A cryptocurrency investor recently lost $6.28 million to a sophisticated phishing scam that exploited malicious signature approvals. The incident serves as a significant reminder of the increasing prevalence of “permit phishing” schemes, which pose a serious threat to users in the DeFi ecosystem. Attacker Steals $6.28 Million   The attack began when the victim received a targeted phishing message that appeared to be a legitimate update from a decentralized finance (DeFi) platform. Tempted by offers of better returns, the investor connected their wallet to a fake website. There, they signed an EIP-2612, which includes a feature that allows token approvals without gas fees. However, it can also unintentionally give scammers unlimited spending access to a smart contract.  The theft occurred shortly after the approvals were granted. The scammer quickly executed a contract that drained 3,200 stETH and a matching amount of aEthWBTC from the victim’s wallet. The loot, which was traced to a mixer address, revealed a calculated plan to conceal the trail.  The entire theft took less than 12 minutes, using automated scripts for speed. Scam Sniffer noted that the victim’s portfolio, which was worth over $10 million before the attack, lost half its value immediately. The rapid process allowed no time for intervention, as blockchain transactions cannot be reversed once completed. On-chain analysis indicated that the assets were unlikely to be recovered, as they were likely laundered through exchanges. Not New   Following the exploit, some users on X have expressed shock, wondering how the victim unwittingly signed malicious token approvals. However, this subtle trap has long troubled the crypto space. For instance, earlier this month, a user of Venus Protocol lost $13.5 million. The victim fell prey to a phishing scam by approving a transaction from a malicious Core Pool Comptroller contract, which granted the attacker access to their funds. Once permission was given, the hacker quickly drained stablecoins and wrapped tokens from the trader’s wallet.  Surprisingly, though, a few hours after the incident, the Venus team tracked the stolen funds by force-liquidating the hackers’ trade positions. The team fully recovered the stolen funds afterwards, leaving the thief with nothing. The post Crypto Investor Loses $6.28M to Sophisticated Phishing Permit Scam appeared first on Cointab.A cryptocurrency investor recently lost $6.28 million to a sophisticated phishing scam that exploited malicious signature approvals. The incident serves as a significant reminder of the increasing prevalence of “permit phishing” schemes, which pose a serious threat to users in the DeFi ecosystem. Attacker Steals $6.28 Million   The attack began when the victim received a targeted phishing message that appeared to be a legitimate update from a decentralized finance (DeFi) platform. Tempted by offers of better returns, the investor connected their wallet to a fake website. There, they signed an EIP-2612, which includes a feature that allows token approvals without gas fees. However, it can also unintentionally give scammers unlimited spending access to a smart contract.  The theft occurred shortly after the approvals were granted. The scammer quickly executed a contract that drained 3,200 stETH and a matching amount of aEthWBTC from the victim’s wallet. The loot, which was traced to a mixer address, revealed a calculated plan to conceal the trail.  The entire theft took less than 12 minutes, using automated scripts for speed. Scam Sniffer noted that the victim’s portfolio, which was worth over $10 million before the attack, lost half its value immediately. The rapid process allowed no time for intervention, as blockchain transactions cannot be reversed once completed. On-chain analysis indicated that the assets were unlikely to be recovered, as they were likely laundered through exchanges. Not New   Following the exploit, some users on X have expressed shock, wondering how the victim unwittingly signed malicious token approvals. However, this subtle trap has long troubled the crypto space. For instance, earlier this month, a user of Venus Protocol lost $13.5 million. The victim fell prey to a phishing scam by approving a transaction from a malicious Core Pool Comptroller contract, which granted the attacker access to their funds. Once permission was given, the hacker quickly drained stablecoins and wrapped tokens from the trader’s wallet.  Surprisingly, though, a few hours after the incident, the Venus team tracked the stolen funds by force-liquidating the hackers’ trade positions. The team fully recovered the stolen funds afterwards, leaving the thief with nothing. The post Crypto Investor Loses $6.28M to Sophisticated Phishing Permit Scam appeared first on Cointab.

Crypto Investor Loses $6.28M to Sophisticated Phishing Permit Scam

2025/09/19 01:35

A cryptocurrency investor recently lost $6.28 million to a sophisticated phishing scam that exploited malicious signature approvals. The incident serves as a significant reminder of the increasing prevalence of “permit phishing” schemes, which pose a serious threat to users in the DeFi ecosystem.

Attacker Steals $6.28 Million  

The attack began when the victim received a targeted phishing message that appeared to be a legitimate update from a decentralized finance (DeFi) platform. Tempted by offers of better returns, the investor connected their wallet to a fake website.

There, they signed an EIP-2612, which includes a feature that allows token approvals without gas fees. However, it can also unintentionally give scammers unlimited spending access to a smart contract. 

The theft occurred shortly after the approvals were granted. The scammer quickly executed a contract that drained 3,200 stETH and a matching amount of aEthWBTC from the victim’s wallet. The loot, which was traced to a mixer address, revealed a calculated plan to conceal the trail. 

