New Web3 attack exploits transaction simulations to steal crypto

Teilen:

Threat actors are employing a new tactic called “transaction simulation spoofing” to steal crypto, with one attack successfully stealing 143.45 Ethereum, worth approximately $460,000.

The attack, spotted by ScamSniffer, highlights a flaw in transaction simulation mechanisms used in modern Web3 wallets, meant to safeguard users from fraudulent and malicious transactions.

How the attack works
Transaction simulation is a feature that allows users to preview the expected outcome of a blockchain transaction before signing and executing it.

It is designed to enhance security and transparency by helping users verify what the transaction will do, like the amount of transferred cryptocurrency, gas fees and other transaction costs, and other on-chain data changes.

The attackers lure victims to a malicious website that mimics a legitimate platform, which initiates what is made to appear as a “Claim” function. The transaction simulation shows that the user will receive a small amount in ETH.

However, a time delay between the simulation and the execution allows the attackers to alter the on-chain contract state to change what the transaction will actually do if approved.

The victim, trusting the wallet’s transaction simulation result, signs the transaction, allowing the site to drain their wallet of all crypto and send it to the attacker’s wallet.

Angriffsfluss
Angriffsfluss
Source: ScamSniffer
ScamSniffer highlights an actual case where the victim signed the deceptive transaction 30 seconds after the state change, losing all their assets (143.35 ETH) as a result.

“This new attack vector represents a significant evolution in phishing techniques.” warns ScamSniffer

“Rather than relying on simple deception, attackers are now exploiting trusted wallet features that users rely on for security. This sophisticated approach makes detection particularly challenging.”

Initial simulation (top) and manipulated transaction (bottom)
Initial simulation (top) and manipulated transaction (bottom)
Source: ScamSniffer
The blockchain monitoring platform suggests that Web3 wallets reduce the simulation refresh rates to match blockchain block times, force refresh simulation results before critical operations, and add expiration warnings to warn users about the risk.

From the user’s perspective, this new attack shows why wallet simulation shouldn’t be trusted.

Cryptocurrency holders should treat “free claim” offers on obscure websites with caution and only trust verified dApps.

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
11:18 pm, Juni 30, 2025
Wetter-Symbol 25°C
L: 23° | H: 26°
klarer Himmel
Luftfeuchtigkeit: 63 %
Druck: 1014 mb
Wind: 3 mph SSE
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 0%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:46 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Tomorrow 10:00 pm
Wetter-Symbol
23° | 26°°C 0 mm 0% 11 mph 65 % 1015 mb 0 mm/h
Mi. Juli 02 10:00 pm
Wetter-Symbol
19° | 26°°C 0 mm 0% 12 mph 75 % 1024 mb 0 mm/h
Do. Juli 03 10:00 pm
Wetter-Symbol
14° | 26°°C 0 mm 0% 7 mph 53 % 1029 mb 0 mm/h
Fr. Juli 04 10:00 pm
Wetter-Symbol
16° | 28°°C 0 mm 0% 10 mph 47 % 1028 mb 0 mm/h
Sa. Juli 05 10:00 pm
Wetter-Symbol
16° | 21°°C 1 mm 100% 12 mph 90 % 1019 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
23° | 24°°C 0 mm 0% 3 mph 62 % 1014 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
21° | 22°°C 0 mm 0% 3 mph 65 % 1014 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
22° | 22°°C 0 mm 0% 5 mph 61 % 1014 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
28° | 28°°C 0 mm 0% 3 mph 44 % 1014 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
30° | 30°°C 0 mm 0% 6 mph 32 % 1014 mb 0 mm/h
Tomorrow 4:00 pm
Wetter-Symbol
34° | 34°°C 0 mm 0% 8 mph 26 % 1013 mb 0 mm/h
Tomorrow 7:00 pm
Wetter-Symbol
32° | 32°°C 0 mm 0% 11 mph 31 % 1013 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
25° | 25°°C 0 mm 0% 8 mph 46 % 1015 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€91,726.36
0.08%
Ethereum(ETH)
€2,141.69
2.99%
Fesseln(USDT)
€0.85
0.00%
XRP(XRP)
€1.95
4.59%
Solana(SOL)
€134.28
4.10%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.142338
1.58%
Shiba Inu(SHIB)
€0.000010
0.00%
Pepe(PEPE)
€0.000009
2.69%
Nach oben scrollen