FILTERED RESULTS
FILTERS
Ads Top
DARK MODE
CHART
MCap $2.9T +0.1%24h Vol $68.4B -24%Fear & Greed 70/100Alts Index 59/100
BTC.D 59.3% -0.1%Stable.D 9.1% 0%ETH.D 11.4% 0%Others.D 20.2% +0.1%
FET$0.2662+18.16%•PROS$0.8248+14.97%•RAIN$0.0119+13.7%•VIRTUAL$0.8811+11.21%•ADA$0.2716+10.85%•DRV$0.4134+9.66%•FLOKI$0.00002977+8.98%•ORCA$1.992+8.02%•HNT$0.5483+7.57%•AKE$0.0346+7.44%•
BR$0.4591-20.64%•BTW$1.179-18.64%•STONK$0.1996-14.92%•AI$0.1145-14.87%•BEAM$0.00250082-12.83%•SOON$0.3410-8.2%•GRASS$0.7003-8.08%•ZAMA$0.0829-6.69%•KITE$0.1438-6.32%•CARDS$0.2464-5.95%•
Top movers 24h
    Filters
      Coins
      Sentiment
      Impact
      Search
      FILTERED RESULTS

        

      Upgrade your plan
      Dashboard

      Crypto Users Lost $472,000 Due to Fake Addresses and Phishing Signatures

      • A user lost around $305,000 in DAI due to an address poisoning attack.
      • In another case, a victim lost $167,342 in LINK after signing a malicious Permit2 approval.
      • Experts urged users not to copy crypto addresses from transaction history and to carefully review signatures before confirming.

      A user lost around $305,000 in DAI as a result of an address substitution (address poisoning) attack. GoPlus Security experts reported this.

      They explained that the attacker first sends the victim a micro-transfer (“dust”) from an address with a similar prefix and suffix. The idea is that the user will later copy the address from their transaction history without fully verifying it.

      In this case, the intended recipient address was 0x085adc…18f1dd, while the attackers used a lookalike address, 0x085ccc…18f1dd.

      GoPlus Security noted that such campaigns can be fully automated. Attackers automate target discovery, the creation of clone tokens with the same names, dust transfers, and subsequent laundering through mixers.

      The company urged users not to copy addresses from transaction history and to verify them in full before sending. Users are also advised to run a small test transaction first before transferring significant amounts.

      Another $167,000 lost due to Permit2

      A separate incident was reported by Scam Sniffer. A user lost $167,342 in LINK tokens after signing a phishing Permit2 approval on the Ethereum network.

      According to the service, the approval was signed on August 18, 2025. However, the attackers moved the user’s assets on October 3 of the following year.

      Onchain Matrix noted that this case highlights the risks associated with signing Permit2, when a user unknowingly grants a malicious approval access to their assets without understanding the consequences.

      According to analysts, clearer warnings during transactions and message signing could help prevent similar losses.

      The total amount lost across the two incidents described exceeds $472,000.

      As a reminder, in March 2026, Trust Wallet added an address poisoning protection feature to combat fraud.

      Сообщение Crypto Users Lost $472,000 Due to Fake Addresses and Phishing Signatures появились сначала на INCRYPTED.


      Source: Incrypted
      .

      Terra Founder Do Kwon Sentenced to 15 Years in Prison for Fraud