Crypto News

Costly Mistake: Victim Loses $68 Million In Address Poisoning Scam

Costly Mistake: Victim Loses $68 Million In Address Poisoning Scam
© Copyright Image: CryptoPotato

Crypto hackers have claimed another major victim, fooling him into sending $68 million to a wallet he thought was somebody elses.

Blockchain data indicates that a once-wealthy Ethereum user lost all of his Bitcoin holdings after hackers contaminated a recipients wallet history. The user now holds just $1.6 million in crypto at his address.

The Danger Of Address Poisoning

According to Etherscan, the sending wallets remaining assets include 0.89 ETH ($2,747) and 1.63 million dollar-pegged DAI stablecoins.

The assets stolen from the victim included 1155 Wrapped Bitcoin (WBTC) a token that operates like a stablecoin for Bitcoin on the Ethereum network, mirroring the price of the dominant digital asset. Naturally, WBTC is vulnerable to the many hacks and exploits common in the Ethereum ecosystem, such as address poisoning.

Wallet contamination or address poisoning involves sending a transaction usually of zero or negligible value to a victims wallet, simply so that the attackers address appears in the victims transaction history.

Notably, attackers will deliberately generate their address to have several starting and ending characters that match those of an address belonging to the victim. Popular wallet software often shrinks addresses to display only the first and last characters, making the differences in the middle undetectable on the surface.

Address Poisoning In Action

In this case, both the attackers address and the real target address had characters starting with 0xd9A1, and ending with 853a91.

Ideally, the attacker hopes they try to copy that address from their history the next time they intend to receive a transaction, under the mistaken belief that its their address or that of someone they know.

Last year, address poisoners targeted a series of SafeWallet users, stealing $2 million within one week. Back in February, a Kraken user was robbed of 1 million USDT after scammers poisoned their history mimicking the victims prior interaction with the exchange.

Metamask suggests users avoid copying transactions from their history, and to add frequently used addresses to their address book to avoid using any that arent specifically whitelisted.

This advice applies to your own address as much as it does the addresses of others to whom you may be sending funds, the wallet provider states on its website.

The post Costly Mistake: Victim Loses $68 Million In Address Poisoning Scam appeared first on CryptoPotato.

Read more: https://cryptopotato.com/costly-mistake-victim-loses-68-million-in-address-poisoning-scam/

Text source: CryptoPotato

Disclaimer: Financial information and news are not financial advice, read the disclaimer.
Buy & sell Crypto in minutes

Join BINANCE!

The world's largest crypto exchange

You're just steps away from receiving your reward.

The most complete Crypto News Center.

Search Stories:

Latest top stories