The post Crypto investor loses $3M in advanced phishing attack appeared on BitcoinEthereumNews.com. An unidentified crypto investor has lost over $3 million in a highly coordinated phishing attack after unknowingly authorizing a malicious contract. On Sept. 11, blockchain investigator ZachXBT first flagged the incident, revealing that the victim’s wallet was drained of $3.047 million in USDC. The attacker quickly swapped the stablecoins for Ethereum and funneled the proceeds into Tornado Cash, a privacy protocol often used to obscure the flow of stolen funds. How the exploit occurred SlowMist founder Yu Xian explained that the compromised address was a 2-of-4 Safe multi-signature wallet. He explained that the breach originated from two consecutive transactions in which the victim approved transfers to an address that mimicked their intended recipient. The attacker crafted the fraudulent contract so that its first and last characters mirrored the legitimate one, making it difficult to detect. Xian added that the exploit took advantage of the Safe Multi Send mechanism, disguising the abnormal approval inside what appeared to be a routine authorization. He wrote: Wall Street Doesn’t Want You to See This… Get 5 days of high-level strategies the pros use to win in crypto. Limited seats available — claim yours now. Brought to you by CryptoSlate Nice 😎 Your first lesson is on the way. Please add [email protected] to your email whitelist. “This abnormal authorization was hard to detect because it wasn’t a standard approve.” According to Scam Sniffer, the attacker had prepared the ground well in advance. They deployed a fake but Etherscan-verified contract nearly two weeks earlier, programming it with multiple “batch payment” functions to look legitimate. On the day of the exploit, the malicious approval was executed through the Request Finance app interface, giving the attacker access to the victim’s funds. In response, Request Finance acknowledged that a malicious actor had deployed a counterfeit version of its Batch… The post Crypto investor loses $3M in advanced phishing attack appeared on BitcoinEthereumNews.com. An unidentified crypto investor has lost over $3 million in a highly coordinated phishing attack after unknowingly authorizing a malicious contract. On Sept. 11, blockchain investigator ZachXBT first flagged the incident, revealing that the victim’s wallet was drained of $3.047 million in USDC. The attacker quickly swapped the stablecoins for Ethereum and funneled the proceeds into Tornado Cash, a privacy protocol often used to obscure the flow of stolen funds. How the exploit occurred SlowMist founder Yu Xian explained that the compromised address was a 2-of-4 Safe multi-signature wallet. He explained that the breach originated from two consecutive transactions in which the victim approved transfers to an address that mimicked their intended recipient. The attacker crafted the fraudulent contract so that its first and last characters mirrored the legitimate one, making it difficult to detect. Xian added that the exploit took advantage of the Safe Multi Send mechanism, disguising the abnormal approval inside what appeared to be a routine authorization. He wrote: Wall Street Doesn’t Want You to See This… Get 5 days of high-level strategies the pros use to win in crypto. Limited seats available — claim yours now. Brought to you by CryptoSlate Nice 😎 Your first lesson is on the way. Please add [email protected] to your email whitelist. “This abnormal authorization was hard to detect because it wasn’t a standard approve.” According to Scam Sniffer, the attacker had prepared the ground well in advance. They deployed a fake but Etherscan-verified contract nearly two weeks earlier, programming it with multiple “batch payment” functions to look legitimate. On the day of the exploit, the malicious approval was executed through the Request Finance app interface, giving the attacker access to the victim’s funds. In response, Request Finance acknowledged that a malicious actor had deployed a counterfeit version of its Batch…

Crypto investor loses $3M in advanced phishing attack

2025/09/12 19:22
2분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 crypto.news@mexc.com으로 연락주시기 바랍니다

An unidentified crypto investor has lost over $3 million in a highly coordinated phishing attack after unknowingly authorizing a malicious contract.

On Sept. 11, blockchain investigator ZachXBT first flagged the incident, revealing that the victim’s wallet was drained of $3.047 million in USDC.

The attacker quickly swapped the stablecoins for Ethereum and funneled the proceeds into Tornado Cash, a privacy protocol often used to obscure the flow of stolen funds.

How the exploit occurred

SlowMist founder Yu Xian explained that the compromised address was a 2-of-4 Safe multi-signature wallet.

He explained that the breach originated from two consecutive transactions in which the victim approved transfers to an address that mimicked their intended recipient.

The attacker crafted the fraudulent contract so that its first and last characters mirrored the legitimate one, making it difficult to detect.

Xian added that the exploit took advantage of the Safe Multi Send mechanism, disguising the abnormal approval inside what appeared to be a routine authorization.

He wrote:

According to Scam Sniffer, the attacker had prepared the ground well in advance. They deployed a fake but Etherscan-verified contract nearly two weeks earlier, programming it with multiple “batch payment” functions to look legitimate.

On the day of the exploit, the malicious approval was executed through the Request Finance app interface, giving the attacker access to the victim’s funds.

In response, Request Finance acknowledged that a malicious actor had deployed a counterfeit version of its Batch Payment contract. The company noted that only one customer was affected and stressed that the vulnerability has since been patched.

Still, Scam Sniffer highlighted broader concerns about the phishing incident.

The blockchain security firm warned that similar exploits could stem from several vectors, including app vulnerabilities, malware or browser extensions modifying transactions, compromised front-ends, or DNS hijacking.

More importantly, the use of verified contracts and near-identical addresses illustrates how attackers are refining their methods to bypass user scrutiny.

Mentioned in this article

Source: https://cryptoslate.com/new-sophisticated-phishing-exploit-drains-3m-in-usdc-from-multi-sig-wallet/

시장 기회
스레숄드 로고
스레숄드 가격(T)
$0.006081
$0.006081$0.006081
-2.14%
USD
스레숄드 (T) 실시간 가격 차트
면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, crypto.news@mexc.com으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

USD1 Genesis: 0 Fees + 12% APR

USD1 Genesis: 0 Fees + 12% APRUSD1 Genesis: 0 Fees + 12% APR

New users: stake for up to 600% APR. Limited time!