The post Crypto whale loses $6M to sneaky phishing scheme targeting staked Ethereum appeared on BitcoinEthereumNews.com. A crypto whale lost more than $6 million in staked Ethereum (stETH) and Aave-wrapped Bitcoin (aEthWBTC) after approving malicious signatures in a phishing scheme on Sept. 18, according to blockchain security firm Scam Sniffer. According to the firm, the attackers disguised their move as a routine wallet confirmation through “Permit” signatures, which tricked the victim into authorizing fund transfers without triggering obvious red flags. Yu Xian, founder of blockchain security company SlowMist, noted that the victim did not recognize the danger because the transaction required no gas fees. He wrote: “From the victim’s perspective, he just clicked a few times to confirm the wallet’s pop-up signature requests, didn’t spend a single penny of gas, and $6.28 million was gone.” How Permit exploits work Permit approvals were originally designed to simplify token transfers. Instead of submitting an on-chain approval and paying fees, a user can sign an off-chain message authorizing a spender. That efficiency, however, has created a new attack surface for malicious players. Once a user signs such a permit, attackers can combine two functions—Permit and TransferFrom—to drain assets directly. Because the authorization takes place off-chain, wallet dashboards show no unusual activity until the funds move. As a result, the assets are gone when the approval executes on-chain, and tokens are redirected to the attacker’s wallet. This loophole has made permit exploits increasingly attractive for malicious actors, who can siphon millions without needing complex hacks or high-cost gas wars. Phishing losses The latest theft highlights a wider trend of escalating phishing campaigns. Scam Sniffer reported that in August alone, attackers stole $12.17 million from more than 15,200 victims. That figure represented a 72% jump in losses compared with July. According to the firm, the most significant share of August’s damages came from three large accounts that accounted for nearly half… The post Crypto whale loses $6M to sneaky phishing scheme targeting staked Ethereum appeared on BitcoinEthereumNews.com. A crypto whale lost more than $6 million in staked Ethereum (stETH) and Aave-wrapped Bitcoin (aEthWBTC) after approving malicious signatures in a phishing scheme on Sept. 18, according to blockchain security firm Scam Sniffer. According to the firm, the attackers disguised their move as a routine wallet confirmation through “Permit” signatures, which tricked the victim into authorizing fund transfers without triggering obvious red flags. Yu Xian, founder of blockchain security company SlowMist, noted that the victim did not recognize the danger because the transaction required no gas fees. He wrote: “From the victim’s perspective, he just clicked a few times to confirm the wallet’s pop-up signature requests, didn’t spend a single penny of gas, and $6.28 million was gone.” How Permit exploits work Permit approvals were originally designed to simplify token transfers. Instead of submitting an on-chain approval and paying fees, a user can sign an off-chain message authorizing a spender. That efficiency, however, has created a new attack surface for malicious players. Once a user signs such a permit, attackers can combine two functions—Permit and TransferFrom—to drain assets directly. Because the authorization takes place off-chain, wallet dashboards show no unusual activity until the funds move. As a result, the assets are gone when the approval executes on-chain, and tokens are redirected to the attacker’s wallet. This loophole has made permit exploits increasingly attractive for malicious actors, who can siphon millions without needing complex hacks or high-cost gas wars. Phishing losses The latest theft highlights a wider trend of escalating phishing campaigns. Scam Sniffer reported that in August alone, attackers stole $12.17 million from more than 15,200 victims. That figure represented a 72% jump in losses compared with July. According to the firm, the most significant share of August’s damages came from three large accounts that accounted for nearly half…

Crypto whale loses $6M to sneaky phishing scheme targeting staked Ethereum

A crypto whale lost more than $6 million in staked Ethereum (stETH) and Aave-wrapped Bitcoin (aEthWBTC) after approving malicious signatures in a phishing scheme on Sept. 18, according to blockchain security firm Scam Sniffer.

According to the firm, the attackers disguised their move as a routine wallet confirmation through “Permit” signatures, which tricked the victim into authorizing fund transfers without triggering obvious red flags.

Yu Xian, founder of blockchain security company SlowMist, noted that the victim did not recognize the danger because the transaction required no gas fees. He wrote:

How Permit exploits work

Permit approvals were originally designed to simplify token transfers. Instead of submitting an on-chain approval and paying fees, a user can sign an off-chain message authorizing a spender.

That efficiency, however, has created a new attack surface for malicious players.

