Crypto investor loses $2.6M in stablecoins in double phishing scam
A single victim was scammed two times within three hours, losing a total of $2.6 million in stablecoins.According to data shared on May 26 by crypto compliance firm Cyvers, the victim sent 843,000 worth of USDt (USDT), f...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
A single victim was scammed two times within three hours, losing a total of $2.6 million in stablecoins.
According to data shared on May 26 by crypto compliance firm Cyvers, the victim sent 843,000 worth of USDt (USDT), followed by another 1.75 million USDt around three hours later. Cyvers said the scam used a method known as a zero-value transfer, a sophisticated form of onchain phishing.
Source: Cyvers AlertZero-value transfers are an onchain phishing technique that abuses token transfer functions to trick users into sending real funds to attackers. The attackers exploit the token transfer From function to transfer zero tokens from the victim’s wallet to a spoofed address.
Since the amount transferred is zero, no signature by the victim’s private key is necessary for onchain inclusion. Consequently, the victims will see the outgoing transaction in their history.
The victim may trust this address since it is included in their transaction history, mistaking it as a known or safe recipient. They may then send real funds to the attacker’s address in a future transaction.
In one high-profile case, a scammer using a zero-transfer phishing attack managed to steal $20 million worth of USDT before getting blacklisted by the stablecoin’s issuer in the summer of 2023.
Related: Hackers using fake Ledger Live app to steal seed phrases and drain crypto
Advanced form of address poisoningA zero-value transfer is considered an evolution of address poisoning, a tactic where attackers send small amounts of cryptocurrency from a wallet address that resembles a victim’s real address, often with the same starting and ending characters. The goal is to trick the user into accidentally copying and reusing the attacker’s address in future transactions, resulting in lost funds.
The technique exploits how users often rely on partial address matching or clipboard history when sending crypto. Custom addresses with similar starting and ending characters can also be combined with zero-value transfers.
Related: Industry exec sounds alarm on Ledger phishing letter delivered by USPS
Threat growing across blockchainsA January 2025 study found that over 270 million poisoning attempts occurred on BNB Chain and Ethereum between July 1, 2022, and June 30, 2024. Of those, 6,000 attempts were successful, leading to losses over $83 million.
The report followed crypto cybersecurity firm Trugard and onchain trust protocol Webacy announcing an artificial intelligence-based system for detecting crypto wallet address poisoning. The new tool purportedly has a success score of 97%, tested across known attack cases.
Magazine: Crypto scam hub expose stunt goes viral, Kakao detects 70K scam apps: Asia Express
Why this matters
This security story adds another data point to the current market tape and is useful when read alongside nearby source coverage.
Original source
Read on CointelegraphRelated market context
Tether froze 1.45 million USDT in THORChain vaults, then reversed course three hours later
The incident highlights the vulnerability of DeFi protocols to centralized issuer actions, emphasizing the need for diversified as...
Tether freezes USDT linked to Ledger user thefts near $90 million
The freeze highlights the need for robust supply chain security and raises concerns about the limitations of centralized control i...
Tether Unfreezes Four THORChain Vaults Three Hours After Blacklisting 1.45 Million USDT
The four Tron addresses came off the USDT blacklist at 15:30 UTC with their balances intact, and THORChain has restarted Tron trad...
2,000 Bitcoin worth $166M transferred to Bitfinex from unknown wallet
Large Bitcoin transfers to exchanges like Bitfinex can signal potential market shifts, impacting investor sentiment and price stab...
Wallet linked to 2016 Bitfinex hack transferred 12,267 BTC valued at $1.01 billion to new addresses
The transfer of BTC linked to the 2016 hack may signal future market volatility and strategic shifts, impacting Bitcoin's price st...
Locked liquidity did not stop this $14 million crypto pool drain
The PancakeSwap pool for 79AU, 79thVault’s token, lost $14.35 million in USDT on Oct. 7 through two selling wallets, according to...