A victim loses $3M $USDC from Safe wallet in Fake Request Finance contract exploit which shows risks of malicious approvals and urgent crypto security vigilance.A victim loses $3M $USDC from Safe wallet in Fake Request Finance contract exploit which shows risks of malicious approvals and urgent crypto security vigilance.

Fake Request Finance Contract Drains $3M $USDC from Safe Wallet

2025/09/12 20:20
2분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 crypto.news@mexc.com으로 연락주시기 바랍니다
usdc main

The Web3 community has experienced a tragic shake with a major crypto security breach. A victim got a sophisticated exploit in which he lost $3.047 million in $USDC. The attack involves a fake Request Finance contract which was linked with a Safe multi-sig wallet.

This breach highlights the fact that even the legitimate-looking batch transactions with hidden malicious approvals can cause the mishap. In this case, the experienced users also suffer and face vulnerability.

Fake Request Finance Contract Makes the System Fool

Scam Sniffer, a platform shedding light on crypto scams, observed that, before the 13 days of the theft, the attacker deployed a malicious contract. The scammer has deliberately designed the Etherscan-verified malicious contract to get a fake copy of the legitimate Request Finance Batch Payment contract.

Both addresses had the same beginning and ending characters, becoming nearly identical. This resulted in difficulty in recognizing the real and fraudulent versions. There was a further execution of multiple “batchPayments” from the attacker to appear as trustworthy.

While using the Request Finance app interface, the victim executed batch transactions. This execution included the hidden approval of a malicious contract unknowingly. Through this approval, the scammer gained access and drained the wallet. After that, he swapped the funds for ETH immediately, funnelling it to Tornado Cash. So now, the recovery of that fund is nearly impossible. 

Industry Response to the Attack and Possible Security Measures

A quick alert was issued by the Request Finance, announcing the deployment of malicious attack having an identical contract. They have cleared that only one person was affected by the attack, ensuring others that they had already addressed the vulnerability.

Besides this, the exact vector involved in the attack is unclear till now. Security experts give a number of possible reasons, including application-level vulnerabilities, compromised frontends, malware or browser extension interference, DNS hijacking, or other injection techniques.

Through this exploit, a growing threat is highlighted, giving awareness of malicious verified contracts and near-identical addresses. To hide malicious approvals, the stealers combine multi-send functionality, even utilizing small and critical oversights for their scam execution.

So, the experts advise users to check and verify every batch approval carefully while cross-checking contract addresses character by character. It is necessary for users to remain vigilant while executing transactions and giving approvals. The app security is essential to prevent devastating losses.

시장 기회
유에스디코인 로고
유에스디코인 가격(USDC)
$0.9995
$0.9995$0.9995
0.00%
USD
유에스디코인 (USDC) 실시간 가격 차트
면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, crypto.news@mexc.com으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

USD1 Genesis: 0 Fees + 12% APR

USD1 Genesis: 0 Fees + 12% APRUSD1 Genesis: 0 Fees + 12% APR

New users: stake for up to 600% APR. Limited time!