financetom
Cryptocurrency
financetom
/
Cryptocurrency
/
Crypto Investor Loses $36M to Permit Phishing Scheme
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
Crypto Investor Loses $36M to Permit Phishing Scheme
Oct 11, 2024 12:46 PM

A recent cyberattack has led to an unsuspecting crypto investor reportedly losing 15,079 fwdETH, worth roughly $36 million.

In the incident, described by security experts as a permit phishing scam, the bad actor tricked the user into unknowingly signing a malicious signature, which gave the thief full access to the individual’s funds.

How it Happened

Scam Sniffer, a Web3 anti-scam platform, broke the news in an October 11 post on X, sharing the addresses of the victim and the attacker.

Five hours before the report surfaced, the victim, identified by the address 0xeab23c1e3776fad145e2e3dc56bcf739f6e0a393, signed a permit phishing signature, unknowingly authorizing the hacker to move their 15,079 fwdETH.

The exploiter, linked to the address 0x0605edee6a8b8b553cae09abe83b2ebeb75516ec, immediately sold the tokens on the market, apparently causing the price of dETH, a related asset, to crash by over 90% within 24 hours.

Chiming in on the incident, analyst roffett.eth warned that the drop in the price of dETH had affected several decentralized finance (DeFi) protocols, particularly PAC Finance and Orbit Finance since the sell-off had allegedly triggered vulnerabilities in their systems.

The Ripple Effect on DeFi

Permit phishing is still relatively new in crypto circles. It comes from criminals exploiting a requirement in certain DeFi tokens or contracts for the user to approve so-called permit signatures that grant third parties the ability to interact with their wallets, including spending or transferring funds.

Attackers usually create a fake website or interface that looks like a legitimate service or decentralized application (dApp) and then ask users to sign the “permit” transaction. This is often disguised as a legitimate request, tricking users into granting full access to their assets.

Such hacks exploit a lack of understanding around transaction permissions, allowing hackers to drain assets from even well-versed crypto users.

This isn’t the first time DeFi users have been targeted by phishing schemes. According to Scam Sniffer, something similar happened just 12 days earlier, with the victim in that incident losing 12,083 spWETH, which was then valued at about $32 million.

Due to the growing instances of such attacks, experts are urging users to be extra cautious when interacting with unfamiliar links or signing transaction permissions.

“Always double-check any signatures you’re asked to sign, and avoid clicking on unknown links,” Scam Sniffer posted as a reminder to the crypto community of the constant threat of phishing tricks.

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
Bitwise, Canary Capital, VanEck, and 21Shares Submit Solana ETF Applications Amid Price Surge
Bitwise, Canary Capital, VanEck, and 21Shares Submit Solana ETF Applications Amid Price Surge
Nov 22, 2024
The race to launch the first Solana-focused exchange-traded fund (ETF) is heating up, with four major issuers filing applications with the Chicago Board Options Exchange (CBOE). This development seems to have triggered a charge leading to the price of Solana’s native SOL token to a new all-time high (ATH), pushing it almost past $263 only hours before this writing. SEC...
Binance Users Will Get Updates and Promo Information on New Platform: Details
Binance Users Will Get Updates and Promo Information on New Platform: Details
Nov 22, 2024
TL;DR The exchange will spread news and educational material on one of the most popular messaging applications. Recently, it added new trading pairs and bot options but also delisted several pairs, triggering short-term price retreats. Making Crypto More Accessible Binance launched an official channel on the messaging application WhatsApp. There, users will receive recent news, event announcements, product updates, and...
Tron’s Justin Sun Wins $6.2M Banana Auction, Reminds Us That Art Is Subjective (and Edible)
Tron’s Justin Sun Wins $6.2M Banana Auction, Reminds Us That Art Is Subjective (and Edible)
Nov 22, 2024
The art world appears to have moved over Picasso. Theres a new muse in town: a banana duct-taped to a wall. Crypto entrepreneur and Tron founder Justin Sun recently splashed a jaw-dropping $6.2 million at Sothebys New York for Comedian, Maurizio Cattelans viral artwork consisting ofwell, a banana and some duct tape. And in true Justin Sun fashion, he plans...
Bitcoin Failed to Reach $100K but Dogecoin Explodes by Double Digits to Almost $0.5
Bitcoin Failed to Reach $100K but Dogecoin Explodes by Double Digits to Almost $0.5
Nov 22, 2024
All eyes in the crypto community were on bitcoin last night as the asset was expected to finally hit the coveted milestone of $100,000. Although it came just $250 away on most exchanges, BTC failed to do so and has retraced by around a grand. However, Dogecoin has emerged to catch the attention now, with a massive surge that drove...