Users Lost $69M in $WBTC due to Address Poisoning

Users Lost $69M in $WBTC due to Address Poisoning

Reported by The Defiant, an unsuspecting user lost $69 million in WBTC after sending the funds to an address linked with an attack known as address poisoning.

Web3 cybersecurity firm Certik first alerted of the malicious transaction early Friday morning. The attacker mimicked a transfer of 0.05 ETH, or $150, which led the victim to send the funds to the wrong address, according to Certik’s X account.

Poisoning addresses refers to attackers sending spam transactions to an address in order to confuse inattentive users. Users then copy the fraudulent address–which usually begins and ends with the same six digits– instead of sending funds to a legitimate wallet address.

Hackers can know an address linked to a user’s exchange account because of recurring payments and other transaction flows.

The pseudonymous Officer, a threat researcher formerly of the Web3 cybersecurity firm ImmuneFi, told The Defiant that these types of attacks are very common but usually have a low success rate.

According to Etherscan, after the attack, the perpetrator moved the funds in eight separate transactions.

According to Officer, many users are lazy when operating in the crypto space.

“A lot of people have a bad habit of blind copying the last address from their transaction history, just to be sure,” he said. Hackers take advantage of this behavior by sending small sums of crypto from similar-looking addresses.

How to counter such attacks?

“Don't trust Clipboard especially given the fact that malware with almost the same scheme exists (it usually targets a clipboard), check all digits one by one and add hot addresses to the allow list (if possible),” he warned.

Exploits have been on a negative curve during 2024.

Hackers stole $336 million in crypto in the first quarter this year, a 23% drop from the same time last year, according to the latest report by Web3 security firm ImmuneFi.

Source

Security Incidents

Related News
Lending Protocol Sonne Finance Exploited for $20M Lending Protocol Sonne Finance Exploited for $20M
Prisma Finance Exploited for $12M Prisma Finance Exploited for $12M
Major Security Vulnerability Found in Ledger Software Library, Affecting Multiple Dapps Major Security Vulnerability Found in Ledger Software Library, Affecting Multiple Dapps
Security Audits are "Not Enough" as Crypto Hacks Losses Topped $1.5B in 2023 Security Audits are "Not Enough" as Crypto Hacks Losses Topped $1.5B in 2023
Decentralized Exchange KyberSwap Suffered $46 million Hack Decentralized Exchange KyberSwap Suffered $46 million Hack
Latest News More More
31 Minutes Ago Mantra and Damac sign $1B deal to tokenize Middle Eastern assets
41 Minutes Ago Fetch.ai launches $10M accelerator for AI agent startups
21 Hours Ago Fidelity’s spot bitcoin, ether ETFs post largest daily net outflows since inception
21 Hours Ago Polkadot-based Phala Network launches Ethereum Layer 2 rollup
1 Day Ago Coinbase premium flips positive for first time in weeks, indicating rising bitcoin demand from US investors
delate
Use TokenInsight App All Crypto Insights Are In Your Hands
Open