The post Crypto whale loses $6M to sneaky phishing scheme targeting staked Ethereum appeared on BitcoinEthereumNews.com. A crypto whale lost more than $6 million in staked Ethereum (stETH) and Aave-wrapped Bitcoin (aEthWBTC) after approving malicious signatures in a phishing scheme on Sept. 18, according to blockchain security firm Scam Sniffer. According to the firm, the attackers disguised their move as a routine wallet confirmation through “Permit” signatures, which tricked the victim into authorizing fund transfers without triggering obvious red flags. Yu Xian, founder of blockchain security company SlowMist, noted that the victim did not recognize the danger because the transaction required no gas fees. He wrote: “From the victim’s perspective, he just clicked a few times to confirm the wallet’s pop-up signature requests, didn’t spend a single penny of gas, and $6.28 million was gone.” How Permit exploits work Permit approvals were originally designed to simplify token transfers. Instead of submitting an on-chain approval and paying fees, a user can sign an off-chain message authorizing a spender. That efficiency, however, has created a new attack surface for malicious players. Once a user signs such a permit, attackers can combine two functions—Permit and TransferFrom—to drain assets directly. Because the authorization takes place off-chain, wallet dashboards show no unusual activity until the funds move. As a result, the assets are gone when the approval executes on-chain, and tokens are redirected to the attacker’s wallet. This loophole has made permit exploits increasingly attractive for malicious actors, who can siphon millions without needing complex hacks or high-cost gas wars. Phishing losses The latest theft highlights a wider trend of escalating phishing campaigns. Scam Sniffer reported that in August alone, attackers stole $12.17 million from more than 15,200 victims. That figure represented a 72% jump in losses compared with July. According to the firm, the most significant share of August’s damages came from three large accounts that accounted for nearly half… The post Crypto whale loses $6M to sneaky phishing scheme targeting staked Ethereum appeared on BitcoinEthereumNews.com. A crypto whale lost more than $6 million in staked Ethereum (stETH) and Aave-wrapped Bitcoin (aEthWBTC) after approving malicious signatures in a phishing scheme on Sept. 18, according to blockchain security firm Scam Sniffer. According to the firm, the attackers disguised their move as a routine wallet confirmation through “Permit” signatures, which tricked the victim into authorizing fund transfers without triggering obvious red flags. Yu Xian, founder of blockchain security company SlowMist, noted that the victim did not recognize the danger because the transaction required no gas fees. He wrote: “From the victim’s perspective, he just clicked a few times to confirm the wallet’s pop-up signature requests, didn’t spend a single penny of gas, and $6.28 million was gone.” How Permit exploits work Permit approvals were originally designed to simplify token transfers. Instead of submitting an on-chain approval and paying fees, a user can sign an off-chain message authorizing a spender. That efficiency, however, has created a new attack surface for malicious players. Once a user signs such a permit, attackers can combine two functions—Permit and TransferFrom—to drain assets directly. Because the authorization takes place off-chain, wallet dashboards show no unusual activity until the funds move. As a result, the assets are gone when the approval executes on-chain, and tokens are redirected to the attacker’s wallet. This loophole has made permit exploits increasingly attractive for malicious actors, who can siphon millions without needing complex hacks or high-cost gas wars. Phishing losses The latest theft highlights a wider trend of escalating phishing campaigns. Scam Sniffer reported that in August alone, attackers stole $12.17 million from more than 15,200 victims. That figure represented a 72% jump in losses compared with July. According to the firm, the most significant share of August’s damages came from three large accounts that accounted for nearly half…

Crypto whale loses $6M to sneaky phishing scheme targeting staked Ethereum

2025/09/19 02:31

A crypto whale lost more than $6 million in staked Ethereum (stETH) and Aave-wrapped Bitcoin (aEthWBTC) after approving malicious signatures in a phishing scheme on Sept. 18, according to blockchain security firm Scam Sniffer.

According to the firm, the attackers disguised their move as a routine wallet confirmation through “Permit” signatures, which tricked the victim into authorizing fund transfers without triggering obvious red flags.

Yu Xian, founder of blockchain security company SlowMist, noted that the victim did not recognize the danger because the transaction required no gas fees. He wrote:

How Permit exploits work

Permit approvals were originally designed to simplify token transfers. Instead of submitting an on-chain approval and paying fees, a user can sign an off-chain message authorizing a spender.

That efficiency, however, has created a new attack surface for malicious players.

Once a user signs such a permit, attackers can combine two functions—Permit and TransferFrom—to drain assets directly. Because the authorization takes place off-chain, wallet dashboards show no unusual activity until the funds move.

As a result, the assets are gone when the approval executes on-chain, and tokens are redirected to the attacker’s wallet.

This loophole has made permit exploits increasingly attractive for malicious actors, who can siphon millions without needing complex hacks or high-cost gas wars.

Phishing losses

The latest theft highlights a wider trend of escalating phishing campaigns.

Scam Sniffer reported that in August alone, attackers stole $12.17 million from more than 15,200 victims. That figure represented a 72% jump in losses compared with July.

According to the firm, the most significant share of August’s damages came from three large accounts that accounted for nearly half of the total. This included one wallet that lost $3.08 million in a single exploit.

Meanwhile, the firm attributed the surge in losses to a rise in EIP-7702 batch-signature scams and direct transfers to malicious contracts.

Considering this, security experts have urged crypto users to be cautious when interacting with wallet requests and refuse demands that grant unlimited permissions to their wallets.

