DCIPCHECK v2.0
< RETURN TO LOGS
DOC_ID: WEB3-PHI

ENS Homograph Attacks: How Unicode Spoofing & Zero-Width Spaces Steal Crypto

DATE: 2026-08-26AUTHOR: DC Cybersecurity (Security Intelligence Analyst)
#ENS#HOMOGRAPH ATTACK#UNICODE SPOOFING#PHISHING#CRYPTO SECURITY
Holographic Ethereum Name Service lookup terminal comparing fake Cyrillic Unicode characters
Fig 1. Homograph Unicode attacks replace Latin characters with identical Cyrillic glyphs to spoof ENS wallet domains.

The Human-Readable Promise of Ethereum Name Service (ENS)

The Ethereum Name Service (ENS) replaces complex 42-character hexadecimal addresses (e.g., 0xd8da6bf26964af9d7eed9e03e53415d37aa96045) with human-readable domains like vitalik.eth. However, cybercriminals exploit Unicode standardization to create devastating ENS Homograph Phishing Attacks.

The Anatomy of an Internationalized Domain Name (IDN) Attack

In the UTF-8 Unicode character set, multiple independent alphabets (Latin, Cyrillic, Greek) contain visually indistinguishable characters known as Homoglyphs:

Displayed CharacterAlphabet / ScriptUnicode Hex Value
aLatin Small Letter AU+0061
аCyrillic Small Letter AU+0430

How Scammers Steal Transfers

  1. Registering Confusable Domains: The scammer registers vitаlik.eth (using Cyrillic а) and binds it to their drainer wallet address.
  2. Pasting in OTC Chatrooms: When facilitating an Over-The-Counter (OTC) crypto trade on Telegram or Discord, the scammer provides the lookalike domain.
  3. Zero-Width Space Injection: Attackers insert invisible zero-width spaces (U+200B) into copyable text, tricking web wallets into resolving an entirely different address.

Protection Protocol: ENS Normalization Standard (ENSIP-15)

Modern Web3 wallets (MetaMask, Rainbow) implement ENSIP-15 Normalization: actively checking Punycode strings and displaying severe visual warnings whenever mixed scripts or confusable homoglyphs are detected.

Review our analysis on Permit2 and eth_sign crypto drainer exploits.

Verify your connection security on our free Web3 network inspector.

> AUTHOR_CREDENTIALS_VERIFIED

💾
DC CybersecurityCODENAME: OPERATOR

Security Intelligence Analyst

Contributing researcher at DCIPCHECK dedicated to tracking IP geolocations, proxy protocols, and cloud privacy.

DC Certified Analyst

END OF TRANSMISSION

Was this intel useful? Verify your own connection security now.

RUN IP SCAN >