• Home
  • Live Rates
  • Privacy Policy
  • Shop
  • Terms of Service
Thursday, April 30, 2026
  • Home
  • Crypto News
  • Bitcoin
  • Ethereum
  • NFT
  • DeFi
  • Blockchain
  • Metaverse
  • Altcoin
  • Tether
  • Solana
    • Dogecoin
  • Live Rates
  • Shop
No Result
View All Result
XXL24
Ledger - Crypto Beginners Pack
  • Home
  • Crypto News
  • Bitcoin
  • Ethereum
  • NFT
  • DeFi
  • Blockchain
  • Metaverse
  • Altcoin
  • Tether
  • Solana
    • Dogecoin
  • Live Rates
  • Shop
No Result
View All Result
XXL24
No Result
View All Result

Ethereum feature abused to steal $60 million from 99K victims

November 14, 2023
in Ethereum
0

Malicious actors have been abusing Ethereum’s ‘Create2’ function to bypass wallet security alerts and poison cryptocurrency addresses, which led to stealing $60,000,000 worth of cryptocurrency from 99,000 people in six months.

This is reported by Web3 anti-scam specialists at ‘Scam Sniffer,’ who observed several cases of in-the-wild exploitation of the function, in some cases losses incurred by one individual reaching up to $1.6 million.

Legitimate function

Create2 is an opcode in Ethereum, introduced in the ‘Constantinople’ upgrade, that allows creating smart contracts on the blockchain.


Unlike the original Create opcode, which generated new addresses based on the creator’s address and nonce, Create2 allows calculating addresses before the deployment of the contract.

It’s a powerful tool for Ethereum developers, enabling advanced and flexible contract interactions, parameter-based contract address pre-calculation, deployment flexibility, suitability for off-chain transactions and certain dApps.

Create2 introduced significant benefits, but several security implications and new attack vectors also came along with them.

Create2 opcode abuse

Scam Sniffer’s report explains that Create2 can be abused to generate fresh contract addresses with no history of malicious/reported transactions, hence bypassing wallet security alerts.

When a victim signs a malicious transaction, the attacker deploys a contract at the pre-calculated address and transfers the victim’s assets to it, a non-reversible process.

In a recent case analysts observed, a victim lost $927,000 worth of GMX after they were tricked into signing a transfer contract that sent the assets to a pre-computed address.

The smart contract used in the attack (Scam Sniffer)

The second type of Create2 abuse is generating addresses similar to legitimate ones owned by the recipient, thus tricking users into sending assets to the threat actors, thinking they’re sending it to a known address.

The scheme, which is named ‘address poisoning,’ involves generating a large number of addresses and then picking those that match their specific phishing needs each time to trick their targets.

Since August 2023, Scam Sniffer has recorded 11 victims losing nearly $3 million, with one of them transferring $1.6 million to an address resembling one they had sent money to recently.

Most of these attacks went under the radar, silently siphoning millions, but some have caught the attention of the community.

At the beginning of the year, MetaMask warned about scammers using freshly-generated addresses that match those used by the victim in recent transactions.

In the scam, the threat actor may also send the victim a small amount in crypto to register the address in the wallet’s history, thus increasing the chances of the victim making the payment.

In early August 2023, a Binance operator mistakenly sent $20 million to scammers who employed the ‘address poisoning’ trick but noticed the error quickly and froze the recipient’s address.

Notably, using lookalike cryptocurrency addresses is a trick seen in clipboard-hijacking malware tools, like the Laplas Clipper, highlighting the method’s effectiveness.

When performing cryptocurrency transactions, it is always recommended to check the recipient’s address thoroughly, and not just the first and last three-four characters, before approving it.



This news is republished from another source.

Previous Post

NFT market revives as major collections soar in sales and volume

Next Post

Cranberry Township Police warning residents of new Bitcoin scam – WPXI

Next Post

Cranberry Township Police warning residents of new Bitcoin scam – WPXI

Name Price
Kinza Babylon Staked BTC
Kinza Babylon Staked BTC (KBTC)
$83,270.00
Steakhouse EURCV Morpho Vault
Steakhouse EURCV Morpho Vault (STEAKEURCV)
$0.000000
Eureka Bridged PAX Gold (Terra)
Eureka Bridged PAX Gold (Terra) (PAXG)
$4,182.54
Vested XOR
Vested XOR (VXOR)
$3,404.23
ICPanda DAO
ICPanda DAO (PANDA)
$0.003106
TruFin Staked APT
TruFin Staked APT (TRUAPT)
$8.02
kpk ETH Prime
kpk ETH Prime (KPK ETH PRIME)
$2,036.25
ApeSwap
ApeSwap (BANANA)
$0.000000
bitcoin
Bitcoin (BTC)
$76,380.00
ethereum
Ethereum (ETH)
$2,259.30

Dogecoin

Will Dogecoin Recover or Dive Below $0.1? 5thScape Set to Dominate 2024! %

July 15, 2024

Investors Shift to Clandeno (CLD) ICO Amid Global Market Uncertainty as Dogecoin (DOGE) and Polkadot (DOT) Drop

July 14, 2024

Dogecoin (DOGE) and Solana (SOL) Lead Crypto Market Recovery as Bitcoin (BTC) Reclaims $60K

July 14, 2024

DOGECOIN PRICE ANALYSIS & PREDICTION (July 13) – Doge Trades Calmly At $0.1, Can It Gain Strength From This Key Level? 

