tradingkey.logo

A crypto investor has lost over $3 million through a malicious phishing attack

Cryptopolitan2025年8月6日 16:44

A cryptocurrency investor has lost over $3 million in Tether (USDT) through a malicious phishing attack. The victim allegedly approved a transaction without knowing it was a malicious social engineering scam.

Analytics platform Lookonchain reported on Wednesday that someone fell victim to a phishing attack and lost $3.05M in USDT. The firm urged people to stay alert and safe, since one wrong click can drain their entire wallet. Lookonchain also cautioned people never to sign a transaction they don’t fully understand.

Phishing scam incidents surge in 2025

Attackers tend to share fraudulent links with victims to steal their sensitive information, such as wallets and private keys. Some victims fail to authenticate the full characters of the wallet addresses, as the middle part is often hidden on platforms.

On-chain data also revealed Sunday that another victim lost over $900,000 worth of virtual currencies to a malicious phishing attack. The attacker allegedly waited for around 458 days after the malicious approval went through and waited for the victim to add funds to the address before the breach.

Scam Sniffer, who exposes crypto scams, revealed that the scammer stole $908,551 worth of USDC on August 2 after signing the phishing approval transaction on April 30, 2024. He warned crypto users to be careful with approvals or fall victim to such social engineering attacks.

In May 2024, a victim fell into a phishing scheme and lost roughly $71 million. The scammer allegedly returned the funds in two weeks after mounting pressure from global blockchain investigators who revealed his potential Hong Kong-based IP address.

Certik’s annual Web3 security report revealed that phishing attacks were the most costly vector for the crypto sector in 2024. According to the report, phishing schemes netted over $1 billion worth of virtual currencies across 296 incidents.

Source: Certik.  Phishing Scam Incidents and losses in 2024 by month.

The firm’s spokesperson mentioned that the figures could be higher if unreported incidents and attacks like pig butchering are included. The spokesperson also cautioned that phishing scams could surge in 2025 due to the developments in artificial intelligence.

Certik also released its Web3 security report for the second quarter and first half of 2025, showing a growing number of phishing incidents. Phishing attacks accounted for over $395 million stolen across 52 incidents.

The firm reported that over $801 million was lost across 144 incidents in Q2, a 52.1% decrease in value lost in the previous quarter. The Ethereum network saw a total of $65.4M lost in 70 attack breaches.

According to the report, between January and June, the crypto industry saw a total of over $2.5 billion lost across 344 incidents. Spoofing accounted for a large chunk of the security breaches, with $410.7 million stolen across 132 security breaches.  The analytics firm also urged users to be cautious, avoid suspicious URLs, double-check links, and use hardware wallets for storage.

Tools exist to mitigate phishing attacks

Ethereum users can mitigate attacks on the network by leveraging Etherscan’s Token Approval Checker to review and revoke unnecessary token approvals. Users will also have to pay a gas fee for each revocation on the checker.

A group of ethical hackers established the anti-hack response team in August 2023, led by white hat hacker Samczun. The Security Alliance aims to make protocols more resilient to cyberattacks. The group also published the Whitehat Safe Harbor Agreement, which was meant to provide financial assistance to white hats facing legal action.

The world’s largest crypto exchange, Binance, also developed an “antidote” to address phishing scams. The program detects spoofed addresses and alerts users before they send digital assets to scammers.

KEY Difference Wire helps crypto brands break through and dominate headlines fast

免责声明:本网站提供的信息仅供教育和参考之用,不应视为财务或投资建议。

相关文章

tradingkey.logo
tradingkey.logo
日内数据由路孚特(Refinitiv)提供,并受使用条款约束。历史及当前收盘数据均由路孚特提供。所有报价均以当地交易所时间为准。美股报价的实时最后成交数据仅反映通过纳斯达克报告的交易。日内数据延迟至少15分钟或遵循交易所要求。
* 参考、分析和交易策略由第三方提供商Trading Central提供,观点基于分析师的独立评估和判断,未考虑投资者的投资目标和财务状况。
风险提示:我们的网站和移动应用程序仅提供关于某些投资产品的一般信息。Finsights 不提供财务建议或对任何投资产品的推荐,且提供此类信息不应被解释为 Finsights 提供财务建议或推荐。
投资产品存在重大投资风险,包括可能损失投资的本金,且可能并不适合所有人。投资产品的过去表现并不代表其未来表现。
Finsights 可能允许第三方广告商或关联公司在我们的网站或移动应用程序的任何部分放置或投放广告,并可能根据您与广告的互动情况获得报酬。
© 版权所有: FINSIGHTS MEDIA PTE. LTD. 版权所有
KeyAI