The post Unlucky phishing victim loses $1.08M after signing malicious ‘permit’ signature appeared on BitcoinEthereumNews.com. According to multiple reports, oneThe post Unlucky phishing victim loses $1.08M after signing malicious ‘permit’ signature appeared on BitcoinEthereumNews.com. According to multiple reports, one

Unlucky phishing victim loses $1.08M after signing malicious ‘permit’ signature

According to multiple reports, one crypto user lost approximately $1.08 million worth of Aave-wrapped Ethereum LBTC (aEthLBTC), which is a tokenized Bitcoin asset on the Aave protocol, in what is likely a phishing exploit. 

According to ScamSniffer, the user in question had signed a malicious “permit” signature, which was what led to the theft. That signature was an off-chain approval mechanism, and it allegedly allows tokens to be spent without triggering an immediate on-chain transaction. 

ScamSniffer shared screenshots of the transactions. As to how the victim was susceptible to the exploit, they believe the scammers would have gotten the victim to sign the permit via a phishing site or cloned dApp, giving them access to drain the wallet. 

How did the scam happen? 

SlowMist’s founder, Cosine, commented on the haul, pointing out that the specific phishing group behind the attack is not one of the “mainstream” drainer groups, which suggests an emergence of smaller, sophisticated independent attackers. 

They also moved fast, rapidly converting the funds to ETH and then laundering the funds immediately via Tornado Cash. 

The incident was highlighted on January 3 by ScamSniffer via its X page, not long after it dropped its 2025 yearly report. In the report, as reviewed by Cryptoplitan, it revealed there was an overall 83% drop in crypto phishing losses, falling from $494 million to $84 million. 

However, it emphasized that sophisticated wallet drainers still abound. They just seem to be targeting high-value holders with permit-oriented attacks, as is often the case during a bull market. 

Permit-based exploits depend on the user’s trust in routine signature requests that actually authorize token transfers off-chain. Unfortunately for scams like these, recovery is very unlikely as the draining happens on-chain and transactions are irreversible. 

Crypto phishing losses went down, but wrench attacks went up 

While ScamSniffer has confirmed crypto phishing losses went down in 2025, crypto security experts claim the frequency of so-called “$5 wrench attacks” went up. 

Ari Redbord, the global head of policy and government affairs at crypto analytics firm TRM Labs, called 2025 a record year for wrench attacks, with roughly 60 reported physical assaults on crypto holders, up from 41 in 2024 and 36 in 2021. However, Redbord believes the actual number of attacks that have happened is significantly higher. 

“Many incidents are logged simply as robberies or burglaries, with the crypto element omitted, while others are never reported due to victim hesitation or uncertainty about how law enforcement will handle crypto-related crimes,” Redbord claimed.

The cybersecurity risk called the “wrench attack” derives its name from the idea that even the most sophisticated forms of encryption and data security are susceptible to physical coercion — like getting threatened by a “$5 wrench.” 

These attacks are inarguably worse than phishing exploits and protocol hacks as they not only put assets at risk but also lives, increasing the stakes for maintaining proper OPSEC beyond wallet management best practices. 

“No matter how many technical precautions you take or how many factors you authenticate with, no individual is immune to human attack vectors,” Tor Bair, CEO of Hybrid Minds Advisory and former president of the Secret Foundation, said.

Although the true number of wrench attacks is difficult to quantify, there appears to be either a higher risk of victimization or, at least, a greater awareness of the threat.

Last year May, French Interior Minister Bruno Retailleau spoke up about the rise of crypto-related assaults in the country, which at the time was the site of about one-third of wrench attacks in 2025, including the high-profile kidnapping and torture of Ledger co-founder David Balland and his wife in January.

Join Bybit now and claim a $50 bonus in minutes

Source: https://www.cryptopolitan.com/phishing-victim-loses-1-08m-malicious-permit/

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

YUL: Solidity’s Low-Level Language (Without the Tears), Part 1: Stack, Memory, and Calldata

YUL: Solidity’s Low-Level Language (Without the Tears), Part 1: Stack, Memory, and Calldata

This is a 3-part series that assumes you know Solidity and want to understand YUL. We will start from absolute basics and build up to writing real contracts. YU
Share
Medium2026/01/10 14:06
Franklin Templeton CEO Dismisses 50bps Rate Cut Ahead FOMC

Franklin Templeton CEO Dismisses 50bps Rate Cut Ahead FOMC

The post Franklin Templeton CEO Dismisses 50bps Rate Cut Ahead FOMC appeared on BitcoinEthereumNews.com. Franklin Templeton CEO Jenny Johnson has weighed in on whether the Federal Reserve should make a 25 basis points (bps) Fed rate cut or 50 bps cut. This comes ahead of the Fed decision today at today’s FOMC meeting, with the market pricing in a 25 bps cut. Bitcoin and the broader crypto market are currently trading flat ahead of the rate cut decision. Franklin Templeton CEO Weighs In On Potential FOMC Decision In a CNBC interview, Jenny Johnson said that she expects the Fed to make a 25 bps cut today instead of a 50 bps cut. She acknowledged the jobs data, which suggested that the labor market is weakening. However, she noted that this data is backward-looking, indicating that it doesn’t show the current state of the economy. She alluded to the wage growth, which she remarked is an indication of a robust labor market. She added that retail sales are up and that consumers are still spending, despite inflation being sticky at 3%, which makes a case for why the FOMC should opt against a 50-basis-point Fed rate cut. In line with this, the Franklin Templeton CEO said that she would go with a 25 bps rate cut if she were Jerome Powell. She remarked that the Fed still has the October and December FOMC meetings to make further cuts if the incoming data warrants it. Johnson also asserted that the data show a robust economy. However, she noted that there can’t be an argument for no Fed rate cut since Powell already signaled at Jackson Hole that they were likely to lower interest rates at this meeting due to concerns over a weakening labor market. Notably, her comment comes as experts argue for both sides on why the Fed should make a 25 bps cut or…
Share
BitcoinEthereumNews2025/09/18 00:36
Ethereum Price Prediction: ETH Targets $10,000 In 2026 But Layer Brett Could Reach $1 From $0.0058

Ethereum Price Prediction: ETH Targets $10,000 In 2026 But Layer Brett Could Reach $1 From $0.0058

Ethereum price predictions are turning heads, with analysts suggesting ETH could climb to $10,000 by 2026 as institutional demand and network upgrades drive growth. While Ethereum remains a blue-chip asset, investors looking for sharper multiples are eyeing Layer Brett (LBRETT). Currently in presale at just $0.0058, the Ethereum Layer 2 meme coin is drawing huge [...] The post Ethereum Price Prediction: ETH Targets $10,000 In 2026 But Layer Brett Could Reach $1 From $0.0058 appeared first on Blockonomi.
Share
Blockonomi2025/09/17 23:45