More than $4.7M stolen in Uniswap fake token phishing attack

Cointelegraph发布于2022-07-12更新于2022-07-12

文章摘要

A sophisticated phishing campaign targeting liquidity providers (LPs) of the Uniswap v3 protocol has seen attackers .

A sophisticated phishing campaign targeting liquidity providers (LPs) of the Uniswap v3 protocol has seen attackers make off with at least $4.7 million worth of Ethereum (ETH). However, the community is reporting the losses could be even greater. 
Metamask security researcher Harry Denley was one of the first to raise the alarm bells of the attack, telling his 13,000 Twitter followers on July 11 that 73,399 addresses had been sent malicious ERC-20 tokens to steal their assets.


At least $4.7 million in ETH has been lost in the attack, according to a Twitter post from Binance CEO Changpeng “CZ” Zhao. However, there are also reports amongst the crypto community that there may be more significant losses from the incursion.
Prominent crypto Twitter user 0xSisyphus noted on July 11 that a “large LP” with around 16,140 ETH, worth $17.5 million, may have also been phished.


How it works
According to Denley, the phishing attack works by sending unsuspecting users a “malicious token” called “UniswapLP” — made to appear as coming from the legitimate "Uniswap V3: Positions NFT" contract by manipulating the “From” field in the blockchain transaction explorer.
Users curious about their new tokens would be directed to a website purporting to allow them to swap their new tokens for Uniswap’s native token UNI, worth $5.34 each at the time of writing.
The website would instead send the users’ address and browser client info to the attackers’ command center, which would also attempt to drain cryptocurrency from their wallets.
A Reddit post also explaining the attack noted that the attackers had stolen native tokens (ETH), ERC20 tokens, and NFTs (namely Uniswap LP positions) from victims.


Not an exploit
Binance’s CEO Zhao created some waves in the crypto markets when he first sounded alarms about the attack, calling it a “potential exploit” of the Uniswap protocol on the ETH blockchain.
Zhao clarified soon after the post with another update, sharing a conversation with the Uniswap team, who noted the attack was part of a phishing attack rather than any issue with the protocol.


CZ’s initial alarming comments coincided with a sharp drop in the Uniswap price, which fell to a 24-hour low of $5.34. The price of UNI has since recovered following the clarification to $5.48 at the time of writing but is still down 11% in 24 hours and is 87.8% down from its all-time-high (ATH).

热门币种推荐

你可能也喜欢

研报解读:MRVL 光学 AI 迎来爆发,为何高估值让大摩明星分析师选择按兵不动?

摩根士丹利分析师Joseph Moore于5月28日更新了对迈威尔(MRVL)的研报。尽管公司季报创纪录并大幅上调全年展望,但Moore维持“等权重”(中性)评级,目标价从172美元上调至195美元,仍低于当时股价。 **核心观点**:分析师认可迈威尔的AI增长机会,但认为当前股价已充分反映预期。195美元目标价对应约40倍2027年预期市盈率。对比英伟达,两者股价接近,但英伟达的每股盈利预期是迈威尔的两倍多。Moore认为,迈威尔需同时兑现以下假设才能支撑当前估值:1)光互联业务持续放量;2)定制AI芯片顺利大规模出货;3)存储及企业业务复苏。 **业务分析**: - **光互联**(高速增长):受益于AI集群数据传输需求,预计未来几个季度光模块产品线年化营收将达10亿美元,是当前最确定的增长点。 - **定制AI芯片**(正在爬坡):为云厂商设计专用芯片,新大客户预计2028财年量产,但今年收入尚不明朗。 - **传统业务**:存储、企业数据中心等板块仍处于去库存阶段,短期缺乏复苏动力。 **关键监测信号**:光模块营收能否如期达到10亿美元年化水平;新客户定制芯片项目能否在2028财年量产;传统业务何时复苏。若任何一环不及预期,当前高估值可能面临压力。 (本文为对第三方研报的解读,不构成投资建议。)

marsbit47分钟前

研报解读:MRVL 光学 AI 迎来爆发,为何高估值让大摩明星分析师选择按兵不动?

marsbit47分钟前

Kraken面向美国专业交易者推出CFTC监管的永续期货

Kraken交易所宣布,通过整合Bitnomial,为美国符合条件的机构和专业客户推出受美国商品期货交易委员会(CFTC)监管的永续期货合约。该产品已在Kraken Pro上线,由CFTC注册的期货佣金商NinjaTrader Clearing提供经纪和清算服务,支持BTC、ETH等多种主流加密资产,并采用八小时资金费率机制。 永续期货是加密货币市场的主流衍生品,允许杠杆交易且无固定到期日。此前这类交易多集中于离岸平台。Kraken此举并非创造新产品,而是将已有的加密原生市场结构引入受监管的美国合规场所,为专业交易者提供了在离岸流动性和本土监管合规性之间的新选择。 需要明确的是,此次发布并非面向大众零售客户,仅限于合格的专业投资者。对Kraken而言,这是构建更完整美国衍生品体系的一部分;对整个市场而言,它标志着永续期货开始正式进入美国受监管的领域。 然而,离岸平台目前仍占据交易量主导。该产品能否成功,关键在于其能否在点差、资金效率、保证金规则和执行质量上提供有竞争力的流动性,从而吸引专业交易者。如果能够实现,可能促使部分交易活动回归岸内;反之,其意义将更多停留在象征层面。市场后续应关注官方确认、初期反响是否持续,以及该发展是否会对流动性格局、监管或风险管理产生持久影响。

bitcoinist1小时前

Kraken面向美国专业交易者推出CFTC监管的永续期货

bitcoinist1小时前

交易

现货
合约

热门文章

如何购买UNI

欢迎来到HTX.com!我们已经让购买Uniswap(UNI)变得简单而便捷。跟随我们的逐步指南,放心开始您的加密货币之旅。第一步:创建您的HTX账户使用您的电子邮件、手机号码注册一个免费账户在HTX上。体验无忧的注册过程并解锁所有平台功能。立即注册第二步:前往买币页面,选择您的支付方式信用卡/借记卡购买:使用您的Visa或Mastercard即时购买Uniswap(UNI)。余额购买:使用您HTX账户余额中的资金进行无缝交易。第三方购买:探索诸如Google Pay或Apple Pay等流行支付方法以增加便利性。C2C购买:在HTX平台上直接与其他用户交易。HTX场外交易台(OTC)购买:为大量交易者提供个性化服务和竞争性汇率。第三步:存储您的Uniswap(UNI)购买完您的Uniswap(UNI)后,将其存储在您的HTX账户钱包中。您也可以通过区块链转账将其发送到其他地方或者用于交易其他加密货币。第四步:交易Uniswap(UNI)在HTX的现货市场轻松交易Uniswap(UNI)。访问您的账户,选择您的交易对,执行您的交易,并实时监控。HTX为初学者和经验丰富的交易者提供了友好的用户体验。

1.3k人学过发布于 2024.03.29更新于 2026.06.02

如何购买UNI

相关讨论

欢迎来到HTX社区。在这里,您可以了解最新的平台发展动态并获得专业的市场意见。以下是用户对UNI(UNI)币价的意见。

活动图片