|

Researchers just uncovered 4,200 malicious smart contracts that successfully tricked 5,700 victims into signing away their crypto

$538M stolen by drainers: ETH & SOL wallets unite with real-time phishing blocks

Simulating transfers utilizing security instruments inside crypto wallets can present a small achieve even when the ultimate transaction sends the person’s deposit to an attacker, based on a July 30 arXiv preprint that hyperlinks the approach to five,742 sufferer addresses and about $3.48 million in historic losses.

The authors used SimGuard, a contract-bytecode detector, to determine 4,224 transaction-simulation phishing contracts throughout Ethereum, BNB Smart Chain, Avalanche and Polygon.

The examine related them with 6,223 sufferer transactions however known as the loss estimate an higher certain as a result of some attacker check exercise could have been misclassified. It attributed 91.5% of the losses to Ethereum and about 83% of the cross-chain complete to its largest inferred cluster.

$538M stolen by drainers: ETH & SOL wallets unite with real-time phishing blocks
Related Reading

$538M stolen by drainers: ETH & SOL wallets unite with real-time phishing blocks

Inside MetaMask/Phantom’s new intel network and how we’ll measure success.
Oct 23, 2025
·
Gino Matos

The findings haven’t been peer reviewed. The paper additionally provides inconsistent figures for its Avalanche contract depend and conflicting endpoints for the remark interval, leaving its per-chain breakdown and precise time window unresolved.

How a safe-looking preview can diverge

Transaction simulation takes a pre-signing snapshot of what a transaction is predicted to do. The contracts described within the paper include branches that can produce one end result throughout that test and one other when the transaction executes on-chain.

Infographic showing how a safe-looking wallet simulation can diverge before execution, with study figures for contracts, victim addresses, transactions and estimated losses.

In a storage-control instance, the simulation returns the person’s deposit plus a tiny reward. An attacker can then change the contract’s state, resembling by blacklisting the person’s handle, earlier than the transaction lands. The executed department sends the deposit to an attacker-controlled handle as a substitute.

Timestamp-based contracts can exploit the later block time, whereas gas-control contracts can behave in a different way when the simulator and ultimate transaction use completely different gasoline limits. Not each variant due to this fact requires an attacker to change saved on-chain knowledge after the preview.

In a managed check, the authors despatched an account’s steadiness to a contract that returned as little as 1 wei, the smallest unit of ETH. They reported that a number of examined previews displayed a constructive estimate and most didn’t clearly present the total outgoing quantity.

The paper doesn’t determine the pockets variations, settings, or simulation backends utilized by the historic victims. MetaMask’s current documentation calls estimated steadiness modifications predictions and warns that the ultimate consequence isn’t assured.

MetaMask opens AI wallet for DeFi agents as security risks shift to user rules
Related Reading

MetaMask opens AI wallet for DeFi agents as security risks shift to user rules

Agent Wallet lets software trade onchain, making user-set limits the new line between automation and loss.
Jun 10, 2026
·
Liam ‘Akiba’ Wright

A Jan. 8, 2025 Etherscan transaction cited by the examine information a Claim() name transferring about 143.45 ETH by way of a contract Etherscan labels as phishing. The on-chain file helps the switch described within the paper, though it can’t present what appeared within the person’s pockets preview.

The authors advocate re-running simulations when related contract state or gasoline fields change, utilizing the gasoline restrict and gasoline value within the precise request, and testing present and future block-number and timestamp inputs. Their UI findings additionally help exhibiting the gross quantity leaving a pockets alongside an correct web steadiness change, so a negligible refund can’t be mistaken for a revenue.

Hundreds of MetaMask wallets drained: What to check before you ‘update'
Related Reading

Hundreds of MetaMask wallets drained: What to check before you ‘update’

ZachXBT tracked $107,000 drained from hundreds of wallets through fake MetaMask emails. Here’s how to spot phishing, revoke approvals, and segregate holdings before attackers strike.
Jan 3, 2026
·
Gino Matos

The preprint describes historic exercise, not a reside July or August assault wave. Its detector analysis lined 44 contracts, together with 30 generated with Gemini, and the linked code-and-data repository returned HTTP 401 when checked.

The mixture outcomes due to this fact stay the authors’ findings moderately than an independently reproduced measurement.

The put up Researchers just uncovered 4,200 malicious smart contracts that successfully tricked 5,700 victims into signing away their crypto appeared first on CryptoSlate.

Similar Posts