Phishing Campaigns Evolve With New Tools as Losses Mount Across Crypto
Phishing remains one of crypto's most persistent threats, and attackers — whether bored teenagers chasing Roblox currency or nation-state operations — continue refining their methods. A single successful phish can net over a million dollars, and as noted in a previous roundup, the environment remains highly favorable for scammers. Since then, a wave of new incidents has hit both small holders and large ones, powered by an expanding toolkit and fresh techniques for evading detection. Targets now extend well beyond inexperienced newcomers and FOMO-driven traders to include seasoned users and even team multisig wallets.
01Scam-as-a-service and drainer upgrades

The wallet-drainer market continues to be a profitable niche. Inferno Drainer, one of the best-known operations in this space, announced its retirement after reportedly extracting a combined $70 million from more than 100,000 victims. Even with that operation winding down, other off-the-shelf drainers keep advancing.
One newer technique exploits the CREATE2 opcode to generate a fresh contract address for every phished signature, defeating efforts to flag known malicious addresses. Because each address is freshly deployed, a victim's wallet interface has no prior history to warn against. ScamSniffer described the mechanism: with CREATE2, a drainer can generate a new temporary address for each malicious signature, and once the victim signs, the drainer deploys a contract at that address and immediately transfers the victim's assets — the goal being to slip past wallet security warnings. Per a related write-up, in malicious-signature phishing cases the freshly approved address is deployed and the assets withdrawn within a single transaction.
This method has already caused real losses, including more than $900,000 taken via an open-source drainer contract, and over $100,000 lost during the first of two front-end compromises affecting Velodrome, the first of which was likewise reported by the project.
A second CREATE2-based approach involves pre-generating enormous batches of contract addresses to power address-poisoning attacks. These addresses are used to seed a victim's transaction history with spam transfers designed to visually resemble genuine past counterparties, in hopes that a copy-paste mistake sends real funds to the attacker instead. Using CREATE2-deployed contracts rather than standard externally-owned accounts spares the attacker from having to fund gas for every address or store private keys for millions of generated wallets — a long-dormant technique that simply waits for a victim's error.
A recent surge of such attacks against Safe multisig wallets resulted in more than $2 million lost in a single week, attributed to one experienced actor who has reportedly accumulated over $5 million across four months. Among the victims was the Florence Finance team, which acknowledged an "operational oversight" that led to a $1.45 million loss from its multisig (transaction). That multiple signers fell for a widely-known attack vector is notable, though this particular case involved an added layer of deception: while Etherscan has hidden these spam transactions since April, the "History" tab within the Safe interface could be manipulated into displaying a fake token as legitimate by using Unicode characters mimicking "USDC" as the token symbol. The Safe UI has since been updated to hide these spoofed entries.
02Delivery methods keep diversifying
Beyond the tooling itself, attackers continue refining how bait is delivered. Greed remains the primary lever, particularly when framed as urgent, FOMO-inducing information. Examples include a fake staking program embedded in a Snapshot governance proposal, malicious links disguised as legitimate transfer addresses, and scams attempting to appear credible by falsely citing VC backing — an approach perhaps validated by Blast's own controversial "deposit now, build later" strategy.
Fear-based tactics are equally effective, exploiting panic to short-circuit careful judgment. Accounts impersonating well-known security researchers — including Peckshield, ZachXBT, and others — managed to drain more than $300,000 by urging frightened users to "revoke approvals" through malicious links, citing fabricated incidents at Uniswap and OpenSea.
Trust itself has become harder to establish. Twitter's verification system continues to be exploited by shameless influencers who leverage the appearance of legitimacy while remaining negligent about basic follower protections; those eventually banned had often operated freely for months, profiting substantially in the meantime. Even mainstream accounts have proven vulnerable to account compromise.
More targeted, resource-intensive attacks aim for bigger payoffs but carry a higher risk of detection. Persistent actors have been targeting known figures within the crypto community, posing as investors and attempting to deliver malicious payloads via Calendly links or during scheduled online meetings. Separately, some purported security researchers have been accused of staging DDoS attacks and then presenting them as critical vulnerabilities in order to extort projects for inflated "bug fix" fees.
03A systemic problem
With attack surfaces multiplying, an uptick in victims is likely as markets recover. Front-end compromises now occur almost weekly — recent examples include Frax, SpookySwap, and Trader Joe — meaning that standard advice like bookmarking trusted URLs is no longer adequate protection. Expecting users chasing new opportunities to maintain an in-wallet address book and independently verify every new contract address against a block explorer and project documentation may be an unrealistic standard. While some wallets do flag known-malicious addresses or new interactions, the incidents described above show that vigilance alone still isn't sufficient; a few projects, such as Pocket Universe, have begun offering insurance products in response.

Wallet UX has been a widely recognized weak point throughout the bear market, yet it has seen little meaningful improvement. Despite extensive discussion of account abstraction, no dominant solution has emerged, and incoming retail users are likely to rely on the same familiar tools as the last cycle — until they too learn the risks firsthand.
Tracing stolen funds occasionally produces results, but recovery is inconsistent — some exchanges show little concern even when stolen funds are deposited directly, while others appear complicit. Legal recourse hasn't kept pace either: even a seemingly clear-cut case has failed to result in punishment, a gap that critics call hypocritical given how often the traditional legal system declines to prosecute clear crypto crimes despite frequently linking the industry to criminal activity.
Not every attacker is a mastermind, however. October's Fantom wallet incident saw the attacker fail to notice they could have sent an ERC-20 token worth $170 million at the time to a burn address — a mistake rivaling the original oversight of reassigning an admin-privileged wallet tied to the FTM contract to a team member in the first place. And proceeds from phishing don't always stay put: aside from reportedly funding close to half of North Korea's military budget, some of the money ends up wagered at online casinos, where it can ironically make its way back to Lazarus Group once again.
As bearish sentiment fades and speculative enthusiasm returns, the pressure to stay alert to phishing attempts will only increase.
Get new scam files the moment we publish them — usually 2–3 emails a week.