CCT - Crypto Currency Tracker logo CCT - Crypto Currency Tracker logo
Cryptopolitan 2026-01-03 19:15:02

Unlucky crypto user loses over $1 million in a phishing attack

According to multiple reports, one crypto user lost approximately $1.08 million worth of Aave-wrapped Ethereum LBTC (aEthLBTC), which is a tokenized Bitcoin asset on the Aave protocol, in what is likely a phishing exploit. According to ScamSniffer, the user in question had signed a malicious “permit” signature, which was what led to the theft. That signature was an off-chain approval mechanism, and it allegedly allows tokens to be spent without triggering an immediate on-chain transaction. ScamSniffer shared screenshots of the transactions. As to how the victim was susceptible to the exploit, they believe the scammers would have gotten the victim to sign the permit via a phishing site or cloned dApp, giving them access to drain the wallet. How did the scam happen? SlowMist’s founder, Cosine, commented on the haul, pointing out that the specific phishing group behind the attack is not one of the “mainstream” drainer groups, which suggests an emergence of smaller, sophisticated independent attackers. They also moved fast, rapidly converting the funds to ETH and then laundering the funds immediately via Tornado Cash. The incident was highlighted on January 3 by ScamSniffer via its X page, not long after it dropped its 2025 yearly report. In the report , as reviewed by Cryptoplitan, it revealed there was an overall 83% drop in crypto phishing losses, falling from $494 million to $84 million. However, it emphasized that sophisticated wallet drainers still abound. They just seem to be targeting high-value holders with permit-oriented attacks, as is often the case during a bull market. Permit-based exploits depend on the user’s trust in routine signature requests that actually authorize token transfers off-chain. Unfortunately for scams like these, recovery is very unlikely as the draining happens on-chain and transactions are irreversible. Crypto phishing losses went down, but wrench attacks went up While ScamSniffer has confirmed crypto phishing losses went down in 2025, crypto security experts claim the frequency of so-called “$5 wrench attacks” went up. Ari Redbord, the global head of policy and government affairs at crypto analytics firm TRM Labs, called 2025 a record year for wrench attacks, with roughly 60 reported physical assaults on crypto holders, up from 41 in 2024 and 36 in 2021. However, Redbord believes the actual number of attacks that have happened is significantly higher. “Many incidents are logged simply as robberies or burglaries, with the crypto element omitted, while others are never reported due to victim hesitation or uncertainty about how law enforcement will handle crypto-related crimes,” Redbord claimed. The cybersecurity risk called the “ wrench attack ” derives its name from the idea that even the most sophisticated forms of encryption and data security are susceptible to physical coercion — like getting threatened by a “$5 wrench.” These attacks are inarguably worse than phishing exploits and protocol hacks as they not only put assets at risk but also lives, increasing the stakes for maintaining proper OPSEC beyond wallet management best practices. “No matter how many technical precautions you take or how many factors you authenticate with, no individual is immune to human attack vectors,” Tor Bair, CEO of Hybrid Minds Advisory and former president of the Secret Foundation, said. Although the true number of wrench attacks is difficult to quantify, there appears to be either a higher risk of victimization or, at least, a greater awareness of the threat. Last year May, French Interior Minister Bruno Retailleau spoke up about the rise of crypto-related assaults in the country, which at the time was the site of about one-third of wrench attacks in 2025, including the high-profile kidnapping and torture of Ledger co-founder David Balland and his wife in January. If you're reading this, you’re already ahead. Stay there with our newsletter .

면책 조항 읽기 : 본 웹 사이트, 하이퍼 링크 사이트, 관련 응용 프로그램, 포럼, 블로그, 소셜 미디어 계정 및 기타 플랫폼 (이하 "사이트")에 제공된 모든 콘텐츠는 제 3 자 출처에서 구입 한 일반적인 정보 용입니다. 우리는 정확성과 업데이트 성을 포함하여 우리의 콘텐츠와 관련하여 어떠한 종류의 보증도하지 않습니다. 우리가 제공하는 컨텐츠의 어떤 부분도 금융 조언, 법률 자문 또는 기타 용도에 대한 귀하의 특정 신뢰를위한 다른 형태의 조언을 구성하지 않습니다. 당사 콘텐츠의 사용 또는 의존은 전적으로 귀하의 책임과 재량에 달려 있습니다. 당신은 그들에게 의존하기 전에 우리 자신의 연구를 수행하고, 검토하고, 분석하고, 검증해야합니다. 거래는 큰 손실로 이어질 수있는 매우 위험한 활동이므로 결정을 내리기 전에 재무 고문에게 문의하십시오. 본 사이트의 어떠한 콘텐츠도 모집 또는 제공을 목적으로하지 않습니다.