Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesBotsEarnCopy
Crypto Investor Loses $36M to Permit Phishing Scheme

Crypto Investor Loses $36M to Permit Phishing Scheme

CryptopotatoCryptopotato2024/10/10 16:00
By:Author: Wayne Jones

Permit phishing scams exploit user approvals in DeFi, tricking them into granting access to their wallets.

A recent cyberattack has led to an unsuspecting crypto investor reportedly losing 15,079 fwdETH, worth roughly $36 million.

In the incident, described by security experts as a permit phishing scam, the bad actor tricked the user into unknowingly signing a malicious signature, which gave the thief full access to the individual’s funds.

How it Happened

Scam Sniffer, a Web3 anti-scam platform, broke the news in an October 11 post on X, sharing the addresses of the victim and the attacker.

Five hours before the report surfaced, the victim, identified by the address 0xeab23c1e3776fad145e2e3dc56bcf739f6e0a393, signed a permit phishing signature, unknowingly authorizing the hacker to move their 15,079 fwdETH.

The exploiter, linked to the address 0x0605edee6a8b8b553cae09abe83b2ebeb75516ec, immediately sold the tokens on the market, apparently causing the price of dETH, a related asset, to crash by over 90% within 24 hours.

Chiming in on the incident, analyst roffett.eth warned that the drop in the price of dETH had affected several decentralized finance (DeFi) protocols, particularly PAC Finance and Orbit Finance since the sell-off had allegedly triggered vulnerabilities in their systems.

The Ripple Effect on DeFi

Permit phishing is still relatively new in crypto circles. It comes from criminals exploiting a requirement in certain DeFi tokens or contracts for the user to approve so-called permit signatures that grant third parties the ability to interact with their wallets, including spending or transferring funds.

Attackers usually create a fake website or interface that looks like a legitimate service or decentralized application (dApp) and then ask users to sign the “permit” transaction. This is often disguised as a legitimate request, tricking users into granting full access to their assets.

Such hacks exploit a lack of understanding around transaction permissions, allowing hackers to drain assets from even well-versed crypto users.

This isn’t the first time DeFi users have been targeted by phishing schemes. According to Scam Sniffer, something similar happened just 12 days earlier, with the victim in that incident losing 12,083 spWETH, which was then valued at about $32 million.

Due to the growing instances of such attacks, experts are urging users to be extra cautious when interacting with unfamiliar links or signing transaction permissions.

“Always double-check any signatures you’re asked to sign, and avoid clicking on unknown links,” Scam Sniffer posted as a reminder to the crypto community of the constant threat of phishing tricks.

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Locked for new tokens.
APR up to 10%. Always on, always get airdrop.
Lock now!

You may also like

Polygon Targets $1 & Ethereum Eyes $3,600, Yet BlockDAG’s CertiK Audit and $0.0019 Coins Could Outperform All

Discover Polygon (POL) price movement and Ethereum (ETH) price analysis as both eye breakouts, and see why BlockDAG’s CertiK audit, growing presale, and attractive pricing position it among the best crypto for higher returns in 2025.Polygon (POL) Price Movement Signals Breakout Toward $1Ethereum (ETH) Price Analysis: Tight Range Could Spark $3,600 BreakoutBlockDAG’s CertiK Audit Strengthens Its Case as the Best Crypto for Higher ReturnsTo Sum It Up

Coinomedia2025/05/08 04:22
Polygon Targets $1 & Ethereum Eyes $3,600, Yet BlockDAG’s CertiK Audit and $0.0019 Coins Could Outperform All

$298M Crypto Liquidations Rock BTC and ETH Traders

Crypto liquidations hit $298M in 24 hours, with BTC and ETH leading losses. Here's what caused the wipeout.A Rough Day for Crypto TradersWhat Triggered the Liquidations?Caution Ahead for Leverage Users

Coinomedia2025/05/08 04:22
$298M Crypto Liquidations Rock BTC and ETH Traders

Top New Meme Coins to Invest in This Month: Troller Cat Flaunts 7k% ROI as Official Trump and Mog Coin Rise from Slumber

Troller Cat ignites excitement with 69% APY and 7,000% ROI target. TRUMP and MOG bounce back, but is this cat the real jackpot?Troller Cat ($TCAT): Clawing Up the Ladder with Massive ROI PotentialOfficial Trump ($TRUMP): Slow Grind with Political BuzzMog Coin ($MOG): The Cult Favorite Gets a PulseConclusion

Coinomedia2025/05/08 04:22
Top New Meme Coins to Invest in This Month: Troller Cat Flaunts 7k% ROI as Official Trump and Mog Coin Rise from Slumber

SOL Technical Analysis Signals Strength, Cardano’s AI Testnet Launches & BlockDAG’s $0.0019 Offer Ends on May 13

Explore SOL Technical Analysis & details on Cardano's AI Testnet. See why BlockDAG’s $0.0019 entry before May 13 could define the best crypto platform call.SOL Technical Analysis Points to Cautious OptimismCardano’s AI Testnet to Simulate High-Frequency Network ConditionsBlockDAG’s Listings Near: $0.0019 Offer Available Until May 13What Defines the Best Crypto Platform in 2025?

Coinomedia2025/05/08 04:22
SOL Technical Analysis Signals Strength, Cardano’s AI Testnet Launches & BlockDAG’s $0.0019 Offer Ends on May 13