tldr; A phishing attack drained over $3 million in USDC from a 2-of-4 Safe multi-signature wallet. The attacker used a fraudulent contract with a near-identical address to the legitimate one, exploiting the Safe Multi Send mechanism to disguise the malicious approval. Funds were swapped for Ethereum and funneled into Tornado Cash. The exploit was executed via the Request Finance app, which has since patched the vulnerability. The incident highlights evolving phishing tactics using verified contracts and similar addresses to bypass scrutiny.
*This summary is auto generated by a bot and not meant to replace reading the original article. As always, DYOR.
DryMyBottom on
there’s always something new in the way shitty people steal out money
J-96788-EU on
Everything new is called sophisticated.
Leave A Reply
Du musst angemeldet sein, um einen Kommentar abzugeben.
3 Kommentare
tldr; A phishing attack drained over $3 million in USDC from a 2-of-4 Safe multi-signature wallet. The attacker used a fraudulent contract with a near-identical address to the legitimate one, exploiting the Safe Multi Send mechanism to disguise the malicious approval. Funds were swapped for Ethereum and funneled into Tornado Cash. The exploit was executed via the Request Finance app, which has since patched the vulnerability. The incident highlights evolving phishing tactics using verified contracts and similar addresses to bypass scrutiny.
*This summary is auto generated by a bot and not meant to replace reading the original article. As always, DYOR.
there’s always something new in the way shitty people steal out money
Everything new is called sophisticated.