HTX denies sending suspected poisoning transfers

Bitbuy
Bybit


HTX said on Aug. 18 that it is investigating small cryptocurrency transfers received by several addresses after community members attributed the deposits to the exchange.

Summary

  • HTX said its internal review found no official transfers or testing activity behind reported deposits.
  • Users reported receiving small USDT deposits from addresses labeled as HTX wallets by blockchain services.
  • HTX is examining whether address labels or transaction attribution errors created a misleading origin trail.
  • No transaction list, verified victim count, confirmed loss, or poisoning campaign operator has been disclosed.
  • Reports of frozen accounts remain unconfirmed by HTX and lack publicly available supporting case details.

The exchange said its initial internal review found that its official channels had not initiated the transfers or conducted related testing. HTX is now examining the origin of the transactions and whether blockchain address labels or attribution methods produced a misleading connection.

Phemex

Some users have described the transactions as “address poisoning.” Others reportedly said their accounts faced restrictions after receiving the funds. Neither description has been independently confirmed through transaction records, platform notices or findings from a blockchain security company.

HTX says it did not initiate the disputed transfers

HTX responded after community members circulated screenshots of small deposits that appeared to come from exchange linked addresses. One user reportedly received 7.5 USDT in a Coinbase account before being asked to explain the source of the funds, according to a report.

A request for information does not necessarily mean an account has been frozen. Coinbase has not publicly addressed the reported case, and no affected user has published a complete platform notice showing a permanent restriction linked to the transfer.

HTX said it had “not conducted any related transfers or testing activities.” The exchange added that it would not speculate before completing its investigation. It promised to provide the community with confirmed information, although it did not set a deadline.

HTX investigates source of unsolicited deposits, source: X
HTX investigates source of unsolicited deposits, source: X

The statement did not identify the blockchain involved, the sending addresses or the transaction hashes. It also did not disclose how many recipients had reported deposits or whether any customer assets were at risk.

Small deposits do not prove address poisoning

Address poisoning normally involves an attacker creating an address that resembles one previously used by a target. The attacker then sends a small or zero value transaction so that the lookalike address appears in the target’s transaction history.

The attacker hopes the user will later copy the planted address without checking every character. Chainalysis describes this transaction history manipulation in its security guide.

Small unsolicited transfers alone do not establish address poisoning. Investigators would need to determine whether the sender resembles a trusted counterparty and whether the transaction was intended to manipulate a recipient’s address history.

The current reports contain no verified evidence that recipients later sent assets to lookalike addresses. No losses have been confirmed. No security researcher has publicly connected the disputed transfers to a specific operator.

As previously reported, a user recently lost 100,000 USDT after copying a planted lookalike address from their transaction history. That case included a confirmed misdirected payment, unlike the activity HTX is investigating.

Wallet labels may explain the apparent HTX connection

Blockchain transactions identify addresses, but they do not automatically identify the legal entity controlling each address. Explorers and analytics companies assign labels using disclosed ownership information, transaction patterns and address clustering.

Those methods can produce useful leads, but a displayed label is not conclusive proof that the named exchange authorized a transfer. Deposit addresses, consolidation wallets, payment processors and intermediary services can further complicate attribution.

HTX said its investigation would consider “address tagging” and the identification of onchain transfer sources. This leaves open the possibility that third party services attributed a sender to HTX incorrectly or without enough supporting evidence.

The exchange previously published a scam warning about unsolicited 0.001 USDT transfers. It advised users to inspect complete wallet addresses instead of relying on shortened address displays or transaction histories.

The present case also arrives amid wider concerns about automated compliance screening. In related coverage, users reported blocked transactions and frozen funds after compliance services flagged exposure to HTX linked addresses. Those earlier restrictions involved sanctions screening and do not prove a connection to the latest deposits.

Account freeze reports require further evidence

Claims that some accounts were “frozen” remain unverified. No exchange has confirmed imposing restrictions because of the disputed transfers, and the available reports do not provide case numbers, notices or affected wallet addresses.

A platform may request information when an automated monitoring system detects an unfamiliar counterparty or a link to a flagged address. Such a review can delay access without proving misconduct by the recipient or the sending address.

The distinction matters because describing every compliance check as a freeze could overstate the event. It could also wrongly suggest that HTX users conducted a coordinated poisoning campaign when neither HTX nor an independent investigator has reached that conclusion.

HTX’s investigation will need to identify the sending addresses, establish who controlled them and explain why they made the transfers. Publishing transaction hashes would allow independent analysts to test the exchange attribution and search for lookalike address patterns.

Until then, users should avoid copying destination addresses from transaction histories. They should verify the full address, use saved address books where available and preserve transaction hashes or account notices for support teams. Interacting with an unsolicited token or unfamiliar contract may introduce separate security risks.

HTX said it would share further findings once confirmed. The exchange has not announced when the review will end or whether it plans to publish a technical report.



Source link

Bybit

Be the first to comment

Leave a Reply

Your email address will not be published.


*