April Sees Yearly Low of $38M in Crypto Phishing
Phishing attacks within the crypto industry decreased by 46% to $38 million in April, marking the lowest amount recorded this year, according to the security firm Scam Sniffer. Notably, this decline aligns with CertiK’s...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
Phishing attacks within the crypto industry decreased by 46% to $38 million in April, marking the lowest amount recorded this year, according to the security firm Scam Sniffer. Notably, this decline aligns with CertiK’s findings, indicating that crypto-related exploits and scams reached a historic low of $25.7 million in April.
April’s Phishing Attack InsightsAccording to Scam Sniffer’s analysis, the Coinbase-backed Ethereum layer-2 network Base experienced a notable surge of 145% to $8.2 million in phishing incidents during the past month. Interestingly, two of the top 10 largest single thefts occurred on this chain, constituting 21% of the month’s total theft.
ERC-20 tokens faced the brunt of these attacks, with a staggering 88% of the stolen assets belonging to this class.
Tools and Tactics Employed by AttackersScam Sniffer has pinpointed fake accounts on the social media platform X (previously known as Twitter) as the primary tool utilized by scammers. These attackers impersonated prominent projects like Renzo, Avail, Ether.fi, Wormhole, and Omni. These fake accounts often displayed counterfeit verification marks, giving them an appearance of authenticity that was exploited to lure unsuspecting users.
Using these fake accounts, the attackers posted deceptive comments on social media platforms to redirect unsuspecting individuals to malicious sites where their assets could be stolen.
Additionally, the attackers frequently utilized phishing signatures such as Permit, IncreaseAllowance, and Uniswap Permit2. These malicious signatures enabled the attackers to access their victim’s funds without their knowledge.
Scam Sniffer further added that despite wallets increasing phishing alerts for certain signatures, wallet drainers are actively finding ways to circumvent these alerts by using legitimate contracts like Disperse and Uniswap Multicall, along with variants of value normalization.
Featured Image: Freepik
Why this matters
This security story adds another data point to the current market tape and is useful when read alongside nearby source coverage.
Original source
Read on CryptoCurrencyNewsRelated market context
With violent crypto home invasions surging, a data breach exposing over 10,000 Trezor owners puts physical safety on the line
On Aug. 13, Trezor said a breach at the fulfillment provider ShipMonk exposed customer data for about 13,689 hardware wallet buyer...
Study finds 65,340 risky crypto addresses tied to $574 million in losses
A study presented at USENIX Security '26 identified 65,340 risky crypto addresses involved in misuse across Ethereum and BNB Smart...
Morgan Stanley’s Bitcoin ETF drew $371 million of share contributions while Bitcoin erased $66.8 million
Morgan Stanley Bitcoin Trust (MSBT) recorded a $66.8 million decrease in net assets from operations during its first 85 days, even...
Metaplanet burned through 83% of a $500 million credit line to build 43,000 BTC, and now it wants investors to fund the next leg
Metaplanet moved over 5,000 Bitcoin (worth about $322 million) this week, triggering market speculation that the firm might be liq...
Why millions of everyday savers will soon own Bitcoin without ever downloading a crypto app
A future Bitcoin buyer may encounter the asset through a portfolio they already own. An adviser can add a small allocation, a brok...
Trezor Data Breach Exposes 13,689 Users, Crypto Wallets Remain Safe From Attack
Key Takeaways: Through a leak in the software of its shipping partner ShipMonk, Trezor disclosed private information related to ap...