The hacker targeted the liquidity providers of the Uniswap v3 protocol to execute an elaborate phishing campaign. More than $8 million in ETH was believed to бе lost so far in the attack.
Uniswap v3 Protocol LPs Targeted
Metamask security analyst Harry Denley was the first one to detect the incident. He observed that 73,399 addresses were sent a malicious token called “UniswapLP” to target their assets under the pretext of a false UNI tokens airdrop.
The malicious token sent to the victims appeared to come from a legitimate “Uniswap V3: Positions NFT” contract by manipulating the “From” field in the blockchain transaction explorer. The website hosted by bad actors would then read sensitive user information and steal funds from their wallets.
The entity behind the attack is believed to be part of a much more sophisticated attack that had targeted roughly 73,399 addresses by sending a malicious token.
According to speculation that nearly $4.7 million worth of Ether had been drained in the attack. However, crypto tracking and compliance platform MistTrack revealed the amount of stolen funds stands at 7,500 ETH (around $8.1 million), which was then laundered via crypto mixing service Tornado Cash in a total of 100 transactions.
Uniswap Labs’ creator confirmed that the hacker managed to impersonate the official website and deceive the LP provider into signing malicious transactions. The protocol, however, hasn’t been exploited.
Phishing Attacks on the Rise
Web2-style attacks such as phishing campaigns continue to wreak havoc in the Web3 landscape. A slew of phishing websites impersonating Stepn, a Solana-based Web3 lifestyle app, was detected in April. More recently, OpenSea reported a data breach that affected the personally-identifying information (PII) of customers subscribed to its mailing list. It warned customers of potential phishing attempts.
According to a new report by a prominent blockchain and DeFi security-focused platform, CertiK, phishing attacks have increased by 170% since last quarter. It also underscored that social media platforms have emerged as a major pain point for Web3 projects. Throughout Q2, CertiK recorded 290 attacks compared to 106 in Q1 of 2022.
“What’s frustrating about these hacks from a web3 security perspective, is that the hackers are deploying the tried and tested tricks of web2 that exploit centralization and human error as a starting point, and are using this to make lateral moves to exploit web3 in turn.”
Over $8 Million Lost in a Uniswap Phishing Attack
CryptoPotatoPublicado a 2022-07-12Actualizado a 2022-07-12
Resumen
The phishing attack resulted in some LP NFTs being siphoned from users who approved malicious transactions, the Uniswap founder, Hayden Adams confirmed.
Lecturas Relacionadas
Trading
Artículos destacados
Cómo comprar UNI
¡Bienvenido a HTX.com! Hemos hecho que comprar Uniswap (UNI) sea simple y conveniente. Sigue nuestra guía paso a paso para iniciar tu viaje de criptos.Paso 1: crea tu cuenta HTXUtiliza tu correo electrónico o número de teléfono para registrarte y obtener una cuenta gratuita en HTX. Experimenta un proceso de registro sin complicaciones y desbloquea todas las funciones.Obtener mi cuentaPaso 2: ve a Comprar cripto y elige tu método de pagoTarjeta de crédito/débito: usa tu Visa o Mastercard para comprar Uniswap (UNI) al instante.Saldo: utiliza fondos del saldo de tu cuenta HTX para tradear sin problemas.Terceros: hemos agregado métodos de pago populares como Google Pay y Apple Pay para mejorar la comodidad.P2P: tradear directamente con otros usuarios en HTX.Over-the-Counter (OTC): ofrecemos servicios personalizados y tipos de cambio competitivos para los traders.Paso 3: guarda tu Uniswap (UNI)Después de comprar tu Uniswap (UNI), guárdalo en tu cuenta HTX. Alternativamente, puedes enviarlo a otro lugar mediante transferencia blockchain o utilizarlo para tradear otras criptomonedas.Paso 4: tradear Uniswap (UNI)Tradear fácilmente con Uniswap (UNI) en HTX's mercado spot. Simplemente accede a tu cuenta, selecciona tu par de trading, ejecuta tus trades y monitorea en tiempo real. Ofrecemos una experiencia fácil de usar tanto para principiantes como para traders experimentados.
365 Vistas totalesPublicado en 2024.12.12Actualizado en 2025.03.21

Discusiones





