeps repeat destinations unaffected.

DFNS is launching Transaction Screening, a security checkpoint that detects address poisoning before dashboard transfers execute. Address poisoning exploits the fact that wallet interfaces truncate addresses, showing only visible start and end characters. Attackers generate lookalike addresses matching these visible ends, then dust them into your transaction history; copying "that address" later means copying the impostor. A Carnegie Mellon study found 270 million poisoning attacks, with 6,633 successful incidents draining $83.8 million. Attackers profile targets, hunting high-balance wallets and striking within minutes. DFNS's lookalike detection adapts the Carnegie Mellon method, comparing visible characters rather than full edit distances. The feature fires on three patterns: matching both visible ends, deep prefix, or deep suffix. Importantly, screening is scoped per wallet (median wallets pay one address, 99% pay fewer than 25), so false positives stay rare. The feature warns but doesn't block, keeping one-click dismissals cheap. More checks from DFNS and partners like Blockaid and Hypernative will follow.