$7M Ethereum Re-Staking Exploit Victim Recovers Funds

A recent incident involving an unfortunate victim who lost 1,807 liquid staked Ether (ETH), valued at $6.91 million, to scammers on May 26 took an unexpected turn. This individual appears to have regained a significant portion of the stolen funds from the culprits. Yu Xian, co-founder of blockchain analytics firm SlowMist, highlighted the rare occurrence, saying, “Yesterday, the old phishing group Inferno Drainer used a permit offline authorization signature to phish nearly $7 million in ETH re-pledged assets from a user. Today, they actually got a refund, which is really rare.”

On the same day, the organization Scam Sniffer noted that the victim had managed to recover 1,445 Ether, equating to 80% of the stolen sum, while the scammers allegedly retained a 20% bounty as their share. Analysts explained that the wallet involved in the breach fell prey to a permit phishing attack. In such attacks, malicious actors generate a legitimate off-chain authorization signature, enabling them to transfer ERC-20 tokens from a wallet they do not own.

According to SlowMist, the attack was made possible by an underappreciated aspect of Ethereum permits, introduced through EIP-2612. This Ethereum Improvement Proposal allows users to interact with smart contracts without needing prior authorization, as they can attach an authorization signature. This permit function can be executed by any account, regardless of ownership. Consequently, even if users had unintentionally compromised their wallet signatures on phishing websites, scammers could exploit this permit feature to drain tokens from their wallets.

To safeguard against such exploits, SlowMist recommended periodic usage of authorization tools like RevokeCash to detect any unusual authorizations. For Uniswap Permit2, the authorization management tool provided by Scam Sniffer can be utilized to verify and revoke irregular authorizations promptly.

Not everyone expressed sympathy for the victim in this case. ZachXBT, a well-known DeFi investigator, commented, “How do you get phished last year for $638K and then again this year for $6.9M. Some people are just careless with their assets.” This reaction underscores the broader community sentiment about maintaining vigilance and securing one’s digital assets.

The incident brings to light the increasing prevalence of cryptocurrency-related scams. In March, reports surfaced that cryptocurrency scams had surged by 53% within the past year.

The FBI’s findings revealed that cryptocurrency-related investment fraud comprised an astonishing 86% of all investment losses in the United States in 2023. This highlights the urgent need for improved security measures and education among cryptocurrency investors to prevent such devastating losses.

As the crypto world continues to evolve, both technological advancements and breaches are inevitable. Therefore, ongoing awareness and proactive measures can make a significant difference in protecting one’s assets from malicious actors. This incident serves as a stark reminder for all digital asset holders to remain vigilant and frequently check their authorization statuses to avoid falling victim to similar scams.