July 14, 2024

Analyst Who Bought Solana At $0.11 And Sold For $250 Says Buy ETFSwap (ETFS) At $0.01831 Now Instead Of Dogecoin (DOGE)

July 13, 2024

Leap Ahead with MOONHOP Presale As 4900% Growth Projection Dwarfs Notcoin & Dogecoin’s Declines

July 13, 2024

Metaverse

Ciz Verse Announces the Launch of Its Bitcoin-Powered Metaverse

July 15, 2024

Mil.k partners AirAsia rewards and The Sandbox to engage consumers in the metaverse

July 15, 2024

Lado Okhotnikov Reveals The Secrets Of The Realistic Meta Force Metaverse

July 14, 2024

GensoKishi Metaverse (MV) Price Down 18.4% This Week

July 14, 2024

The 3 Smartest Metaverse Stocks to Buy With $500 Right Now

July 14, 2024

Top 3 Metaverse Tokens For 3X Surge This Bull Rally!

July 13, 2024

transcosmos launches Roblox metaverse services with EbuAction

July 13, 2024
No Result
View All Result

Pages

  • Home
  • Live Rates
  • Privacy Policy
  • Shop
  • Terms of Service

Tether

Zimbabwe ZiG Hits Record Low as Interest in Tether (USDT) Rises

July 15, 2024

Solana

How Solana flipped Ethereum, Bitcoin in NFT Adoption

July 15, 2024

Solana Reaches Market Capitalization of $67.27 Billion (SOL)

July 14, 2024

Advertisement

  • Shop
  • Privacy Policy
  • Terms of Service

© 2023 XXL24


No Result
View All Result
  • Home
  • Crypto News
  • Bitcoin
  • Ethereum
  • NFT
  • DeFi
  • Blockchain
  • Metaverse
  • Altcoin
  • Tether
  • Solana
    • Dogecoin
  • Live Rates
  • Shop

© 2023 XXL24


  • Kinza Babylon Staked BTCKinza Babylon Staked BTC(KBTC)$83,270.000.00%
  • Steakhouse EURCV Morpho VaultSteakhouse EURCV Morpho Vault(STEAKEURCV)$0.000000-100.00%
  • Eureka Bridged PAX Gold (Terra)Eureka Bridged PAX Gold (Terra)(PAXG)$4,182.540.23%
  • Vested XORVested XOR(VXOR)$3,404.231,000.00%
  • ICPanda DAOICPanda DAO(PANDA)$0.003106-39.39%
  • TruFin Staked APTTruFin Staked APT(TRUAPT)$8.020.00%
  • kpk ETH Primekpk ETH Prime(KPK ETH PRIME)$2,036.250.01%
  • ApeSwapApeSwap(BANANA)$0.0000000.00%
  • bitcoinBitcoin(BTC)$76,380.000.71%
  • ethereumEthereum(ETH)$2,259.300.31%
  • kpk ETH Yieldkpk ETH Yield(KPK ETH YIELD)$2,031.88-0.04%
  • tetherTether(USDT)$1.00-0.01%
  • JPool Staked SOLJPool Staked SOL(JSOL)$170.103.95%
  • rippleXRP(XRP)$1.37-0.06%
  • binancecoinBNB(BNB)$615.76-0.22%
  • usd-coinUSDC(USDC)$1.00-0.02%
  • solanaSolana(SOL)$82.920.05%
  • tronTRON(TRX)$0.3261770.86%
  • staked-etherLido Staked Ether(STETH)$2,262.76-3.72%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.02-1.13%
  • dogecoinDogecoin(DOGE)$0.1063803.09%
  • Gaj FinanceGaj Finance(GAJ)$0.0059271.46%
  • Content BitcoinContent Bitcoin(CTB)$24.482.55%
  • WhiteBIT CoinWhiteBIT Coin(WBT)$57.245.94%
  • USD OneUSD One(USD1)$1.000.11%
  • USDSUSDS(USDS)$1.000.00%
  • Wrapped stETHWrapped stETH(WSTETH)$2,773.89-3.48%
  • UGOLD Inc.UGOLD Inc.(UGOLD)$3,042.460.08%
  • leo-tokenLEO Token(LEO)$10.33-0.26%
  • HyperliquidHyperliquid(HYPE)$39.60-0.96%
  • ParkcoinParkcoin(KPK)$1.101.76%
  • wrapped-bitcoinWrapped Bitcoin(WBTC)$76,102.00-3.36%
  • cardanoCardano(ADA)$0.2466241.06%
  • Binance Bridged USDT (BNB Smart Chain)Binance Bridged USDT (BNB Smart Chain)(BSC-USD)$1.00-0.07%
  • bitcoin-cashBitcoin Cash(BCH)$440.87-1.41%
  • Wrapped Beacon ETHWrapped Beacon ETH(WBETH)$2,462.35-3.82%
  • Wrapped eETHWrapped eETH(WEETH)$2,462.97-3.62%
  • moneroMonero(XMR)$378.791.00%
  • Yay StakeStone EtherYay StakeStone Ether(YAYSTONE)$2,671.07-2.84%
  • chainlinkChainlink(LINK)$9.110.12%
  • Coinbase Wrapped BTCCoinbase Wrapped BTC(CBBTC)$76,319.00-3.28%
  • PengPeng(PENG)$0.60-13.59%
  • zcashZcash(ZEC)$348.976.72%
  • CantonCanton(CC)$0.150857-0.16%
  • stellarStellar(XLM)$0.159089-0.48%
  • wethWETH(WETH)$2,264.05-3.78%
  • MurasakiMurasaki(MURA)$4.32-12.46%
  • USD1USD1(USD1)$1.00-0.02%
  • sUSDSsUSDS(SUSDS)$1.090.12%
  • USDT0USDT0(USDT0)$1.00-0.11%