A cryptocurrency venture capital fund has suffered a significant loss of over $36 million due to a phishing attack that involved a fraudulent permit signature. The incident reportedly affected an entity linked to Continue Capital.
According to a report by blockchain monitoring platform Lookonchain, the phishing attack occurred on October 11, resulting in the theft of 15,079 wrapped Ethereum tokens (fwDETH). The malicious transaction was executed using a deceptive “permit” signature, which allowed the attackers to siphon funds from the victim’s wallet.
Phishing attacks are a common threat in the cryptocurrency space, often masquerading as legitimate transactions. In this case, the attackers exploited a signature mechanism that tricked the victim into approving a transaction without directly interacting with their assets.
Blockchain data reveals that the victim’s wallet, associated with Continue Capital, unknowingly granted permission for the transfer of the fwDETH tokens on the Blast chain. The stolen assets were quickly transferred to a hacker-controlled address, identified as 0x0605edee6a8b8b553cae09abe83b2ebeb75516ec, where they were promptly sold. This rapid offloading led to a more than 95% drop in fwDETH prices before a partial recovery.
The swift transfer and sale of the stolen funds have had a ripple effect on decentralized finance (DeFi) protocols reliant on fwDETH liquidity, including PAC Finance and Orbit Finance. While the full impact on these protocols is still being assessed, analysts indicate that the sell-off exacerbated existing liquidity issues, negatively affecting token prices and other investors holding fwDETH.
Growing Phishing Threats in the Crypto Space
This $36 million phishing attack is one of the largest recent incidents involving a fraudulent “permit” signature and highlights the rising sophistication of phishing scams targeting the cryptocurrency market. Similar attacks have caused substantial losses for other investors; for instance, a September incident saw a victim lose $32.4 million worth of spWETH tokens through a phishing scheme.
Additionally, a recent report indicated that the Inferno Drainer tool, responsible for over $215 million in theft from 200,000 victims, has resurfaced in 2024 after being inactive in late 2023. Other high-profile attacks this year include one where a whale lost approximately $55.4 million in Dai stablecoins.
The increase in phishing incidents aligns with a broader trend of escalating crypto scams. According to cybersecurity firm CertiK, the third quarter of 2024 alone saw losses exceeding $753 million from various forms of fraud, with $127 million attributed to phishing scams.
These attacks frequently involve tricking users into signing fraudulent contracts or connecting their wallets to malicious websites, enabling hackers to drain funds with minimal user awareness. Moreover, recent reports indicate that the crypto sector is the second most targeted industry for identity fraud, accounting for nearly 29% of global fraud attempts.
As scammers continue to exploit vulnerabilities in both retail and institutional markets, the need for enhanced security measures in the cryptocurrency space has never been more critical.
