Uniswap Hack: Multicall Misused in Phishing Attack, Drains 85 Lido ETH (2024)

News

Uniswap Hack: Multicall Misused in Phishing Attack, Drains 85 Lido ETH (1)

  • Elena R

    Uniswap Hack: Multicall Misused in Phishing Attack, Drains 85 Lido ETH (2)

    Elena R Uniswap Hack: Multicall Misused in Phishing Attack, Drains 85 Lido ETH (3)

    Author

    Elena is an expert in technical analysis and risk management in cryptocurrency market. She has 10+year experience in writing - accordingly she is avid journalists with a passion towards researching new insights coming into crypto erena.

    • Uniswap Hack: Multicall Misused in Phishing Attack, Drains 85 Lido ETH (4)

  • May 6, 2024 13:45 UTC
  • [article_wishlist article_id="298034" article_link="https://coinpedia.org/news/beware-crypto-wallet-drainers-leverage-legitimate-uniswap-contracts-for-phishing-attacks/"]

Story Highlights

  • Hackers are using a legitimate feature of Uniswap (Multicall) to steal crypto through phishing attacks.

  • Scammers are exploiting a loophole where they can appear as a legitimate contract to drain user wallets.

  • To stay safe, never approve token transfers for Uniswap Multicall or similar contracts. Be cautious and stay informed.

Cryptocurrency users beware! Hackers are getting craftier.

As a new tactic, wallet drainers are now using Multicall, a legitimate feature of Uniswap V3, to circumvent security measures and carry out advanced phishing attacks. It is this strategy that just recently resulted in 85 Lido ETH displaced from a victim who was unfortunately enticed by the fraudulent actions.

Want to learn how this scam works and how to protect yourself? Read on to find out!

Sneaky Tactics Revealed: How Are They Doing It?

The victim’s story shows how hackers are misusing Permit signatures to pretend they’re the Uniswap Multicall contract and move assets without permission.

Web3 anti-scam platform, Scam sniffer, alerted the community with this latest action of scammers. With the help of Multicall’s aggregate function consisting of permit and transfer features, the drainer executed the transaction stealthily and successfully from the victim, who lost 85 Lido ETH, which is nearly 269,620 s per the market rates.

🧵 [1/6] ⚠️ Wallet drainers are using legitimate contracts like Uniswap V3's Multicall to bypass wallet security alerts for phishing attacks 🚨.

A victim lost 85 Lido ETH to such tactics 5 days ago. 🔍💸 pic.twitter.com/7MsdP5qSVk

— Scam Sniffer | Web3 Anti-Scam (@realScamSniffer) May 5, 2024

To stay undetected by MEV (Miner Extractable Value) bots, the attacker also performed checks to ensure the authenticity of the originating address which in return made the attacker’s activity masked and made the identification process more difficult.

Although different countermeasures were introduced to cope with this type of threat, front-running still proved to be an insurmountable barrier.

Are You Staying Safe?

Developers reacted to this by activating a new version of the Multicall contract with improved permission checks to ensure that front-run attempts won’t take place again. Crypto users owe it to themselves to act carefully and not give any token approval to Uniswap Multicall or rather, such similar contracts.

As the ERC token approval function is inherent to the nature of a permissionless environment, phishing attacks can be quite challenging to fight effectively.

As the crypto ecosystem continues to develop, maintaining awareness of the best security practices by staying away from malicious actors, as well as maintaining trust in the decentralized finance system, is vital. Be informed, and stay safe!

Also, Read About a Similar Incident: WBTC Investor Loses $71 Million in Deceptive Phishing Attack

Staying informed is key! How do you keep yourself updated on the latest crypto security risks? Share your tips.

Tags

Hack

Show More

We'd Love to Hear Your Thoughts on This Article!

Was this writing helpful?

Uniswap Hack: Multicall Misused in Phishing Attack, Drains 85 Lido ETH (7) Uniswap Hack: Multicall Misused in Phishing Attack, Drains 85 Lido ETH (8) Yes Uniswap Hack: Multicall Misused in Phishing Attack, Drains 85 Lido ETH (9) Uniswap Hack: Multicall Misused in Phishing Attack, Drains 85 Lido ETH (10) No

Tell us why!

Uniswap Hack: Multicall Misused in Phishing Attack, Drains 85 Lido ETH (2024)
Top Articles
The Fall Trends You’re About to See (and Wear) Everywhere
E-commerce payment methods: How to choose | Stripe
Jordanbush Only Fans
Koopa Wrapper 1 Point 0
Ups Stores Near
Washu Parking
Best Big Jumpshot 2K23
Room Background For Zepeto
Occupational therapist
Manhattan Prep Lsat Forum
Phone Number For Walmart Automotive Department
Bbc 5Live Schedule
Skylar Vox Bra Size
Cooktopcove Com
Current Time In Maryland
Hoe kom ik bij mijn medische gegevens van de huisarts? - HKN Huisartsen
Craigslist Free Stuff Santa Cruz
Costco Gas Foster City
Forest Biome
Catherine Christiane Cruz
Sodium azide 1% in aqueous solution
12 Facts About John J. McCloy: The 20th Century’s Most Powerful American?
Craigslist Lake Charles
Greensboro sit-in (1960) | History, Summary, Impact, & Facts
Discord Nuker Bot Invite
Telegram Voyeur
Beaufort 72 Hour
From This Corner - Chief Glen Brock: A Shawnee Thinker
Mikayla Campinos: Unveiling The Truth Behind The Leaked Content
Fuse Box Diagram Honda Accord (2013-2017)
Helpers Needed At Once Bug Fables
Earthy Fuel Crossword
Laveen Modern Dentistry And Orthodontics Laveen Village Az
Σινεμά - Τι Ταινίες Παίζουν οι Κινηματογράφοι Σήμερα - Πρόγραμμα 2024 | iathens.gr
Black Adam Showtimes Near Amc Deptford 8
Toonily The Carry
Restored Republic December 9 2022
The best Verizon phones for 2024
Nearest Ups Office To Me
Dr Adj Redist Cadv Prin Amex Charge
9 oplossingen voor het laptoptouchpad dat niet werkt in Windows - TWCB (NL)
Anguilla Forum Tripadvisor
Questions answered? Ducks say so in rivalry rout
Weather In Allentown-Bethlehem-Easton Metropolitan Area 10 Days
FedEx Authorized ShipCenter - Edouard Pack And Ship at Cape Coral, FL - 2301 Del Prado Blvd Ste 690 33990
Youravon Com Mi Cuenta
Unblocked Games 6X Snow Rider
Strange World Showtimes Near Marcus La Crosse Cinema
Rovert Wrestling
Tweedehands camper te koop - camper occasion kopen
Craigslist.raleigh
Mast Greenhouse Windsor Mo
Latest Posts
Article information

Author: Corie Satterfield

Last Updated:

Views: 6156

Rating: 4.1 / 5 (62 voted)

Reviews: 93% of readers found this page helpful

Author information

Name: Corie Satterfield

Birthday: 1992-08-19

Address: 850 Benjamin Bridge, Dickinsonchester, CO 68572-0542

Phone: +26813599986666

Job: Sales Manager

Hobby: Table tennis, Soapmaking, Flower arranging, amateur radio, Rock climbing, scrapbook, Horseback riding

Introduction: My name is Corie Satterfield, I am a fancy, perfect, spotless, quaint, fantastic, funny, lucky person who loves writing and wants to share my knowledge and understanding with you.