Crypto users lost tens of millions of dollars in January to address poisoning and signature phishing scams, as attackers exploited lower transaction costs and user inattention to steal funds at scale.
Scam Sniffer Warns of Spike in Address Poisoning Losses
Crypto wallet scams intensified in January, with address poisoning and signature phishing attacks driving significant losses, according to data from blockchain security firm Scam Sniffer.
In one of the most striking cases, a single victim lost $12.2 million after mistakenly copying a malicious address from their transaction history. The incident followed a similar address poisoning attack in December that resulted in roughly $50 million in losses.
Scam Sniffer reported that address poisoning remains one of the most reliable methods for draining large sums from crypto wallets. Attackers create addresses that match the first and last characters of a trusted wallet, while subtly altering the middle portion, making them difficult to spot at a glance.
Alongside address poisoning, signature phishing attacks also surged in January. Scam Sniffer estimates that $6.27 million was stolen from 4,741 victims through malicious signature requests, marking a 207% increase compared to December. Notably, just two wallets were responsible for 65% of all signature phishing-related losses during the month.
Unlike address poisoning, signature phishing relies on tricking users into signing harmful blockchain transactions, such as granting unlimited token approvals or authorizing fund transfers without realizing the consequences.
Analysts believe the recent rise in attack volume may be partly linked to Ethereum’s Fusaka upgrade, rolled out in December. By reducing transaction costs, the upgrade made it cheaper for attackers to send large numbers of dust transactions, lowering the barrier to running address poisoning campaigns at scale.
Read more: SEC Sounds Alarm as Crypto Scammers Flood Group Chats With AI-Powered Cons
Security firms continue to urge users to double-check wallet addresses, avoid copying addresses from transaction histories, and carefully review signature requests before approving them, as these attack methods show no signs of slowing down.
FAQ 🚨
- What is address poisoning in crypto?
Scammers send look-alike wallet addresses to trick users into copying the wrong one.
- How much was lost to these scams in January?
Victims lost tens of millions, including a single $12.2 million address poisoning case.
- Why did signature phishing spike sharply?
Attackers exploited user inattention, stealing $6.27 million via malicious signatures.
- What’s driving the rise in these attacks now?
Lower transaction fees made large-scale scam campaigns cheaper and easier to run.
Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to
Disclaimer.
Related Articles
IoTeX Releases ioTube Security Incident Report: Actual Losses Approximately $4.4 Million, Pledges Full Compensation to Affected Users
IoTeX reports that the ioTube cross-chain bridge incident on March 6 resulted in approximately $4.4 million in losses. 99.5% of the stolen assets have been frozen, and the team has committed to fully compensate affected users. The mainnet has resumed operation, and the attacker’s address has been blacklisted. Meanwhile, efforts are underway to promote decentralized governance and security audits.
GateNews58m ago
Prince Group is laundering 10.7 billion NT dollars in Taiwan! Developing their own "OJBK Wallet" to connect with underground currency exchanges.
Taipei District Prosecutors Office is investigating the Cambodia "Prince Group" money laundering case, indicting 62 individuals and 13 companies. The involved amount of money laundering is 10.7 billion, and assets worth 5.5 billion have been seized. The group used USDT and their self-developed "OJBK Wallet" to conduct cross-border money laundering, conceal criminal proceeds, and withdraw cash in multiple countries.
区块客2h ago
HypurrFi reveals that early versions of Aave V3 had a rounding error vulnerability, and the addition of new lending markets for XAUT0 and UBTC has been suspended.
HyperEVM's custodial lending protocol HypurrFi disclosed that previous versions of Aave V3 had a "rounding error" vulnerability, allowing attackers to extract underlying tokens. HypurrFi guarantees the safety of user funds, has paused supply and borrowing operations in affected markets, and is working with relevant parties to address security issues.
GateNews3h ago
AI agents bypass Cloudflare protection, encrypting DeFi front-end security faces further tests
Recently, the autonomous AI agent OpenClaw successfully bypassed Cloudflare defenses using the Scrapling library, raising concerns about DeFi security. Although the tool can legally scrape content, the potential risks remind developers to establish multiple layers of defense and avoid over-reliance on traditional protection measures.
GateNews4h ago
MONTRA token team "ran away," causing the market cap to instantly evaporate by 80%, blamed on Iran's conscription.
Cryptocurrency project Montra Finance has suspended its project after the development team was conscripted by Iran, leading to an 80% plunge in the token's market value. The lack of official information has raised investor doubts, with some believing this is a "exit scam." The incident highlights the impact of geopolitics on the crypto market, and investors should remain cautious of opaque projects.
GateNews4h ago
Netizens want to bet on the "Iranian Rial": it has fallen 90% and will definitely rebound! Is this kind of war gamble worth buying?
The Iranian rial has plummeted over 96% in two months, hitting a record low. If a nuclear agreement is reached with the United States, the rial may have room for a rebound, but purchasing options are difficult and risky. Investors should be aware of U.S. sanctions risks and potential impacts of Iran's currency reforms on exchange rates. Many people are exchanging rial through cryptocurrencies, but caution is advised.
動區BlockTempo5h ago