Hackers Exploit New Feature To Bypass Security Alerts – Report

2023-11-12 16:40

In a concerning trend, hackers, specifically wallet drainers, have begun to leverage the CREATE2 opcode on the Ethereum network to sidestep security measures in select wallets. This development was revealed on Sunday via an X post by blockchain security company Scam Sniffer. 

Over $60 Million Lost To Hackers Via CREATE2 Exploit, Report Says

The CREATE2 opcode was designed to allow the prediction of a contract address before deployment. Most notably, it is used by prominent decentralized exchange Uniswap to facilitate the creation of pair contracts. 

However, using this feature, cybercriminals have found a way to bypass security checks in regard to investor wallets. Scam Sniffer explains that hackers use CREATE2 to effortlessly generate momentary new addresses, each with a malicious signature. 

When unsuspecting investors sign this crafted signature, the hackers deploy a contract at the predicted address and process an unauthorized transfer of assets. Using this technique, these bad actors have been able to operate undetected, siphoning large amounts of funds from innocent victims.

1/ Here is a real case happened 9 hours ago

A victim lost $927k worth of $GMX after signing a `signalTransfer(address receiver)` transaction to the GMX Reward Router on Arbitrum.https://t.co/kB2Je5a0pK https://t.co/78k82fbRfk pic.twitter.com/izfKPeBW9p

— Scam Sniffer | Web3 Anti-Scam (@realScamSniffer) November 12, 2023

Speaking about a sample incident, Scam Sniffer explains how a victim lost $927,000 worth of GMX on Sunday after unknowingly authorizing a “signalTransfer” transaction that allowed hackers to withdraw these assets to a pre-computed contract address. 

In total, Scam Sniffer revealed that the main group of wallet drainers exploiting the CREATE2 feature has so far stolen $60 million from an estimated 99,000 victims in the last six months. 

Meanwhile, during a discussion with SlowMist, another prominent blockchain security firm, Scam Sniffer learned a separate group of hackers has been using the same technique in address poisoning.

Since August, findings reveal that this second group has stolen nearly $3 million worth of assets from 11 victims, of which $1.6 million belonged to a single victim. In wrapping up its report, Scam Sniffer reminds crypto users to stay on alert and verify every transaction, as the continuous cycle of detection and counter-detection in the crypto space will likely not end.

Beyond Hacks, Crypto Scams Remain A Peril

Just like hacks, crypto scams are also still considered a major source of concern for many investors. According to FootPrint x Boesin’s H1 2023 security report, scams resulted in a total asset loss of $184.17 million, accounting for 28% of losses recorded by investors in the first half of the year. 

Notably, Scam Sniffer has reported two major scam incidents over the last 48 hours in which both victims lost a combined $468, 000 worth of assets. These attacks only underscore the continuous need for enhanced security measures in the cryptocurrency ecosystem. 

origin »

Bitcoin price in Telegram @btc_price_every_hour

SherLOCK Security (LOCK) на Currencies.ru

$ 0 (+0.00%)
Объем 24H $0
Изменеия 24h: 6.06 %, 7d: -9.29 %
Cегодня L: $0 - H: $0
Капитализация $0 Rank 99999
Цена в час новости $ 0.1387 (-100%)

security hackers development wallets revealed measures select

security hackers → Результатов: 126


Increased Safeguards Is Needed For Crypto Growth As Nearly $10B Has Been Stolen: KPMG

Ever since 2017, hackers have stolen over $9.8 billion in digital assets due to poorly written code or lax security, according to a KPMG report from Monday. Furthermore, the accounting firm added that the adoption of cryptocurrencies like Bitcoin (BTC) and Ether (ETH) by institutional investors has increased competition amongst investors seeking to occupy a […]

2020-3-3 23:42


Hackers Insert Monero (XMR) Mining Script in Late Basketball Great Kobe Bryant’s Wallpaper

A hidden cryptocurrency mining malware was found in a wallpaper of late basketball player Kobe Bryant, reported the security intelligence unit of technology giant Microsoft on Jan. 31st. Microsoft Security Intelligence tweeted that cybercriminals are taking advantage of the tragedy of Bryant’s tragic death “as expected” by running a malicious HTML file in the late […]

2020-2-1 22:37


Chainalysis report claims exchange security, hackers have improved simultaneously

In an excerpt from its upcoming ‘2020 Crypto Crime Report,’ Chainalysis addressed cases of cryptocurrency exchange hacks over the years, while tracking where the funds went after they’re stolen.The post Chainalysis report claims exchange security, hackers have improved simultaneously appeared first on AMBCrypto.

2020-1-23 03:30


Upbit Crypto Exchange Reopens Ethereum (ETH) Wallet Services After $49 Million Hack

Upbit, one of the major crypto exchanges in South Korea, has restarted Ethereum (ETH) wallet services almost 2 months after being attacked by hackers for $49 million ETH. It has been officially made public that after an enhancement to its wallet security structure, Upbit is supporting deposits and withdrawals in ETH again. In a tweet from […]

2020-1-15 01:10


Фото:

Microsoft: Russian government hackers are targeting IoT devices

Microsoft today warned that Russian government hackers have been using video decoders, printers, and internet of things devices to breach computer networks. In a blog post, the Microsoft Threat Intelligence Center wrote that the “devices became points of ingress from which the actor established a presence on the network and continued looking for further access.

2019-8-6 03:36