Shocking NFT Heist: How Scammers Made Off with $110K in Minutes! ๐Ÿ˜ฑ๐Ÿ’ธ

  • Oh look, another NFT theft! $18K just vanished into thin air! ๐ŸŽฉโœจ
  • Fake airdrop? More like fake your bank account! $92K ETH gone! ๐Ÿ’”๐Ÿ’ฐ
  • Pro tip: Re-deploy those old approvals and verify domains, or just keep your money in a piggy bank. ๐Ÿท๐Ÿ’ธ

So, here we are again, folks! NFT and crypto scams have racked up a staggering $110,000 in losses, all thanks to some sneaky malicious approvals and those delightful blind signatures. This week, our friends at Web3 Antivirus uncovered not one, but two wallet-draining attacks. Because why not? ๐Ÿ˜

Picture this: Offenders swindled rare NFTs and a hefty chunk of Ethereum from their unsuspecting victims, who were probably just trying to buy a cute digital cat or something. ๐Ÿฑ๐Ÿ’”

In the first act of this tragicomedy, NFTs worth around $18,000 were snatched away. Yes, you heard that right! With a malicious contract approval, the attackers wiped out the precious Plooshy #565 and a few Lil Pudgys NFTs. It was like a digital heist movie, but with less Brad Pitt and more tears. ๐ŸŽฌ๐Ÿ˜ข

NFT drains and multicall expose flow through Blind Signatures

Source – X

According to Web3 Antivirus on X (not the social media platform, but you get it), several prized NFTs were sold faster than you can say “I should have checked my approvals.” The fraudsters exploited malicious approvals to bypass normal security, giving them access to the tokens like they were at an all-you-can-eat buffet. ๐Ÿฝ๏ธ๐Ÿ˜ฑ

This is a during-transfer strategy that lets assets be transferred without the userโ€™s consent. Because who needs consent when you can just take what you want, right? ๐Ÿ™„

These wallets (0xac82โ€ฆ, 0xb1f9โ€ฆ) that scammed it with the multicall functionality drained funds systematically and without detection. Analysts are waving red flags about blind approvals, insisting that contract verification must be done thoroughly. Because, you know, itโ€™s not like weโ€™re living in a digital Wild West or anything. ๐Ÿค 

Scalper Pseudocross airdrop Contract Snatches 92K ETH

Source – X

In another episode of “What Were They Thinking?”, one poor soul lost nearly $100,000 in ETH. All it took was a blind signature to interact with a fake airdrop contract called Cross Airdrop. Spoiler alert: the wallet was emptied faster than you can say “I should have done my research.” ๐Ÿ˜ฌ

Web3 Antivirus is waving the caution flag about blind signatures, especially on those sketchy airdrop sites. They recommend users check the authenticity of the domain and invalidate stale contract approvals. Because, apparently, trusting random links is not a good idea. Who knew? ๐Ÿคทโ€โ™€๏ธ

Analysts are observing that scammers are getting creative, mixing traditional tricks with smart contract bugs. Itโ€™s like theyโ€™re the Picasso of digital crime. ๐ŸŽจ๐Ÿ’”

These malware attacks are aimed at targeting naive users who innocently believe theyโ€™re just having a casual chat with the web3 world. Spoiler: itโ€™s not a friendly chat. ๐Ÿ˜ฌ

Blockchain security sources are shouting from the rooftops that wallet users need to keep track of contract permission revocation regularly. Because if you donโ€™t, you might as well just hand your wallet to the nearest scammer. ๐Ÿฅด

Read More

2025-08-20 23:43