Close Menu
StreamLineCrypto.comStreamLineCrypto.com
  • Home
  • Crypto News
  • Bitcoin
  • Altcoins
  • NFT
  • Defi
  • Blockchain
  • Metaverse
  • Regulations
  • Trading
What's Hot

Researchers just uncovered 4,200 malicious smart contracts that successfully tricked 5,700 victims into signing away their crypto

August 3, 2026

Crypto Clarity Act Risks More Delay As Recess Looms

August 3, 2026

What is restaking and how EigenLayer turns staked ETH into shared security

August 3, 2026
Facebook X (Twitter) Instagram
Monday, August 3 2026
  • Contact Us
  • Privacy Policy
  • Cookie Privacy Policy
  • Terms of Use
  • DMCA
Facebook X (Twitter) Instagram
StreamLineCrypto.comStreamLineCrypto.com
  • Home
  • Crypto News
  • Bitcoin
  • Altcoins
  • NFT
  • Defi
  • Blockchain
  • Metaverse
  • Regulations
  • Trading
StreamLineCrypto.comStreamLineCrypto.com

Researchers just uncovered 4,200 malicious smart contracts that successfully tricked 5,700 victims into signing away their crypto

August 3, 2026Updated:August 3, 2026No Comments4 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Researchers just uncovered 4,200 malicious smart contracts that successfully tricked 5,700 victims into signing away their crypto
Share
Facebook Twitter LinkedIn Pinterest Email
ad


Simulating transfers utilizing security instruments inside crypto wallets can present a small achieve even when the ultimate transaction sends the consumer’s deposit to an attacker, in response to a July 30 arXiv preprint that hyperlinks the approach to five,742 sufferer addresses and about $3.48 million in historic losses.

The authors used SimGuard, a contract-bytecode detector, to determine 4,224 transaction-simulation phishing contracts throughout Ethereum, BNB Good Chain, Avalanche and Polygon.

The examine related them with 6,223 sufferer transactions however known as the loss estimate an higher sure as a result of some attacker take a look at exercise could have been misclassified. It attributed 91.5% of the losses to Ethereum and about 83% of the cross-chain complete to its largest inferred cluster.

Researchers just uncovered 4,200 malicious smart contracts that successfully tricked 5,700 victims into signing away their crypto$538M stolen by drainers: ETH & SOL wallets unite with real-time phishing blocks
Associated Studying

$538M stolen by drainers: ETH & SOL wallets unite with real-time phishing blocks

Inside MetaMask/Phantom’s new intel community and the way we’ll measure success.

Oct 23, 2025 · Gino Matos

The findings haven’t been peer reviewed. The paper additionally provides inconsistent figures for its Avalanche contract rely and conflicting endpoints for the commentary interval, leaving its per-chain breakdown and actual time window unresolved.

How a safe-looking preview can diverge

Transaction simulation takes a pre-signing snapshot of what a transaction is anticipated to do. The contracts described within the paper comprise branches that may produce one consequence throughout that examine and one other when the transaction executes on-chain.

Infographic showing how a safe-looking wallet simulation can diverge before execution, with study figures for contracts, victim addresses, transactions and estimated losses.Infographic showing how a safe-looking wallet simulation can diverge before execution, with study figures for contracts, victim addresses, transactions and estimated losses.

In a storage-control instance, the simulation returns the consumer’s deposit plus a tiny reward. An attacker can then change the contract’s state, similar to by blacklisting the consumer’s tackle, earlier than the transaction lands. The executed department sends the deposit to an attacker-controlled tackle as an alternative.

Timestamp-based contracts can exploit the later block time, whereas gas-control contracts can behave in another way when the simulator and ultimate transaction use totally different fuel limits. Not each variant subsequently requires an attacker to change saved on-chain information after the preview.

In a managed take a look at, the authors despatched an account’s steadiness to a contract that returned as little as 1 wei, the smallest unit of ETH. They reported that a number of examined previews displayed a optimistic estimate and most didn’t clearly present the total outgoing quantity.

CryptoSlate Each day Temporary

Each day indicators, zero noise.

Market-moving headlines and context delivered each morning in a single tight learn.

5-minute digest 100k+ readers

Free. No spam. Unsubscribe any time.

Whoops, appears to be like like there was an issue. Please strive once more.

You’re subscribed. Welcome aboard.

The paper doesn’t determine the pockets variations, settings, or simulation backends utilized by the historic victims. MetaMask’s present documentation calls estimated steadiness adjustments predictions and warns that the ultimate consequence isn’t assured.

MetaMask opens AI wallet for DeFi agents as security risks shift to user rulesMetaMask opens AI wallet for DeFi agents as security risks shift to user rules
Associated Studying

MetaMask opens AI pockets for DeFi brokers as safety dangers shift to consumer guidelines

Agent Pockets lets software program commerce onchain, making user-set limits the brand new line between automation and loss.

Jun 10, 2026 · Liam ‘Akiba’ Wright

A Jan. 8, 2025 Etherscan transaction cited by the examine information a Declare() name shifting about 143.45 ETH via a contract Etherscan labels as phishing. The on-chain document helps the switch described within the paper, though it can’t present what appeared within the consumer’s pockets preview.

The authors suggest re-running simulations when related contract state or fuel fields change, utilizing the fuel restrict and fuel value within the precise request, and testing present and future block-number and timestamp inputs. Their UI findings additionally assist displaying the gross quantity leaving a pockets alongside an correct web steadiness change, so a negligible refund can’t be mistaken for a revenue.

Hundreds of MetaMask wallets drained: What to check before you ‘update'Hundreds of MetaMask wallets drained: What to check before you ‘update'
Associated Studying

A whole lot of MetaMask wallets drained: What to examine earlier than you ‘replace’

ZachXBT tracked $107,000 drained from tons of of wallets via faux MetaMask emails. Here is tips on how to spot phishing, revoke approvals, and segregate holdings earlier than attackers strike.

Jan 3, 2026 · Gino Matos

The preprint describes historic exercise, not a dwell July or August assault wave. Its detector analysis lined 44 contracts, together with 30 generated with Gemini, and the linked code-and-data repository returned HTTP 401 when checked.

The combination outcomes subsequently stay the authors’ findings somewhat than an independently reproduced measurement.



Source link

ad
contracts Crypto Malicious researchers Signing Smart Successfully tricked uncovered victims
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Related Posts

Crypto Clarity Act Risks More Delay As Recess Looms

August 3, 2026

What is restaking and how EigenLayer turns staked ETH into shared security

August 3, 2026

Trump-backed American Bitcoin (ABTC) executive Matt Prusak joins Giga Energy

August 3, 2026

Hashdex Will Liquidate Market’s Smallest Bitcoin ETF DEFI

August 3, 2026
Add A Comment
Leave A Reply Cancel Reply

ad
What's New Here!
Researchers just uncovered 4,200 malicious smart contracts that successfully tricked 5,700 victims into signing away their crypto
August 3, 2026
Crypto Clarity Act Risks More Delay As Recess Looms
August 3, 2026
What is restaking and how EigenLayer turns staked ETH into shared security
August 3, 2026
Trump-backed American Bitcoin (ABTC) executive Matt Prusak joins Giga Energy
August 3, 2026
Hashdex Will Liquidate Market’s Smallest Bitcoin ETF DEFI
August 3, 2026
Facebook X (Twitter) Instagram Pinterest
  • Contact Us
  • Privacy Policy
  • Cookie Privacy Policy
  • Terms of Use
  • DMCA
© 2026 StreamlineCrypto.com - All Rights Reserved!

Type above and press Enter to search. Press Esc to cancel.