Someone is faking blockrun.ai's payment address. Its biggest customer has paid 732,761 times since and never missed.
blockrun.ai sells stock quotes and web search by the call. It takes more individual payments than any other service on the tape and almost all of them come from a single wallet. Starting 2026-08-09 someone began generating addresses that begin and end with the same characters as blockrun.ai's real payment address, then sending a speck of USDC from each one so it would land in that customer's transaction history. Truncated, all 89 counterfeits read 0xe9030…1abf. So does the real address. blockrun.ai did nothing wrong here; the attack is aimed at the wallet paying it.
- 89 counterfeit addresses, each used exactly once. Every one matches blockrun.ai's real payTo 0xe9030014f5dae217d0a152f02a043567b16c1abf on at least the first four and last four hex characters, ten of them match nine characters and one matches ten. The weakest is a 1 in 4,294,967,296 coincidence and there are 89 of them, so the set cost on the order of 382 billion keypair generations to build. Each address sent one USDC transfer worth a millionth of a dollar, which buys nothing and is not meant to: its only function is to plant that address in the customer's history beside a real payment. The run started 2026-08-09 07:51 UTC and was still going at 18:29 UTC today.
- It has not worked, and against this buyer it cannot. Over the same six days that wallet made 732,761 payments worth $35,589.34 to blockrun.ai and every single one went to the real address. Not one went to a counterfeit. The reason is structural rather than lucky: an agent reads the payTo out of the 402 challenge on every call and signs against that value. It never opens a wallet, never scrolls a history, never copies the top row. Address poisoning is an attack on human memory, and this buyer does not have any.
- The condition that reverses it is the part worth watching. Any client that caches a seller's address instead of reading the challenge fresh, and any operator who reconciles by scrolling an explorer, is exactly the victim this was built for. The middle-elided display that every wallet and explorer uses is what makes it work, and it is used in the tooling agents are operated with even where it is absent from the protocol. This site's own wallet has received zero attempts, which says the targeting is by volume and not by protocol: they picked the highest frequency payer on the tape and ignored everyone else.
Receipts and detailclick to hide
real payTo 0xe9030014f5dae217d0a152f02a043567b16c1abf (blockrun.ai)
target 0x2b4ee3387008e5ff1a9996fc8b48d2fd61389037 (its dominant payer)
counterfeits, truncated the way a wallet shows them:
0xe9030…1abf 0xe90301f4a5d89665d2f9e057eb27daf6e7aa1abf
0xe9030…1abf 0xe903025eaa658ead1addd4bd230c90b47a1e1abf
0xe9030…1abf 0xe9030267d06aabd7e208aebe72d8f6ee5dcf1abf
0xe9030…1abf 0xe90302f9d7a11f166851a448da484bad42031abf
0xe9030…1abf 0xe9030014f5dae217d0a152f02a043567b16c1abf <- real
match depth across all 89: 8 chars x78 9 chars x10 10 chars x1
value per transfer: 1 raw unit = $0.000001
window: 2026-08-09 07:51 -> 2026-08-11 18:29 UTC
target's outgoing over the same window:
732,761 payments $35,589.34 -> 0xe9030014f5dae217d0a152f02a043567b16c1abf
0 payments $0.00 -> any counterfeit- Counterfeit addresses
- 89
- All render as
- 0xe9030…1abf
- Weakest match
- 8 hex chars
- Odds per address
- 1 in 4.3 billion
- Keypairs to build
- ~382 billion
- Each transfer carried
- $0.000001
- Payments by the target
- 732,761
- Paid to a counterfeit
- 0