The entire theft took less than 12 minutes, using automated scripts for speed. Scam Sniffer noted that the victim’s portfolio, which was worth over $10 million before the attack, lost half its value immediately. The rapid process allowed no time for intervention, as blockchain transactions cannot be reversed once completed. On-chain analysis indicated that the assets were unlikely to be recovered, as they were likely laundered through exchanges.

Not New  

Following the exploit, some users on X have expressed shock, wondering how the victim unwittingly signed malicious token approvals. However, this subtle trap has long troubled the crypto space. For instance, earlier this month, a user of Venus Protocol lost $13.5 million.

The victim fell prey to a phishing scam by approving a transaction from a malicious Core Pool Comptroller contract, which granted the attacker access to their funds. Once permission was given, the hacker quickly drained stablecoins and wrapped tokens from the trader’s wallet. 

Surprisingly, though, a few hours after the incident, the Venus team tracked the stolen funds by force-liquidating the hackers’ trade positions. The team fully recovered the stolen funds afterwards, leaving the thief with nothing.

The post Crypto Investor Loses $6.28M to Sophisticated Phishing Permit Scam appeared first on Cointab.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Developers of Altcoin Traded on Binance Reveal Reason for Major Price Drop – “Legal Process Has Begun”

Developers of Altcoin Traded on Binance Reveal Reason for Major Price Drop – “Legal Process Has Begun”

The post Developers of Altcoin Traded on Binance Reveal Reason for Major Price Drop – “Legal Process Has Begun” appeared on BitcoinEthereumNews.com. Private computing network Nillion explained that the sharp volatility seen in the NIL token price yesterday was caused by a market maker selling a large amount without authorization. The company stated that the party in question did not respond to any communication from the team during and after the sale. Nillion announced that it initiated a buyback process immediately following the incident, using funds from the treasury. It also stated that it had worked with exchanges to freeze accounts related to the sale and initiate legal action against the person or institution responsible. The company maintained that such unauthorized transactions occur from time to time in the crypto space, but that they would not remain passive this time. Nillion also announced that any funds recovered from the unauthorized token sales would be used for additional buybacks. NIL price has lost 36.3% of its value in the last 24 hours and is trading at $0.118 at the time of writing. Chart showing the decline in the price of NIL. NIL broke its all-time high price record at $0.95 about 8 months ago and is trading 87% lower than that record level at the time of writing. *This is not investment advice. Follow our Telegram and Twitter account now for exclusive news, analytics and on-chain data! Source: https://en.bitcoinsistemi.com/developers-of-altcoin-traded-on-binance-reveal-reason-for-major-price-drop-legal-process-has-begun/
Share
BitcoinEthereumNews2025/11/21 13:29
XRP Price Extends Losses, Deepens Move Below $2.0 Amid Softer Sentiment

XRP Price Extends Losses, Deepens Move Below $2.0 Amid Softer Sentiment

XRP price started a fresh decline below $2.050. The price is now struggling and faces resistance near the $2.050 pivot level. XRP price started a fresh decline below the $2.050 zone. The price is now trading below $2.050 and the 100-hourly Simple Moving Average. There is a bearish trend line forming with resistance at $2.080 on the hourly chart of the XRP/USD pair (data source from Kraken). The pair could continue to move down if it settles below $2.00. XRP Price Dips Further XRP price attempted a recovery wave above $2.120 but failed to continue higher, like Bitcoin and Ethereum. The price started a fresh decline below $2.050 and $2.020. There was a move below the $2.00 support level. A low was formed at $1.957, and the price is now consolidating losses below the 23.6% Fib retracement level of the downward move from the $2.141 swing high to the $1.9575 low. The price is now trading below $2.050 and the 100-hourly Simple Moving Average. If there is a fresh upward move, the price might face resistance near the $2.050 level and the 50% Fib retracement level of the downward move from the $2.141 swing high to the $1.9575 low. The first major resistance is near the $2.080 level. There is also a bearish trend line forming with resistance at $2.080 on the hourly chart of the XRP/USD pair. A close above $2.080 could send the price to $2.120. The next hurdle sits at $2.150. A clear move above the $2.150 resistance might send the price toward the $2.20 resistance. Any more gains might send the price toward the $2.250 resistance. The next major hurdle for the bulls might be near $2.320. More Losses? If XRP fails to clear the $2.080 resistance zone, it could start a fresh decline. Initial support on the downside is near the $1.950 level. The next major support is near the $1.920 level. If there is a downside break and a close below the $1.920 level, the price might continue to decline toward $1.880. The next major support sits near the $1.8450 zone, below which the price could continue lower toward $1.80. Technical Indicators Hourly MACD – The MACD for XRP/USD is now gaining pace in the bearish zone. Hourly RSI (Relative Strength Index) – The RSI for XRP/USD is now below the 50 level. Major Support Levels – $1.950 and $1.920. Major Resistance Levels – $2.050 and $2.080.
Share
NewsBTC2025/11/21 12:48