A victim of a $24 million phishing attack has received a partial refund after the perpetrator voluntarily returned some of the stolen funds.
According to Scam Sniffer, a web3 anti-scam solution, the attacker sent back $9.3 million to the victim. The theft occurred in late 2023, involving 9,579 Lido Staked Ether (stETH) and 4,850 Rocket Pool (rETH) tokens.
💰 The scammer returned $9.27M in DAI to the victim.
(credits: @bax1337) https://t.co/xwSASQOUis pic.twitter.com/T5vF1Ak3wo
— Scam Sniffer | Web3 Anti-Scam (@realScamSniffer) July 13, 2024
The victim fell prey to the attack by approving “Increase Allowance” transactions during the phishing incident, a common tactic used to gain control over assets within a wallet.
This vulnerability, particularly with ERC-20 tokens, allows bad actors to exploit users through malicious smart contracts. The attacker, using the Railgun privacy protocol, obscured the returned funds, totaling 38.84% of the stolen amount.
Despite rare instances of funds being returned by attackers, phishing scams remain a significant issue in the crypto industry, with losses exceeding $290 million reported by Scam Sniffer in 2023 alone.
A decentralized exchange targeted in a multi-million-dollar exploit has recovered its losses just days after the incident, thanks to an unexpected twist involving the hacker themselves.
A recent cyberattack targeting a UK government official’s social media account has highlighted ongoing concerns over digital impersonation and crypto scams.
A former NFT trader is facing potential prison time after admitting to hiding millions in profits from the IRS through undeclared sales of high-value digital assets.
Cybersecurity researchers are sounding the alarm after discovering a new and increasingly sophisticated attack targeting the crypto community.