Users Lost $69M in $WBTC due to Address Poisoning

Users Lost $69M in $WBTC due to Address Poisoning

Reported by The Defiant, an unsuspecting user lost $69 million in WBTC after sending the funds to an address linked with an attack known as address poisoning.

Web3 cybersecurity firm Certik first alerted of the malicious transaction early Friday morning. The attacker mimicked a transfer of 0.05 ETH, or $150, which led the victim to send the funds to the wrong address, according to Certik’s X account.

Poisoning addresses refers to attackers sending spam transactions to an address in order to confuse inattentive users. Users then copy the fraudulent address–which usually begins and ends with the same six digits– instead of sending funds to a legitimate wallet address.

Hackers can know an address linked to a user’s exchange account because of recurring payments and other transaction flows.

The pseudonymous Officer, a threat researcher formerly of the Web3 cybersecurity firm ImmuneFi, told The Defiant that these types of attacks are very common but usually have a low success rate.

According to Etherscan, after the attack, the perpetrator moved the funds in eight separate transactions.

According to Officer, many users are lazy when operating in the crypto space.

“A lot of people have a bad habit of blind copying the last address from their transaction history, just to be sure,” he said. Hackers take advantage of this behavior by sending small sums of crypto from similar-looking addresses.

How to counter such attacks?

“Don't trust Clipboard especially given the fact that malware with almost the same scheme exists (it usually targets a clipboard), check all digits one by one and add hot addresses to the allow list (if possible),” he warned.

Exploits have been on a negative curve during 2024.

Hackers stole $336 million in crypto in the first quarter this year, a 23% drop from the same time last year, according to the latest report by Web3 security firm ImmuneFi.

Source

Security Incidents

Related News
Bybit hackers move over half the stolen ETH onto Bitcoin, largely using ThorChain Bybit hackers move over half the stolen ETH onto Bitcoin, largely using ThorChain
Stablecoin neobank Infini exploited for $49 million: security analysts Stablecoin neobank Infini exploited for $49 million: security analysts
NoOnes CEO Ray Youssef discloses $8 million exploit weeks after the fact, confirming crypto sleuth ZachXBT's investigation NoOnes CEO Ray Youssef discloses $8 million exploit weeks after the fact, confirming crypto sleuth ZachXBT's investigation
Lending Protocol Sonne Finance Exploited for $20M Lending Protocol Sonne Finance Exploited for $20M
Prisma Finance Exploited for $12M Prisma Finance Exploited for $12M
Latest News More More
7 Hours Ago Argentine prosecutor seeks to freeze $110 million in proceeds tied to Libra memecoin scandal: report
7 Hours Ago Mt. Gox moves over $1 billion worth of bitcoin to unmarked address: Arkham
1 Day Ago Ethereum devs activate Pectra upgrade on Sepolia testnet in last phase before mainnet rollout
1 Day Ago Binance Records $3.97B Weekly Inflows
1 Day Ago MEXC Partners With Hacken to Increase Security Standards
delate
Use TokenInsight App All Crypto Insights Are In Your Hands
Open