The post Crypto phishing losses drop by 83% appeared on BitcoinEthereumNews.com. Global crypto phishing losses fell by more than 80% in the last year, accordingThe post Crypto phishing losses drop by 83% appeared on BitcoinEthereumNews.com. Global crypto phishing losses fell by more than 80% in the last year, according

Crypto phishing losses drop by 83%

2026/01/03 17:46
4분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 crypto.news@mexc.com으로 연락주시기 바랍니다

Global crypto phishing losses fell by more than 80% in the last year, according to new data from blockchain security firm Scam Sniffer. The total losses resulting from wallet drainer phishing attacks reached $83.85 million, affecting 106,106 victims worldwide.

According to Scan Sniffer’s 2025 phishing report, there was an 83% drop in stolen funds and a 68% reduction in victims compared with 2024, when phishing scams drained nearly half a billion dollars from more than 330,000 users. 

The Web3 security group said the reduction was likely a result of the mixed bullish and bearish market cycles last year, where phishing activity went up at peak market performances and fell when user engagement on blockchain networks dropped. 

Crypto market valuation declines ‘sends away’ phishing scammers

Per Scam Sniffer’s analysis and chart data tracking the first quarter, when markets were declining, losses stood at $21.94 million, affecting slightly over 22,000 victims. When markets began to recover in the second quarter, phishing losses declined to $17.78 million from about 21,000 victims.

Phishing losses and victims by month. Source: Scam Sniffer.

The third quarter was the most dangerous period for market participants because several assets had witnessed strong rallies, including Bitcoin, which peaked at $123,000, and Ethereum, which hit its all-time-high price at $4,946 in August. The price charge and bull market environment came with a surge in phishing activity, pushing losses to $31.04 million and impacting 40,000 victims. 

August and September alone accounted for 29% of total annual losses, making the quarter the most active for attackers. However, the last quarter of the year saw a pullback in phishing losses that fell to $13.09 million, by far the quietest part of 2025. 

Permit / Permit2 leads signature phishing theft methods 

The biggest single phishing theft last year resulted in a $6.5 million loss in September, where hackers made away with staked ether and wrapped bitcoin derivatives. The attackers used a method known as the Permit-style signature, a feat that made up 38% of losses among cases exceeding $1 million. 

Permit/Permit 2 signatures allow token spending approvals without direct transfers, which attackers take advantage of by disguising malicious permissions to appear as legitimate prompts and trick token holders into accepting them without question.

Other cases included a $3.13 million theft of wrapped Bitcoin in May using an approval escalation technique, and a $3.05 million loss of stablecoins in August through a direct transfer exploit. Yet, only 11 cases exceeded $1 million in the year, down from 30 the year before.

The data also showed a decline in the average loss per victim, which fell to $790, down from nearly $1,500 last year.

While the report focused on signature-based wallet drainer attacks, one of the most unforgettable cases occurred in February, when the Lazarus Group compromised a developer machine through a multisignature wallet provider within the Bybit crypto exchange. A malicious code was injected into a signing interface, enabling attackers to spoof legitimate approvals and steal approximately $1.46 billion.

Supply chain attacks were also among the most prevalent methods used, with attackers stealing developer credentials through phishing emails and injecting malicious code into open-source packages, backdooring hundreds of software libraries, and exfiltrating private information and security credentials.

Other campaigns phishing hackers used included compromised front-end interfaces, hijacked social media accounts, and spreading malware to steal private keys and authentication data. 

2025 closed with Google Task notification phishing abuse

In other news, the year ended with a sophisticated email phishing campaign in December, as hackers targeted more than 3,000 organizations in manufacturing by abusing Google’s cloud-based infrastructure.

Several users reported receiving emails that appeared as genuine task notifications, prompting recipients to complete an urgent “All Employees Task.” Victims who clicked buttons labeled “View task” or “Mark complete” were redirected to malicious pages hosted on trusted cloud storage services.

Because the messages were sent using legitimate application integration tools, they passed all major email authentication checks and walked past security gateways undetected. 

Join a premium crypto trading community free for 30 days – normally $100/mo.

Source: https://www.cryptopolitan.com/crypto-phishing-losses-drop-by-83/

시장 기회
Moonveil 로고
Moonveil 가격(MORE)
$0.00003941
$0.00003941$0.00003941
+0.63%
USD
Moonveil (MORE) 실시간 가격 차트
면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, crypto.news@mexc.com으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

USD1 Genesis: 0 Fees + 12% APR

USD1 Genesis: 0 Fees + 12% APRUSD1 Genesis: 0 Fees + 12% APR

New users: stake for up to 600% APR. Limited time!