Mentioned in this article

Source: https://cryptoslate.com/crypto-whale-loses-6m-to-sneaky-phishing-scheme-targeting-staked-ethereum/

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Why Tom Lee’s BitMine Is Buying Ethereum (ETH) Aggressively Despite Market Fear

Why Tom Lee’s BitMine Is Buying Ethereum (ETH) Aggressively Despite Market Fear

BitMine Immersion Technologies, the largest corporate holder of Ethereum (ETH), has doubled down on its acquisition of ETH in December, highlighting confidence in the asset. The renewed buying comes despite a tough environment for Ethereum. Rising exchange inflows and ongoing exchange-traded fund (ETF) outflows point to short-term pressure across the market. BitMine Scoops Up 138,452 ETH in a Week, Now Controls 3.2% of Supply According to a recent disclosure, BitMine acquired 138,452 ETH last week, representing a 156% increase over the previous four weeks. Its total holdings stand at 3.86 million ETH. This accounts for over 3.2% of Ethereum’s circulating supply. Furthermore, it puts BitMine two-thirds of the way toward its goal to control 5% of ETH’s supply. Since adopting ETH as a reserve asset, BitMine has continued to make large-scale purchases. Between June 30 and October 5, BitMine accumulated 2.83 million ETH. Since October 5, it has added another 1.03 million ETH to its holdings. Ethereum’s weakness throughout the fourth quarter makes BitMine’s steady accumulation even more notable. Since early October, ETH has shed about 24.8% of its value, reflecting persistent downward pressure. December has offered a small break from that trend. The price has climbed more than 4% since the start of the month, and with it have climbed BitMine’s ETH purchases. According to BitMine Chairman Tom Lee, the company’s accelerated purchasing activity reflects its confidence that ETH will likely see gains in the coming months, supported by several key catalysts. These include the Fusaka upgrade, which was activated last week and delivers meaningful improvements to Ethereum’s scalability, security, and overall network efficiency. BitMine also points to the broader macro backdrop, with the Federal Reserve ending quantitative tightening and potentially introducing another interest rate cut tomorrow. Together, these developments form the basis for the company’s view that market conditions could turn more supportive for ETH after weeks of volatility. “We are now more than 8 weeks past the October 10th liquidation shock event, a sufficient length of time to allow crypto to again trade on forward fundamentals,” Lee added. Market Conditions Point to Near-Term Volatility Despite this, on-chain data signals caution. CryptoOnchain noted that Ethereum exchange netflow to Binance has surged. The exchange received 162,084 ETH on December 5, 2025. This was the largest single-day inflow of ETH to the exchange since May 2023. Large deposits on exchanges often suggest impending sell pressure, since investors typically transfer tokens to platforms before liquidating. “Given the magnitude of this inflow, market participants should remain cautious. A supply shock of this size, if executed as market orders, could lead to heightened volatility or a short-term price correction,” the analyst stated. Furthermore, Ethereum exchange-traded funds are also signaling weakened demand. The ETFs experienced a record $1.4 billion in net outflows in November 2025, marking the largest monthly withdrawal on record. The trend has continued into December. According to SoSoValue, an additional $65.59 million exited ETH-focused ETFs in the first week of the month. “Historically, ETF flow reversals tell you more about liquidity pressure than about long term fundamentals. When redemptions spike, it’s usually a sign that broader risk sentiment is cracking, not that the asset itself broke. If ETF outflows continue, near term price action stays choppy as liquidity gets drained at the edges,” Milk Road posted. The ongoing divergence between direct accumulation and ETF redemptions highlights a market split, with retail and institutional players following diverging strategies regarding Ethereum’s outlook.
Share
Coinstats2025/12/09 16:08
Tom Lee’s BitMine Continues Aggressive Buying of Ethereum

Tom Lee’s BitMine Continues Aggressive Buying of Ethereum

The post Tom Lee’s BitMine Continues Aggressive Buying of Ethereum appeared on BitcoinEthereumNews.com. BitMine Immersion Technologies, the largest corporate holder of Ethereum (ETH), has doubled down on its acquisition of ETH in December, highlighting confidence in the asset. The renewed buying comes despite a tough environment for Ethereum. Rising exchange inflows and ongoing exchange-traded fund (ETF) outflows point to short-term pressure across the market. Sponsored BitMine Scoops Up 138,452 ETH in a Week, Now Controls 3.2% of Supply According to a recent disclosure, BitMine acquired 138,452 ETH last week, representing a 156% increase over the previous four weeks. Its total holdings stand at 3.86 million ETH. This accounts for over 3.2% of Ethereum’s circulating supply. Furthermore, it puts BitMine two-thirds of the way toward its goal to control 5% of ETH’s supply. Since adopting ETH as a reserve asset, BitMine has continued to make large-scale purchases. Between June 30 and October 5, BitMine accumulated 2.83 million ETH. Since October 5, it has added another 1.03 million ETH to its holdings. Ethereum’s weakness throughout the fourth quarter makes BitMine’s steady accumulation even more notable. Since early October, ETH has shed about 24.8% of its value, reflecting persistent downward pressure. Sponsored December has offered a small break from that trend. The price has climbed more than 4% since the start of the month, and with it have climbed BitMine’s ETH purchases. According to BitMine Chairman Tom Lee, the company’s accelerated purchasing activity reflects its confidence that ETH will likely see gains in the coming months, supported by several key catalysts. These include the Fusaka upgrade, which was activated last week and delivers meaningful improvements to Ethereum’s scalability, security, and overall network efficiency. BitMine also points to the broader macro backdrop, with the Federal Reserve ending quantitative tightening and potentially introducing another interest rate cut tomorrow. Together, these developments form the basis for the company’s view…
Share
BitcoinEthereumNews2025/12/09 16:50