Signature Phishing Up 200% As January Losses Pass $6M

ETH-0,96%
XAUT0,08%
TOKEN-0,4%

In brief

  • Signature phishing victims jumped more than 200% in January, with $6.27 million stolen, blockchain security firm Scam Sniffer warned.
  • Despite the spike, total phishing losses in 2025 were sharply lower than in 2024.
  • Cheaper Ethereum fees after the Fusaka upgrade have made phishing tactics like mass address poisoning attacks more attractive for scammers, researchers said.

Blockchain security firm Scam Sniffer is warning of a sharp spike in signature phishing, with losses totaling $6.27 million and 4,700 wallets drained in January—an increase of 207% from December. Signature phishing occurs when attackers lure users to malicious decentralized applications that prompt them to sign off‑chain messages. While the requests appear harmless—such as approving a token deposit or listing an NFT—the signatures can instead authorize unlimited token spending or the transfer of NFTs, allowing attackers to later drain wallets.

Someone lost $12.25M in January by copying the wrong address from their transaction history. In December, another victim lost $50M the same way.

Two victims. $62M gone.

Signature phishing also surged — $6.27M stolen across 4,741 victims (+207% vs Dec).

Top cases:
· $3.02M —… pic.twitter.com/7D5ynInRrb

— Scam Sniffer | Web3 Anti-Scam (@realScamSniffer) February 8, 2026

The January surge contrasts with a broader decline in crypto phishing over the past year. Scam Sniffer reported total phishing losses of $83.85 million across 106,106 victims in 2025 on Ethereum and EVM-based chains, down 83% in value and 68% in victims compared with 2024. Losses last month were highly concentrated. Two wallets accounted for roughly 65% of the total stolen through phishing and other attacks, including $3.02 million taken through a permit and increaseAllowance attack involving SLV and XAUt tokens, and $1.08 million drained via a permit attack. Beyond signature phishing, Scam Sniffer pointed to address poisoning and permit scams as key contributors. Address poisoning attackers send tiny transactions, or dust, to targets using addresses that closely resemble legitimate ones the wallet has already interacted with. When users later copy an address from their transaction history, they may inadvertently send funds to an attacker-controlled lookalike address.  Ethereum’s Fusaka upgrade changes scam economics Researchers said tactics like address poisoning have become more attractive following Ethereum’s Fusaka upgrade, which sharply reduced transaction fees. Blockchain researcher Andrey Sergeenkov found that new address creation surged last month, with one week seeing 2.7 million new addresses, about 170% above typical levels. He said roughly two-thirds of new addresses received less than $1 in stablecoins as their first transaction, consistent with large-scale address poisoning campaigns.

Sergeenkov argued that lower Ethereum fees have changed the economics of mass poisoning attacks. While conversion rates remain extremely low, the reduced cost of sending millions of dust transactions has made the strategy viable, with profits now coming from a small number of high-value mistakes. In addition to ensuring users check transactions and make sure they understand what they are signing or where they are sending money, wallets are also trying to introduce features to limit the risk of attacks. Tara Annison, head of product at Twinstake, said wallets are increasingly adding transaction simulations, clearer warnings and pre-execution checks to flag risky interactions. “Rabby does pre-execution simulation and will warn you if you’re interacting with known malicious smart contracts or if there’s hidden logic in the transaction,” she told_ Decrypt_. Metamask, meanwhile, “gives you a nice big warning if the site you’re connecting to looks like a phishing website and includes human readable warnings if the transaction looks like it might be about to do something dodgy for your assets,” Annison said. She added wallets are placing security features like this “front and centre to avoid you signing something you shouldn’t.” Decrypt has approached the Ethereum Foundation for comment.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

Investigation Report: Timor-Leste’s “crypto resort” project appears to be linked to the sanctioned fraud group Prince Group, but the construction site is empty

The Guardian and the Organized Crime and Corruption Reporting Project (OCCRP) released the results of their four-month joint investigation, revealing that in Timor-Leste, one of the world’s poorest countries, a development project billed as the “world’s first cryptocurrency resort” appears to be linked to a scam network operated by Cambodia’s Prince Group, which is subject to U.S. sanctions. This February, the investigative reporters went to the construction site near Dili airport for on-site interviews, only to find an empty lot overgrown with weeds. A gap between promotion and reality: the luxury crypto resort is now just an empty lot AB Digital Technology Resort’s promotional materials tout luxury villas, ocean views, and a “global technology elite exchange hub,” and claim that it will use part of its proceeds for charity. However, when the reporter went to the coastal construction site shown in the promotional photos, they found that there was nothing at all on the fenced-off land—only scattered shrubs. This project is under investigation’s review

ChainNewsAbmedia1h ago

HypurrFi announces that the blockchain hash has surpassed a new milestone, and the same day it also faced a domain hijacking incident

HypurrFi announced that its independently developed Hyperliquid client has successfully achieved block-hash consistency, enabling developers to independently verify the on-chain state and improving decentralization. On the same day, it discovered a domain-hijacking incident; although it did not affect users’ funds, it still urged everyone to stop interacting with suspicious domains immediately and to obtain updates through official channels. AI contributed 99.9% to this technical development.

MarketWhisper1h ago

Chaos Labs exits Aave, saying there is a legal gap in DeFi risk management

Risk management firm Chaos Labs announced it is ending its three-year partnership with DeFi lending protocol Aave, citing a fundamental disagreement between the two parties on approaches to risk management. This exit has exposed the legal gray area in the DeFi ecosystem where regulatory safeguards are lacking—especially after a recent oracle incident that led to an erroneous liquidation of about $27 million. The separation between Chaos Labs and Aave leaves Aave facing a governance vacuum during a critical period for the V4 upgrade, further fueling concerns about accountability for decentralized risk systems.

MarketWhisper2h ago

The Ministry of State Security warns of risks from mnemonic-token scams, involving allegedly illegal financial activities such as stockpiling mnemonic tokens and off-exchange trading

The Ministry of State Security issued a notice warning of the risks of “token scams,” stating that hoarding tokens and off-exchange trading may involve illegal financial activities that endanger national security. It emphasizes the need to guard against risks such as data leakage, forgery, and fraud, and reminds the public to view tokens rationally while strengthening awareness of information and privacy security.

GateNews2h ago

Phantom Wallet experiences a service outage, and token price and balance displays are affected

Gate News update: On April 7, the crypto wallet app Phantom experienced a temporary service interruption, causing abnormal token prices and balance displays. The Phantom team said it is actively working to fix the issue.

GateNews2h ago

Jack Dorsey posted to confirm that Apple has removed Bitchat, the decentralized messaging software, at China’s request.

Block CEO Jack Dorsey confirmed that Apple has removed the decentralized communications app Bitchat in accordance with China’s requirements because it violates China’s Cybersecurity Law. Bitchat uses Bluetooth and a mesh network for communication and does not rely on the internet, which is why it has been widely used in protests. The app can still be used in other countries, and the global download count has exceeded 3 million.

ChainNewsAbmedia13h ago
Comment
0/400
No comments