Close Menu
AsiaTokenFundAsiaTokenFund
  • Home
  • Crypto News
    • Bitcoin
    • Altcoin
  • Web3
    • Blockchain
  • Trading
  • Regulations
    • Scams
  • Submit Article
  • Contact Us
  • Terms of Use
    • Privacy Policy
    • DMCA
What's Hot

BlackRock Targets Stablecoin Issuers and Institutions in Latest Tokenized Funds

August 3, 2026

Corporate crypto accounts on HTX face a complete dead end with zero legal exit routes when EU sanctions strike on August 23

August 3, 2026

Michael Saylor Says He’s Never Sold Bitcoin, Not One Satoshi

August 3, 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) YouTube LinkedIn
AsiaTokenFundAsiaTokenFund
ATF Capital
  • Home
  • Crypto News
    • Bitcoin
    • Altcoin
  • Web3
    • Blockchain
  • Trading
  • Regulations
    • Scams
  • Submit Article
  • Contact Us
  • Terms of Use
    • Privacy Policy
    • DMCA
AsiaTokenFundAsiaTokenFund

Malicious smart contracts tricked 5,742 crypto victims

0
By Aggregated - see source on August 3, 2026 Scams
Share
Facebook Twitter LinkedIn Pinterest Email

Malicious smart contracts can make safety tools inside crypto wallets show a small gain even when the final transaction sends the user’s deposit to an attacker, according to a July 30 arXiv preprint that links the technique to 5,742 victim addresses and about $3.48 million in historical losses.

The authors used SimGuard, a contract-bytecode detector, to identify 4,224 transaction-simulation phishing contracts across Ethereum, BNB Smart Chain, Avalanche and Polygon.

The study associated them with 6,223 victim transactions but called the loss estimate an upper bound because some attacker test activity may have been misclassified. It attributed 91.5% of the losses to Ethereum and about 83% of the cross-chain total to its largest inferred cluster.

$538M stolen by drainers: ETH & SOL wallets unite with real-time phishing blocks
Related Reading

$538M stolen by drainers: ETH & SOL wallets unite with real-time phishing blocks

Inside MetaMask/Phantom’s new intel network and how we’ll measure success.

Oct 23, 2025 · Gino Matos

The findings have not been peer reviewed. The paper also gives inconsistent figures for its Avalanche contract count and conflicting endpoints for the observation period, leaving its per-chain breakdown and exact time window unresolved.

How malicious smart contracts fool wallet previews

Transaction simulation takes a pre-signing snapshot of what a transaction is expected to do. The contracts described in the paper contain branches that can produce one result during that check and another when the transaction executes on-chain.

Infographic showing how malicious smart contracts can make a wallet simulation appear safe before execution, with study figures for contracts, victim addresses, transactions and estimated losses.

In a storage-control example, the simulation returns the user’s deposit plus a tiny reward. An attacker can then change the contract’s state, such as by blacklisting the user’s address, before the transaction lands. The executed branch sends the deposit to an attacker-controlled address instead.

Timestamp-based contracts can exploit the later block time, while gas-control contracts can behave differently when the simulator and final transaction use different gas limits. Not every variant therefore requires an attacker to alter stored on-chain data after the preview.

In a controlled test, the authors sent an account’s balance to a contract that returned as little as 1 wei, the smallest unit of ETH. They reported that several tested previews displayed a positive estimate and most did not clearly show the full outgoing amount.

CryptoSlate Daily Brief

Daily signals, zero noise.

Market-moving headlines and context delivered every morning in one tight read.

5-minute digest 100k+ readers

Free. No spam. Unsubscribe any time.

Whoops, looks like there was a problem. Please try again.

You’re subscribed. Welcome aboard.

The paper does not identify the wallet versions, settings, or simulation backends used by victims of these malicious smart contracts. MetaMask’s current documentation calls estimated balance changes predictions and warns that the final outcome is not guaranteed.

MetaMask opens AI wallet for DeFi agents as security risks shift to user rulesMetaMask opens AI wallet for DeFi agents as security risks shift to user rules
Related Reading

MetaMask opens AI wallet for DeFi agents as security risks shift to user rules

Agent Wallet lets software trade onchain, making user-set limits the new line between automation and loss.

Jun 10, 2026 · Liam ‘Akiba’ Wright

A Jan. 8, 2025 Etherscan transaction cited by the study records a Claim() call moving about 143.45 ETH through a contract Etherscan labels as phishing. The on-chain record supports the transfer described in the paper, although it cannot show what appeared in the user’s wallet preview.

The authors recommend re-running simulations when relevant contract state or gas fields change, using the gas limit and gas price in the actual request, and testing current and future block-number and timestamp inputs. Their UI findings also support showing the gross amount leaving a wallet alongside an accurate net balance change, so a negligible refund cannot be mistaken for a profit.

Hundreds of MetaMask wallets drained: What to check before you ‘update'Hundreds of MetaMask wallets drained: What to check before you ‘update'
Related Reading

Hundreds of MetaMask wallets drained: What to check before you ‘update’

ZachXBT tracked $107,000 drained from hundreds of wallets through fake MetaMask emails. Here’s how to spot phishing, revoke approvals, and segregate holdings before attackers strike.

Jan 3, 2026 · Gino Matos

The preprint describes historical activity involving these malicious smart contracts, not a live July or August attack wave. Its detector evaluation covered 44 contracts, including 30 generated with Gemini, and the linked code-and-data repository returned HTTP 401 when checked.

The aggregate results therefore remain the authors’ findings rather than an independently reproduced measurement.

Credit: Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Apple’s App Store promoted fake Bitcoin wallet that stole $1.8M after developer spent a year warning them

July 28, 2026

Two Ethereum bridges lose $31.7M within hours as third protocol halts staking

July 25, 2026

US targets $26.4 million in five crypto scam cases as DOJ says $800 million recovered

July 22, 2026
Leave A Reply Cancel Reply

What's New Here!

BlackRock Targets Stablecoin Issuers and Institutions in Latest Tokenized Funds

August 3, 2026

Corporate crypto accounts on HTX face a complete dead end with zero legal exit routes when EU sanctions strike on August 23

August 3, 2026

Michael Saylor Says He’s Never Sold Bitcoin, Not One Satoshi

August 3, 2026

BlackRock Files With SEC to Issue Tokenized Fund Shares on Solana

August 3, 2026
AsiaTokenFund
Facebook X (Twitter) LinkedIn YouTube
  • Home
  • Crypto News
    • Bitcoin
    • Altcoin
  • Web3
    • Blockchain
  • Trading
  • Regulations
    • Scams
  • Submit Article
  • Contact Us
  • Terms of Use
    • Privacy Policy
    • DMCA
© 2026 asiatokenfund.com - All Rights Reserved!

Type above and press Enter to search. Press Esc to cancel.

Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.