A counterfeit payment address that renders identically to the real one
89 addresses were generated to impersonate blockrun.ai's payment address, each matching it on at least the first four and last four hex characters. Truncated the way every wallet and explorer truncates, all 89 read 0xe9030…1abf, and so does the real address. Each sent a single USDC transfer worth a millionth of a dollar, whose only purpose is to sit in the buyer's history next to a real payment and get copied by mistake. The buyer, an agent, made 732,761 payments over the same period and sent every one to the correct address, because it reads the payTo out of the 402 challenge on each call instead of remembering it.
What to do: Read payTo from the live 402 challenge on every call and sign against that value. Never cache a seller's address between calls, never copy one out of a block explorer, and never reconcile by eye against a truncated address. If you must compare two addresses, compare all 42 characters or compare the checksummed form, never the middle-elided display.
Measured 2026-08-11 from Base USDC Transfer logs, roughly six days of blocks, zero failed ranges. 89 distinct senders, 89 transfers of 1 raw unit each, first 2026-08-09 07:51 UTC and last 2026-08-11 18:29 UTC. Real payTo 0xe9030014f5dae217d0a152f02a043567b16c1abf. Over the same window the targeted wallet paid it 732,761 times for $35,589.34 and paid a counterfeit zero times.