Address poisoning is a sneaky scam that targets a very human habit: copying an address from your recent transaction history instead of typing it out.
Here is how it works. An attacker generates a wallet address that starts and ends with the same characters as one you have used before. They send you a tiny, often worthless transaction. Now their lookalike address sits in your history. The next time you copy an address from that list to send funds, you might grab theirs by mistake and send your crypto straight to the attacker.
The danger is that most people only check the first and last few characters of an address. That is exactly the weakness this scam exploits.
The defence is strict: never copy an address from your transaction history. Always get it from the person or service you are actually paying, and check the entire address, not just the ends.