CryptoReal
CASE FILE — Sep 22, 2023

Inside Crypto's Phishing Epidemic — A Look at the Vectors Draining Wallets in Late 2023

Phishing remains a persistent threat in crypto, and recent weeks have delivered an unusually dense run of incidents. A compromised front-end, a wave of "pig butchering" schemes reported by researchers, a single eight-figure loss tied to a signing mistake, hacks of both crypto and non-crypto public figures (one, two), and even a U.S. government agency falling victim — the pattern spans a wide set of well-known attack methods: token-approval phishing, social engineering, SIM-swapping, wallet-drainer malware, disguised apps, and address poisoning.

Even with much of the retail crowd having stepped back from the market, these techniques continue to catch victims, including people who might be expected to know better, as earlier coverage of expert targets illustrates.

Targeted campaigns against high-value individuals

Some phishing operations are narrowly targeted. The Lazarus Group's ongoing campaign — which this year alone has been linked to breaches at Atomic Wallet, AlphaPo, Stake, and CoinEx for a combined total exceeding $250 million — tends to zero in on staff at custodial platforms, since compromising a handful of private keys can unlock sums as large as those taken in the Ronin incident. These "spearphishing" efforts are frequently drawn out over long timeframes; a prior article covers the vectors involved in more depth.

Large individual losses from allowance exploits and romance-style scams

Separately, a user lost 4.5 million USDT just a day before publication in what looks like a "fake mining" scheme — a category of fraud that, per Tayvano's Dune dashboard, has now surpassed $300 million in cumulative losses. Known as "pig butchering," this approach relies on sustained contact with the target — sometimes for months — using blackmail, romance, or manufactured trust to eventually convince them to move funds into what's presented as a promising investment.

Not every scam takes that long, though. Earlier in the month, an experienced DeFi participant lost $24 million within minutes of signing malicious increaseAllowance requests. That single action let the attacker route the victim's stETH (worth $15.6 million) and rETH (worth $8.6 million) straight into their own wallet. That function has since been deprecated after criticism that its narrow legitimate use case was outweighed by how easily it enabled this kind of theft. How the malicious link reached the victim is unclear, though distribution via hijacked or fake Twitter/X accounts has proven effective under the platform's current ownership.

Broad-based attacks still catch plenty of victims

Beyond high-effort targeted attacks, wide-net phishing continues to pull in smaller sums from many people at once. Less than two weeks before this writing, Vitalik Buterin's Twitter account was hijacked to push a fake "commemorative NFT" tied to an upcoming Ethereum upgrade. The access came through a SIM-swap of his phone number — a verification method Twitter requires for Verified accounts — which let the attacker bypass two-factor authentication, reset the password, and seize control. The scheme brought in nearly $700,000 for the attacker's wallet, with a 33% share going to the operators of Pink Drainer, the drainer service used to execute it.

As of last month, ZachXBT tallied over $13 million lost to SIM-swap attacks on prominent crypto accounts; since then, similar incidents have hit Gitcoin, Ordinals Wallet, and Polymarket.

Wallet drainers operate as a scam-as-a-service model: malware that lets non-technical scammers run social-engineering campaigns, with proceeds split between whoever distributes the malicious links (through compromised Twitter or Discord accounts) and the developers who built the tool. Originally built to strip NFT holders of their collections, these kits now scan a target's wallet first to identify the most valuable assets to take. As one description of Pink Drainer's script put it, it "will target you with any number of attacks depending on which would be the most profitable."

Sums referenced in this case file

Pink Drainer has taken in close to $9 million so far and represents the latest generation of off-the-shelf drainer malware, following Monkey Drainer ($16.5 million, now shut down), Venom ($27 million, itself recommended by Monkey Drainer), and Inferno ($42 million). While these tools initially targeted NFT collectors susceptible to FOMO, they've expanded to cover ETH and ERC-20 tokens as NFT interest has cooled — a shift that looks prescient given the SEC's recent actions that may push PFP collections further out of favor.

Compromised front-ends

Attackers don't always need social media — going directly to a protocol's own interface can be just as effective. On Wednesday, Balancer warned users — for the second time in a month — that its front-end had been compromised, resulting in at least $238,000 in losses. This type of attack, which exploits users' trust in a project's official website, also hit Curve last year and Badger DAO in 2021, where victims — including Celsius — lost a combined $120 million. The method involves social-engineering domain registrars to gain control of a protocol's official UI, then inserting code that presents malicious contracts for users to unknowingly approve. Those approvals can be collected over long windows (nearly two weeks in Badger's case) before funds are drained straight from users' wallets.

Malware disguised as legitimate apps

Rather than distributing drainers directly, some attackers disguise malware as genuine crypto applications. A fake MetaMask app in an app store could be enough to fool someone unfamiliar with crypto — which is reportedly what happened to Mark Cuban last weekend. The loss, nearly $900,000, wasn't Cuban's first brush with a DeFi mishap (he was previously caught out providing liquidity to Iron Finance's failed stablecoin in 2021); further losses on Polygon were reportedly avoided this time.

Separately, SlowMist flagged malicious open-source MEV bot code that redirects funds straight to an attacker-controlled address when run by aspiring MEV searchers — a scheme that had already collected close to 50,000 (in the relevant token/currency) within a couple of days.

Address poisoning

A separate on-chain technique, address poisoning, uses lookalike addresses to trick victims — and it recently even snagged the U.S. Drug Enforcement Administration, for over $50,000. The method uses vanity-address generation tools such as Profanity (notably not the original version, whose vulnerability caused a $160 million loss for Wintermute last year) to produce an address that shares the same first and last characters as one the victim has recently transacted with. That address is then planted in the victim's transaction history via a spoofed transfer, a zero-value token transfer (a technique Etherscan has since started hiding), or occasionally a small real transfer if the attacker judges it worthwhile. The scam banks on the victim later copy-pasting the wrong address from their history, since interfaces typically display only the first and last few characters.

A structural problem, not just a criminal one

Many of these techniques exploit crypto's continued dependence on legacy web2 infrastructure, compounded by the persistence and resourcefulness of organized scam operations. Bot accounts with large follower counts — now frequently carrying blue checkmarks — dominate top replies under crypto-related tweets regardless of relevance. These accounts likely always existed, but the boosted visibility that comes with paid "Verified" status has made them harder to ignore and harder to get removed after being reported.

SIM swapping remains difficult to prevent even when a target is aware it's underway, and continues to threaten any part of the industry still reliant on legacy telecom identity verification. More such incidents appear to be on the way, with one report noting: "This is T-Mobile's 8th breach since 2018. This is the 3rd breach this year."

If regulators are serious about protecting the public from crypto-related risk, holding telecom and identity providers to higher accountability standards would be a straightforward step — one that could find support from both crypto advocates and skeptics. And the problem isn't confined to social media accounts: registrars surrendering control of front-ends, Google ads masquerading as official links, and repeated customer-data breaches — including recent incidents at Nansen and at FTX's bankruptcy claims agent, Kroll — hand scammers pre-filtered lists of likely targets.

Closing thoughts

Even with a large share of retail participants having exited the market, organized scam operations — along with opportunistic amateurs — keep finding ways to extract value regardless of market conditions. The prospect of a quick payday, less common since the peak of bull-market enthusiasm, has increasingly been replaced by wariness. Long, targeted spear-phishing operations aimed at specific individuals raise an unsettling question: would we recognize it happening to us? But the bigger risk for most people remains the broader, less targeted schemes that prey on greed, FOMO, unfamiliarity with the technology, or simple mistakes.

PhishingScams
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.