Skip to main content
Back to news
SafetyMajor story — Significance is rated automatically and is not a price signal.

4,200 Malicious Smart Contracts Drained Crypto From 5,700 Victims — Here's How They Pulled It Off

(60 days ago) · 1 source · Summarized by CryptoBipto

Security researchers have identified over 4,200 malicious smart contracts designed to trick users into unknowingly signing away access to their cryptocurrency. Approximately 5,700 victims fell for these schemes, which exploited the complexity of smart contract approvals to steal funds. The findings highlight the ongoing and growing threat of approval-based scams in decentralized finance.

WHY IT MATTERS

Think of a smart contract approval like giving someone a signed blank check — you're authorizing them to withdraw from your account, sometimes with no limit. In crypto, when you interact with an app or website and your wallet asks you to "approve" something, you might actually be giving a program permission to move your tokens. Scammers create fake apps that look legitimate but are designed solely to get you to sign that approval. Once you do, they can drain your wallet. This research found thousands of these traps and thousands of people who fell for them. It's a reminder that in crypto, every transaction you sign matters — and if you don't understand what you're approving, it's safest not to sign it.

This research shines a spotlight on one of the most persistent and dangerous attack vectors in crypto: malicious smart contract approvals. Unlike traditional phishing that steals passwords, these scams trick users into signing blockchain transactions that grant the attacker permission to move tokens out of the victim's wallet.

Read the full analysis with a CryptoBipto membership

Members can read the full analysis of every story, not just the headline.

Get started

SOURCES

  • Source

RELATED

Smart Contract SecurityCrypto ScamsWallet SafetyDeFi RisksSocial Engineering