BPOI Banner
$55 Million in DAI Stolen From This Crypto Whale via Phishing Attack $55 Million in DAI Stolen From This Crypto Whale via Phishing Attack

Crypto Investor Loses $36M to Permit Phishing Scheme

A recent cyberattack has led to an unsuspecting crypto investor reportedly losing 15,079 fwdETH, worth roughly $36 million.

In the incident, described by security experts as a permit phishing scam, the bad actor tricked the user into unknowingly signing a malicious signature, which gave the thief full access to the individual’s funds.

How it Happened

Scam Sniffer, a Web3 anti-scam platform, broke the news in an October 11 post on X, sharing the addresses of the victim and the attacker.

Five hours before the report surfaced, the victim, identified by the address 0xeab23c1e3776fad145e2e3dc56bcf739f6e0a393, signed a permit phishing signature, unknowingly authorizing the hacker to move their 15,079 fwdETH.

The exploiter, linked to the address 0x0605edee6a8b8b553cae09abe83b2ebeb75516ec, immediately sold the tokens on the market, apparently causing the price of dETH, a related asset, to crash by over 90% within 24 hours.

Chiming in on the incident, analyst roffett.eth warned that the drop in the price of dETH had affected several decentralized finance (DeFi) protocols, particularly PAC Finance and Orbit Finance since the sell-off had allegedly triggered vulnerabilities in their systems.

The Ripple Effect on DeFi

Permit phishing is still relatively new in crypto circles. It comes from criminals exploiting a requirement in certain DeFi tokens or contracts for the user to approve so-called permit signatures that grant third parties the ability to interact with their wallets, including spending or transferring funds.

Attackers usually create a fake website or interface that looks like a legitimate service or decentralized application (dApp) and then ask users to sign the “permit” transaction. This is often disguised as a legitimate request, tricking users into granting full access to their assets.

Such hacks exploit a lack of understanding around transaction permissions, allowing hackers to drain assets from even well-versed crypto users.

This isn’t the first time DeFi users have been targeted by phishing schemes. According to Scam Sniffer, something similar happened just 12 days earlier, with the victim in that incident losing 12,083 spWETH, which was then valued at about $32 million.

Due to the growing instances of such attacks, experts are urging users to be extra cautious when interacting with unfamiliar links or signing transaction permissions.

“Always double-check any signatures you’re asked to sign, and avoid clicking on unknown links,” Scam Sniffer posted as a reminder to the crypto community of the constant threat of phishing tricks.

SPECIAL OFFER (Sponsored)

Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER 2024 at BYDFi Exchange: Up to $2,888 welcome reward, use this link to register and open a 100 USDT-M position for free!

Source link

Wayne Jones

https://cryptopotato.com/crypto-investor-loses-36m-to-permit-phishing-scheme/

2024-10-11 19:34:06

bitcoin
Bitcoin (BTC) $ 91,005.38 3.03%
ethereum
Ethereum (ETH) $ 3,079.77 0.35%
tether
Tether (USDT) $ 1.00 0.02%
solana
Solana (SOL) $ 216.77 1.98%
bnb
BNB (BNB) $ 619.35 1.25%
dogecoin
Dogecoin (DOGE) $ 0.375408 0.12%
xrp
XRP (XRP) $ 0.885168 12.69%
usd-coin
USDC (USDC) $ 1.00 0.12%
staked-ether
Lido Staked Ether (STETH) $ 3,077.52 0.24%
cardano
Cardano (ADA) $ 0.738274 25.27%
tron
TRON (TRX) $ 0.192866 8.67%
shiba-inu
Shiba Inu (SHIB) $ 0.000025 4.71%
the-open-network
Toncoin (TON) $ 5.37 1.37%
avalanche-2
Avalanche (AVAX) $ 33.00 4.48%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 90,884.35 3.39%
wrapped-steth
Wrapped stETH (WSTETH) $ 3,657.14 0.22%
sui
Sui (SUI) $ 3.60 6.40%
pepe
Pepe (PEPE) $ 0.000023 5.71%
weth
WETH (WETH) $ 3,075.98 0.40%
chainlink
Chainlink (LINK) $ 13.79 5.05%
bitcoin-cash
Bitcoin Cash (BCH) $ 430.17 2.38%
polkadot
Polkadot (DOT) $ 5.15 6.60%
leo-token
LEO Token (LEO) $ 7.63 3.23%
near
NEAR Protocol (NEAR) $ 5.49 0.51%
aptos
Aptos (APT) $ 11.80 4.31%
litecoin
Litecoin (LTC) $ 83.30 1.45%
wrapped-eeth
Wrapped eETH (WEETH) $ 3,239.37 0.37%
usds
USDS (USDS) $ 0.993193 0.48%
uniswap
Uniswap (UNI) $ 8.55 3.36%
crypto-com-chain
Cronos (CRO) $ 0.169029 12.83%
stellar
Stellar (XLM) $ 0.144926 9.94%
internet-computer
Internet Computer (ICP) $ 8.68 7.49%
dogwifcoin
dogwifhat (WIF) $ 3.84 4.75%
bittensor
Bittensor (TAO) $ 516.20 2.32%
kaspa
Kaspa (KAS) $ 0.137764 2.49%
ethereum-classic
Ethereum Classic (ETC) $ 23.17 5.37%
fetch-ai
Artificial Superintelligence Alliance (FET) $ 1.28 2.64%
dai
Dai (DAI) $ 0.99957 0.16%
whitebit
WhiteBIT Coin (WBT) $ 22.32 0.68%
ethena-usde
Ethena USDe (USDE) $ 1.00 0.03%
bonk
Bonk (BONK) $ 0.000044 18.86%
polygon-ecosystem-token
POL (ex-MATIC) (POL) $ 0.371449 2.70%
blockstack
Stacks (STX) $ 1.87 2.10%
hedera-hashgraph
Hedera (HBAR) $ 0.073352 14.91%
render-token
Render (RENDER) $ 6.88 2.59%
okb
OKB (OKB) $ 43.91 0.55%
monero
Monero (XMR) $ 143.49 3.74%
first-digital-usd
First Digital USD (FDUSD) $ 1.00 0.25%
filecoin
Filecoin (FIL) $ 4.19 7.28%
aave
Aave (AAVE) $ 164.19 2.91%