Signature Phishing Up 200% As January Losses Pass $6M

ETH2,98%
XAUT-0,3%
TOKEN-0,67%

In brief

  • Signature phishing victims jumped more than 200% in January, with $6.27 million stolen, blockchain security firm Scam Sniffer warned.
  • Despite the spike, total phishing losses in 2025 were sharply lower than in 2024.
  • Cheaper Ethereum fees after the Fusaka upgrade have made phishing tactics like mass address poisoning attacks more attractive for scammers, researchers said.

Blockchain security firm Scam Sniffer is warning of a sharp spike in signature phishing, with losses totaling $6.27 million and 4,700 wallets drained in January—an increase of 207% from December. Signature phishing occurs when attackers lure users to malicious decentralized applications that prompt them to sign off‑chain messages. While the requests appear harmless—such as approving a token deposit or listing an NFT—the signatures can instead authorize unlimited token spending or the transfer of NFTs, allowing attackers to later drain wallets.

Someone lost $12.25M in January by copying the wrong address from their transaction history. In December, another victim lost $50M the same way.

Two victims. $62M gone.

Signature phishing also surged — $6.27M stolen across 4,741 victims (+207% vs Dec).

Top cases:
· $3.02M —… pic.twitter.com/7D5ynInRrb

— Scam Sniffer | Web3 Anti-Scam (@realScamSniffer) February 8, 2026

The January surge contrasts with a broader decline in crypto phishing over the past year. Scam Sniffer reported total phishing losses of $83.85 million across 106,106 victims in 2025 on Ethereum and EVM-based chains, down 83% in value and 68% in victims compared with 2024. Losses last month were highly concentrated. Two wallets accounted for roughly 65% of the total stolen through phishing and other attacks, including $3.02 million taken through a permit and increaseAllowance attack involving SLV and XAUt tokens, and $1.08 million drained via a permit attack. Beyond signature phishing, Scam Sniffer pointed to address poisoning and permit scams as key contributors. Address poisoning attackers send tiny transactions, or dust, to targets using addresses that closely resemble legitimate ones the wallet has already interacted with. When users later copy an address from their transaction history, they may inadvertently send funds to an attacker-controlled lookalike address.  Ethereum’s Fusaka upgrade changes scam economics Researchers said tactics like address poisoning have become more attractive following Ethereum’s Fusaka upgrade, which sharply reduced transaction fees. Blockchain researcher Andrey Sergeenkov found that new address creation surged last month, with one week seeing 2.7 million new addresses, about 170% above typical levels. He said roughly two-thirds of new addresses received less than $1 in stablecoins as their first transaction, consistent with large-scale address poisoning campaigns.

Sergeenkov argued that lower Ethereum fees have changed the economics of mass poisoning attacks. While conversion rates remain extremely low, the reduced cost of sending millions of dust transactions has made the strategy viable, with profits now coming from a small number of high-value mistakes. In addition to ensuring users check transactions and make sure they understand what they are signing or where they are sending money, wallets are also trying to introduce features to limit the risk of attacks. Tara Annison, head of product at Twinstake, said wallets are increasingly adding transaction simulations, clearer warnings and pre-execution checks to flag risky interactions. “Rabby does pre-execution simulation and will warn you if you’re interacting with known malicious smart contracts or if there’s hidden logic in the transaction,” she told_ Decrypt_. Metamask, meanwhile, “gives you a nice big warning if the site you’re connecting to looks like a phishing website and includes human readable warnings if the transaction looks like it might be about to do something dodgy for your assets,” Annison said. She added wallets are placing security features like this “front and centre to avoid you signing something you shouldn’t.” Decrypt has approached the Ethereum Foundation for comment.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

Web3 wallet Zerion detected abnormal activity on the platform; the web service is temporarily offline

Gate News message, April 11, Web3 wallet Zerion posted an announcement on the X platform saying that it detected abnormal activity on the platform, and the web app service has been temporarily taken offline. Zerion urges users to temporarily not use the web app; at the moment, the iOS and Android apps, as well as the browser extension program, are running normally and are secure, and users’ funds in the wallet are not affected. Zerion says it is actively monitoring the situation, and it will notify users separately once the web application is restored.

GateNews12h ago

Phantom Wallet crashes big time! During the airdrop period, token prices went haywire and balances were reset to zero—users blasted it for “making them pay up.”

Phantom, a wallet in the Solana ecosystem, experienced a service outage during the airdrop, causing abnormal token prices and account balances to be displayed, which affected user transactions. Some users suffered losses as a result and demanded compensation. Security experts warned of the risk of phishing attacks and advised users to verify on-chain data. Although the issue has been fixed, the trust crisis still needs to be monitored. This incident highlights the challenges of self-custody wallets in terms of system stability and the user experience.

区块客13h ago

TAO Plummets 25% as Bittensor Co-Founder Accused of Using Token Sales to Coerce Compliance

Bittensor's TAO token dropped 25% due to allegations of centralized control by co-founder Jacob Steeves, resulting in $650 million market cap loss and $9.1 million liquidations. The controversy raises concerns about the project's governance.

Coinpedia13h ago

Bitcoin Depot Discloses $3.6M BTC Theft After Hack on Settlement Accounts

Bitcoin Depot reported a security breach where hackers stole 50.9 BTC, worth approximately $3.6 million, by compromising internal settlement account credentials. This incident highlights vulnerabilities in crypto companies' operational infrastructure, emphasizing the need for enhanced security measures.

CryptoNewsFlash17h ago

OpenAI Releases an Announcement on a Third-Party Library Security Incident: No Evidence of User Data Leaks or System Intrusion Found

OpenAI issued a security advisory on April 11 confirming that it identified a security issue involving the third-party library Axios, but found no evidence that user data was accessed. To ensure security, the company requires all macOS users to update to the latest version to prevent the risk of forged applications.

GateNews17h ago

Blockchain security losses from 2026 to date are nearly $800 million, with incidents related to North Korea accounting for about 42%.

Since January 1, 2026, CertiK Alert has recorded 163 blockchain security incidents, with total losses of about $796.7 million. Of these, 12 were related to North Korean hacker organizations, with losses of about $329 million, accounting for 42% of total losses. Compared with the 60% share in 2025, it has declined.

GateNews19h ago
Comment
0/400
No comments