Malicious Smart Contracts Tricked 5,700 Victims Out of $3.48 Million
A recent study has uncovered 4,200 malicious smart contracts on Ethereum and other blockchains that successfully tricked 5,700 victims into signing away their cryptocurrency. The contracts, which were identified using a contract-bytecode detector called SimGuard, simulated transfers to show a small gain, but ultimately sent the user's deposit to an attacker-controlled address.
The study associated these contracts with $3.48 million in historical losses, with 91.5% of the losses attributed to Ethereum. The authors recommend that wallet users re-run simulations when relevant contract state or gas fields change and use the actual request's gas limit and gas price.