Malicious Smart Contracts Steal $3.48M from Over 5,700 Victims
A recent study has uncovered 4,224 malicious smart contracts that have successfully tricked over 5,700 victims into signing away their cryptocurrency. The contracts were found to be lurking on various blockchain networks, including Ethereum, BNB Smart Chain, Avalanche, and Polygon.
The study used a contract-bytecode detector called SimGuard to identify the phishing contracts. It was found that these contracts contained branches that could produce one result during a pre-signing snapshot of what a transaction is expected to do, but another when the transaction executes on-chain.
The authors of the study reported that several tested previews displayed a positive estimate and most did not clearly show the full outgoing amount. In some cases, the simulation returned the user's deposit plus a tiny reward, only to send the deposit to an attacker-controlled address later.