Cryptocurrency [loss] $60M+

"Wallet Drainers Starts Using Create2 Bypass Wallet Security Alert"

2023-11-12 [vendor] Create2 wallet drainer [chain] ethereum
Primary Source ↗
Financial Loss $60.0M (60,000,000 USD)
Affected 100K individuals/accounts
Blockchain(s) Ethereum

Incident Details

A wallet drainer service has facilitated the theft of more than $60 million in various assets from almost 100,000 victims since May 2023. According to research group ScamSniffer, the drainer has recently started using functionality in the Ethereum network called CREATE2 to generate new addresses for each malicious signature. This allows the drainer to sidestep security alerts built into some crypto wallet software that would flag known malicious addresses.ScamSniffer identified one victim who lost almost 17,000 GMX (~$927,000) to this drainer after signing a malicious transaction.

Total loss estimated at $60,000,000.

Technical Details

Initial Attack Vector
Smart contract exploit / hack
Vendor / Product
Create2 wallet drainer

Timeline

  1. 2023-11-12 Breach occurred
  2. 2023-11-12 Publicly disclosed