Address Poisoning Detection
Address Poisoning — Single Address
GET
/
v2
/
hashdit
/
address-poisoning
curl --get \
--url https://service.hashdit.io/v2/hashdit/address-poisoning \
--header 'X-API-KEY: YOUR_API_KEY' \
--data-urlencode 'chain_id=56' \
--data-urlencode 'address=0x938915fd4b7c188a21ad73ed655ae1f18c334146' \
--data-urlencode 'user_address=0x938915fd4b7c188a211113ed655ae1f18c334146'
{
"code": "0",
"status": "ok",
"data": {
"target_address": {
"is_poisoning": "1",
"mimics_user": "1",
"mimics_exchange": "0"
},
"token_address": {},
"target_address_input": "0x938915fd4b7c188a21ad73ed655ae1f18c334146",
"user_address_input": "0x938915fd4b7c188a211113ed655ae1f18c334146",
"token_address_input": ""
}
}
Synchronous endpoint
Analyze one target address through query parameters. This GET variant supports the single-address request only; use Address Poisoning — Batch for multiple targets or tokens.
All verdict flags are the strings
"0" and "1", not booleans. Compare a flag with "1"; the string "0" is truthy in JavaScript.Quick Start
Includeuser_address whenever the connected wallet is available. It enables the classic address-poisoning check against lookalike transaction-history entries.
curl --get \
--url https://service.hashdit.io/v2/hashdit/address-poisoning \
--header 'X-API-KEY: YOUR_API_KEY' \
--data-urlencode 'chain_id=56' \
--data-urlencode 'address=0x938915fd4b7c188a21ad73ed655ae1f18c334146' \
--data-urlencode 'user_address=0x938915fd4b7c188a211113ed655ae1f18c334146'
{
"code": "0",
"status": "ok",
"data": {
"target_address": {
"is_poisoning": "1",
"mimics_user": "1",
"mimics_exchange": "0"
},
"token_address": {},
"target_address_input": "0x938915fd4b7c188a21ad73ed655ae1f18c334146",
"user_address_input": "0x938915fd4b7c188a211113ed655ae1f18c334146",
"token_address_input": ""
}
}
Request Fields
string
required
Your HashDit API key. Missing or invalid keys return HTTP
401. Keep the key on a trusted server.string
required
Network identifier, such as
"56", or a supported non-EVM alias.string
required
Target address to analyze.
string
Connected wallet address used for the lookalike comparison.
string
Token contract to compare with well-known tokens on the same chain.
Response Fields
string
required
"0" indicates that the request completed successfully.string
required
"ok" for a completed request.string
Aggregate target verdict:
"1" when a poisoning signal was detected, otherwise "0".string
"1" when the target is confusable with user_address.string
"1" when the target is confusable with a known exchange or bridge address.string
Aggregate token verdict when
token_address was supplied.string
"1" when the token resembles a well-known token on that chain.string
The matched token label, or an empty string when there is no match.
How to Use the Response
- Branch on
data.target_address.is_poisoning; it is the aggregate target verdict. - Use
mimics_userandmimics_exchangeto explain why a warning was shown. user_addressenables the classic poisoning comparison. If omitted,mimics_userremains"0"."0"means no configured signal was detected. It is not a guarantee that an address is safe.- If
token_addresswas not requested,data.token_addressmay be an empty object.
Errors and Retry Guidance
| HTTP | Meaning | Client action |
|---|---|---|
400 | Unsupported chain or invalid address | Correct the query; do not retry unchanged. |
401 | Missing or invalid API key | Fix authentication; do not retry unchanged. |
422 | Query validation failed | Correct field names or values. |
429 | Rate limit exceeded | Retry with exponential backoff and jitter. |
500 | Transient service failure | Retry a bounded number of times with backoff. |
Was this page helpful?