4,200 Phishing Smart Contracts Deceived 6,000 Victims Out of $3.48 Million
Researchers have identified over 4,200 malicious smart contracts that successfully tricked nearly 6,000 victims into signing away their cryptocurrency. The study linked these contracts to $3.48 million in losses.
The researchers used SimGuard, a contract-bytecode detector, to identify the phishing contracts across Ethereum, BNB Smart Chain, Avalanche, and Polygon. They found that these contracts can show benign wallet previews before rerouting deposits when on-chain conditions change.
Transaction simulation takes a pre-signing snapshot of what a transaction is expected to do. However, the contracts described in the paper contain branches that can produce one result during this check and another when the transaction executes on-chain.