Once a user signs such a permit, attackers can combine two functions—Permit and TransferFrom—to drain assets directly. Because the authorization takes place off-chain, wallet dashboards show no unusual activity until the funds move.

As a result, the assets are gone when the approval executes on-chain, and tokens are redirected to the attacker’s wallet.

This loophole has made permit exploits increasingly attractive for malicious actors, who can siphon millions without needing complex hacks or high-cost gas wars.

Phishing losses

The latest theft highlights a wider trend of escalating phishing campaigns.

Scam Sniffer reported that in August alone, attackers stole $12.17 million from more than 15,200 victims. That figure represented a 72% jump in losses compared with July.

According to the firm, the most significant share of August’s damages came from three large accounts that accounted for nearly half of the total. This included one wallet that lost $3.08 million in a single exploit.

Meanwhile, the firm attributed the surge in losses to a rise in EIP-7702 batch-signature scams and direct transfers to malicious contracts.

Considering this, security experts have urged crypto users to be cautious when interacting with wallet requests and refuse demands that grant unlimited permissions to their wallets.

Mentioned in this article

Source: https://cryptoslate.com/crypto-whale-loses-6m-to-sneaky-phishing-scheme-targeting-staked-ethereum/

Market Opportunity
Threshold Logo
Threshold Price(T)
$0.00687
$0.00687$0.00687
0.00%
USD
Threshold (T) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

ETH Exit Queue Gridlocks As Validators Pile Up

ETH Exit Queue Gridlocks As Validators Pile Up

The post ETH Exit Queue Gridlocks As Validators Pile Up appeared on BitcoinEthereumNews.com. Welcome to The Protocol, CoinDesk’s weekly wrap of the most important stories in cryptocurrency tech development. I’m Margaux Nijkerk, a reporter at CoinDesk. In this issue: Ethereum Faces Validator Bottleneck With 2.5M ETH Awaiting Exit Is Ethereum’s DeFi Future on L2s? Liquidity, Innovation Say Perhaps Yes Ethereum Foundation Starts New AI Team to Support Agentic Payments American Express Introduces Blockchain-Based ‘Travel Stamps’ Network News ETHEREUM VALIDATOR EXIT QUEUE FACES BOTTLENECK: Ethereum’s proof-of-stake system is facing its largest test yet. As of mid-September, roughly 2.5 million ETH — valued at roughly $11.25 billion — is waiting to leave the validator set, according to validator queue dashboards. The backlog pushed exit wait times to more than 46 days on Sept. 14, the longest in Ethereum’s short staking history, dashboards show. The last peak, in August, put the exit queue at 18 days. The initial spark came on Sept. 9, when Kiln, a large infrastructure provider, chose to exit all of its validators as a safety precaution. The move, triggered by recent security incidents including the NPM supply-chain attack and the SwissBorg breach, pushed around 1.6 million ETH into the queue at once. Though unrelated to Ethereum’s staking protocol itself, the hacks rattled confidence enough for Kiln to hit pause, highlighting how events in the broader crypto ecosystem can cascade into Ethereum’s validator dynamics. In a blog post from staking provider Figment, Senior Analyst Benjamin Thalman noted that the current exit queue build up isn’t only about security. After ETH has rallied more than 160% since April, some stakers are simply taking profits. Others, especially institutional players, are shifting their portfolios’ exposure. At the same time, the number of validators entering the Ethereum staking ecosystem has been steadily rising. Ethereum’s churn limit, which is a protocol safeguard that caps how many validators can…
Share
BitcoinEthereumNews2025/09/18 15:15
TheWell Bioscience Launches VitroPrime™ 3D Culture and Imaging Plate for Organoid and 3D Cell Culture Workflows

TheWell Bioscience Launches VitroPrime™ 3D Culture and Imaging Plate for Organoid and 3D Cell Culture Workflows

A new in-plate, zero-disruption design enables reproducible organoid culture, downstream processing, and high-resolution imaging in a single 3D cell culture plate
Share
AI Journal2026/02/09 22:02
Tom Lee Linked BitMine Scoops Up $82 Million in Ethereum as Institutional Appetite Heats Up

Tom Lee Linked BitMine Scoops Up $82 Million in Ethereum as Institutional Appetite Heats Up

Tom Lee–Backed BitMine Makes $82 Million Ethereum Purchase, Signaling Growing Institutional Confidence BitMine, a crypto-focused firm associated with veteran ma
Share
Hokanews2026/02/09 22:08