Crypto whale loses $6M to sneaky phishing scheme targeting staked Ethereum

Share This Post

A crypto whale lost more than $6 million in staked Ethereum (stETH) and Aave-wrapped Bitcoin (aEthWBTC) after approving malicious signatures in a phishing scheme on Sept. 18, according to blockchain security firm Scam Sniffer.

According to the firm, the attackers disguised their move as a routine wallet confirmation through “Permit” signatures, which tricked the victim into authorizing fund transfers without triggering obvious red flags.

Yu Xian, founder of blockchain security company SlowMist, noted that the victim did not recognize the danger because the transaction required no gas fees. He wrote:

“From the victim’s perspective, he just clicked a few times to confirm the wallet’s pop-up signature requests, didn’t spend a single penny of gas, and $6.28 million was gone.”

How Permit exploits work

Permit approvals were originally designed to simplify token transfers. Instead of submitting an on-chain approval and paying fees, a user can sign an off-chain message authorizing a spender.

That efficiency, however, has created a new attack surface for malicious players.

Once a user signs such a permit, attackers can combine two functions—Permit and TransferFrom—to drain assets directly. Because the authorization takes place off-chain, wallet dashboards show no unusual activity until the funds move.

As a result, the assets are gone when the approval executes on-chain, and tokens are redirected to the attacker’s wallet.

This loophole has made permit exploits increasingly attractive for malicious actors, who can siphon millions without needing complex hacks or high-cost gas wars.

Phishing losses

The latest theft highlights a wider trend of escalating phishing campaigns.

Scam Sniffer reported that in August alone, attackers stole $12.17 million from more than 15,200 victims. That figure represented a 72% jump in losses compared with July.

According to the firm, the most significant share of August’s damages came from three large accounts that accounted for nearly half of the total. This included one wallet that lost $3.08 million in a single exploit.

Meanwhile, the firm attributed the surge in losses to a rise in EIP-7702 batch-signature scams and direct transfers to malicious contracts.

Considering this, security experts have urged crypto users to be cautious when interacting with wallet requests and refuse demands that grant unlimited permissions to their wallets.

The post Crypto whale loses $6M to sneaky phishing scheme targeting staked Ethereum appeared first on CryptoSlate.

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

Strategy CEO Defends $1.44-B Reserve: “It’s About Protecting Investor Confidence”

According to remarks made on CNBC’s Power Lunch, Strategy’s CEO Phong Le said the company moved quickly to calm investor fears after Bitcoin fell sharply The firm announced a $144 billion US

Analyst Points To $82,000 As Most Crucial Bitcoin Price Level — Here’s Why

In a not-so-surprising turn of events, the bearish orientation of the Bitcoin price has continued into the month of December, suggesting that the premier cryptocurrency could end the year in the red

New Western Union ‘Stable Card’ Targets Remittance Losses in Argentina and Beyond

Western Union is reportedly rolling out a “stable card” aimed at helping people in high-inflation economies protect the value of their remittances Western Union’s latest move folds neatly into

Massive Bitcoin Awakening: 2 Physical Coins Unlock $179 Million After 13 Years

Two long-dormant Casascius coins, each loaded with 1,000 Bitcoin, were activated on Friday, unlocking more than $179 million that had sat untouched for over 13 years Related Reading: Bitcoin Adoption

Ripple Announces Groundbreaking “One-Stop Shop” For Everything, Here’s What It Is

Crypto firm Ripple recently announced its mission to be the one-stop shop for crypto infrastructure This came as the firm highlighted the acquisitions it made this year in a bid to achieve this

Stablecoin Sector Roars Back as Market Nears a Record Peak

Stablecoin market caps are picking up steam again, inching their way back toward the $309 billion all-time high after another $226 billion poured in over the past week Stablecoin Market Cap Charges