A victim of a $24 million phishing attack has received a partial refund after the perpetrator voluntarily returned some of the stolen funds.
According to Scam Sniffer, a web3 anti-scam solution, the attacker sent back $9.3 million to the victim. The theft occurred in late 2023, involving 9,579 Lido Staked Ether (stETH) and 4,850 Rocket Pool (rETH) tokens.
💰 The scammer returned $9.27M in DAI to the victim.
(credits: @bax1337) https://t.co/xwSASQOUis pic.twitter.com/T5vF1Ak3wo
— Scam Sniffer | Web3 Anti-Scam (@realScamSniffer) July 13, 2024
The victim fell prey to the attack by approving “Increase Allowance” transactions during the phishing incident, a common tactic used to gain control over assets within a wallet.
This vulnerability, particularly with ERC-20 tokens, allows bad actors to exploit users through malicious smart contracts. The attacker, using the Railgun privacy protocol, obscured the returned funds, totaling 38.84% of the stolen amount.
Despite rare instances of funds being returned by attackers, phishing scams remain a significant issue in the crypto industry, with losses exceeding $290 million reported by Scam Sniffer in 2023 alone.
The U.S. Department of Justice has sentenced Dwayne Golden, 57, of Pennsylvania to 97 months in prison for orchestrating a fraudulent crypto investment scheme that stole over $40 million from investors.
The first half of 2025 has become the most damaging six-month period in crypto history, with over $2.1 billion stolen across 75+ separate incidents, according to new data.
A new breed of cyber-attack is sweeping through crypto media, exploiting site pop-ups and wallet-connect prompts instead of smart-contract bugs.
CoinMarketCap, one of the most widely used crypto data tracking platforms, is reportedly facing a front-end security breach, with multiple users encountering a suspicious prompt to verify their wallets.