Cryptocurrency [loss] $8M+

Tweets about "permit phishing" by ScamSniffer

2023-04-30 [vendor] "Permit phishing" [chain] ethereum
Primary Source ↗
Financial Loss $7.8M (7,769,000 USD)
Blockchain(s) Ethereum

Incident Details

Between March and April 2023, the Scam Sniffer organization has identified at least $7.7 million stolen by so-called “permit phishers”. These attackers convince their victims to sign malicious crypto transactions that use the “permit” functionality, which allows the attackers to siphon funds from the crypto wallets. This type of attack has existed for over a year, but there have been some high-value instances of the attack lately.On March 11, ScamSniffer tweeted that they had detected 162 instances of the scam, totaling almost $4 million stolen, over the prior two days. On March 24, an individual wallet lost $4 million. Similar attacks on April 19, April 21, and April 30 saw individual wallets lose $449,000, $1.04 million, and $2.28 million, respectively.

Total loss estimated at $7,769,000.

Technical Details

Initial Attack Vector
Smart contract exploit / hack
Vendor / Product
"Permit phishing"

Timeline

  1. 2023-04-30 Breach occurred
  2. 2023-04-30 Publicly disclosed