Researchers just uncovered 4,200 malicious smart contracts that successfully tricked 5,700 victims into signing away their crypto
Simulating transfers using safety tools inside crypto wallets can show a small gain even when the final transaction sends the user's deposit to an attacker, according to a July 30 arXiv preprint that links the technique...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
Simulating transfers using safety tools inside crypto wallets can show a small gain even when the final transaction sends the user's deposit to an attacker, according to a July 30 arXiv preprint that links the technique to 5,742 victim addresses and about $3.48 million in historical losses.
The authors used SimGuard, a contract-bytecode detector, to identify 4,224 transaction-simulation phishing contracts across Ethereum, BNB Smart Chain, Avalanche and Polygon.
The study associated them with 6,223 victim transactions but called the loss estimate an upper bound because some attacker test activity may have been misclassified. It attributed 91.5% of the losses to Ethereum and about 83% of the cross-chain total to its largest inferred cluster.
Related Reading $538M stolen by drainers: ETH & SOL wallets unite with real-time phishing blocks Inside MetaMask/Phantom’s new intel network and how we’ll measure success. Oct 23, 2025 · Gino MatosThe findings have not been peer reviewed. The paper also gives inconsistent figures for its Avalanche contract count and conflicting endpoints for the observation period, leaving its per-chain breakdown and exact time window unresolved.
How a safe-looking preview can divergeTransaction simulation takes a pre-signing snapshot of what a transaction is expected to do. The contracts described in the paper contain branches that can produce one result during that check and another when the transaction executes on-chain.
In a storage-control example, the simulation returns the user's deposit plus a tiny reward. An attacker can then change the contract's state, such as by blacklisting the user's address, before the transaction lands. The executed branch sends the deposit to an attacker-controlled address instead.
Timestamp-based contracts can exploit the later block time, while gas-control contracts can behave differently when the simulator and final transaction use different gas limits. Not every variant therefore requires an attacker to alter stored on-chain data after the preview.
In a controlled test, the authors sent an account's balance to a contract that returned as little as 1 wei, the smallest unit of ETH. They reported that several tested previews displayed a positive estimate and most did not clearly show the full outgoing amount.
The paper does not identify the wallet versions, settings, or simulation backends used by the historical victims. MetaMask's current documentation calls estimated balance changes predictions and warns that the final outcome is not guaranteed.
Related Reading MetaMask opens AI wallet for DeFi agents as security risks shift to user rules Agent Wallet lets software trade onchain, making user-set limits the new line between automation and loss. Jun 10, 2026 · Liam 'Akiba' WrightA Jan. 8, 2025 Etherscan transaction cited by the study records a Claim() call moving about 143.45 ETH through a contract Etherscan labels as phishing. The on-chain record supports the transfer described in the paper, although it cannot show what appeared in the user's wallet preview.
The authors recommend re-running simulations when relevant contract state or gas fields change, using the gas limit and gas price in the actual request, and testing current and future block-number and timestamp inputs. Their UI findings also support showing the gross amount leaving a wallet alongside an accurate net balance change, so a negligible refund cannot be mistaken for a profit.
Related Reading Hundreds of MetaMask wallets drained: What to check before you ‘update' ZachXBT tracked $107,000 drained from hundreds of wallets through fake MetaMask emails. Here's how to spot phishing, revoke approvals, and segregate holdings before attackers strike. Jan 3, 2026 · Gino MatosThe preprint describes historical activity, not a live July or August attack wave. Its detector evaluation covered 44 contracts, including 30 generated with Gemini, and the linked code-and-data repository returned HTTP 401 when checked.
The aggregate results therefore remain the authors' findings rather than an independently reproduced measurement.
The post Researchers just uncovered 4,200 malicious smart contracts that successfully tricked 5,700 victims into signing away their crypto appeared first on CryptoSlate.
Why this matters
Ethereum is showing up inside the Security Incidents theme, so this story is worth tracking for follow-through rather than treating it as a one-off headline.
Original source
Read on CryptoSlateRelated market context
Bitget Halts Withdrawals After $351.6M Hot Wallet Incident Hits Crypto Exchange
Key Takeaways: Bitget reported unauthorized transactions of about $351.6 million that occurred in a portion of its hot & warm wall...
Old Magic Eden NFT approvals put users at risk after whitehat moves 3,832 NFTs
Old Magic Eden NFT approvals could still put some former users at risk months after the company closed its Ethereum marketplace. A...
US Charges Man After Crypto Scam Wallets Received More Than $53M
TL;DR U.S. prosecutors have charged a Vietnamese national with money laundering tied to alleged cryptocurrency “pig butchering” sc...
D’CENT app wallet attack drains 12.4M XRP from thousands of users over 10-day spree
The attack highlights the critical need for robust security measures and timely updates to prevent large-scale cryptocurrency thef...
Ethereum, Solana and Zcash Face Wild Year-End Price Predictions
Three cryptocurrencies, three very different bets and millions of dollars riding on what happens before New Year’s Day. Prediction...
ARK partners with Securitize to put a venture fund on Ethereum, but leaves exit doors locked
ARK Invest and Securitize announced on Sept. 24 that eligible investors would be able to hold tokenized interests in the ARK Ventu...