Crypto whale loses $6M to sneaky phishing scheme targeting staked Ethereum

Share This Post

A crypto whale lost more than $6 million in staked Ethereum (stETH) and Aave-wrapped Bitcoin (aEthWBTC) after approving malicious signatures in a phishing scheme on Sept. 18, according to blockchain security firm Scam Sniffer.

According to the firm, the attackers disguised their move as a routine wallet confirmation through “Permit” signatures, which tricked the victim into authorizing fund transfers without triggering obvious red flags.

Yu Xian, founder of blockchain security company SlowMist, noted that the victim did not recognize the danger because the transaction required no gas fees. He wrote:

“From the victim’s perspective, he just clicked a few times to confirm the wallet’s pop-up signature requests, didn’t spend a single penny of gas, and $6.28 million was gone.”

How Permit exploits work

Permit approvals were originally designed to simplify token transfers. Instead of submitting an on-chain approval and paying fees, a user can sign an off-chain message authorizing a spender.

That efficiency, however, has created a new attack surface for malicious players.

Once a user signs such a permit, attackers can combine two functions—Permit and TransferFrom—to drain assets directly. Because the authorization takes place off-chain, wallet dashboards show no unusual activity until the funds move.

As a result, the assets are gone when the approval executes on-chain, and tokens are redirected to the attacker’s wallet.

This loophole has made permit exploits increasingly attractive for malicious actors, who can siphon millions without needing complex hacks or high-cost gas wars.

Phishing losses

The latest theft highlights a wider trend of escalating phishing campaigns.

Scam Sniffer reported that in August alone, attackers stole $12.17 million from more than 15,200 victims. That figure represented a 72% jump in losses compared with July.

According to the firm, the most significant share of August’s damages came from three large accounts that accounted for nearly half of the total. This included one wallet that lost $3.08 million in a single exploit.

Meanwhile, the firm attributed the surge in losses to a rise in EIP-7702 batch-signature scams and direct transfers to malicious contracts.

Considering this, security experts have urged crypto users to be cautious when interacting with wallet requests and refuse demands that grant unlimited permissions to their wallets.

The post Crypto whale loses $6M to sneaky phishing scheme targeting staked Ethereum appeared first on CryptoSlate.

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

Analyst Says Dogecoin Price Is Ready To Fly, Here’s Why

Dogecoin has been bleeding lower in recent days, grinding back toward the mid-$013 band Sellers have been in control of most candles in the past 24 hours, and each attempt at a rebound has faded

$3.4 Billion In Bitcoin Options Expires, Triggering Market Squeeze — Details

Bitcoin’s price action has been grossly dramatic throughout the year After reaching its current all-time-high price of $126,000 in early October, the world’s leading cryptocurrency saw a

PVARA Chief: Pakistan to Roll out Stablecoin, Advance CBDC Plans

Pakistan announced plans to launch its first government-backed stablecoin as a key step in integrating virtual assets into its national economy Regulatory Push Pakistan plans to launch its first

Citadel pushes SEC to classify open-source developers as unregistered stockbrokers – Uniswap fires back

On Dec 2, Citadel Securities filed a 13-page letter with the SEC arguing that decentralized protocols facilitating tokenized US equity trading already meet statutory definitions of exchanges and

Strategy CEO Defends $1.44-B Reserve: “It’s About Protecting Investor Confidence”

According to remarks made on CNBC’s Power Lunch, Strategy’s CEO Phong Le said the company moved quickly to calm investor fears after Bitcoin fell sharply The firm announced a $144 billion US

Analyst Points To $82,000 As Most Crucial Bitcoin Price Level — Here’s Why

In a not-so-surprising turn of events, the bearish orientation of the Bitcoin price has continued into the month of December, suggesting that the premier cryptocurrency could end the year in the red