A victim of a $24 million phishing attack has received a partial refund after the perpetrator voluntarily returned some of the stolen funds.
According to Scam Sniffer, a web3 anti-scam solution, the attacker sent back $9.3 million to the victim. The theft occurred in late 2023, involving 9,579 Lido Staked Ether (stETH) and 4,850 Rocket Pool (rETH) tokens.
💰 The scammer returned $9.27M in DAI to the victim.
(credits: @bax1337) https://t.co/xwSASQOUis pic.twitter.com/T5vF1Ak3wo
— Scam Sniffer | Web3 Anti-Scam (@realScamSniffer) July 13, 2024
The victim fell prey to the attack by approving “Increase Allowance” transactions during the phishing incident, a common tactic used to gain control over assets within a wallet.
This vulnerability, particularly with ERC-20 tokens, allows bad actors to exploit users through malicious smart contracts. The attacker, using the Railgun privacy protocol, obscured the returned funds, totaling 38.84% of the stolen amount.
Despite rare instances of funds being returned by attackers, phishing scams remain a significant issue in the crypto industry, with losses exceeding $290 million reported by Scam Sniffer in 2023 alone.
Chris Larsen, the co-founder of Ripple, suffered a significant financial blow in 2024 when he lost over $661 million worth of XRP due to a security breach in the password management system LastPass.
Venture capitalist and Mission Gate founder George Bachiashvili is now facing imprisonment in Georgia after a court revoked his bail.
Hackers have exploited a vulnerability in DeFi aggregator 1inch’s resolver smart contract, leading to losses of over $5 million, according to blockchain security firm SlowMist.
Tether has taken a significant step by freezing $27 million worth of USDt on the Russian crypto exchange Garantex, which has led to the platform halting its operations.