Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert & block trade
Convert crypto with one click and zero fees
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
New ‘sophisticated’ phishing exploit drains $3M in USDC from multi-sig wallet

New ‘sophisticated’ phishing exploit drains $3M in USDC from multi-sig wallet

CryptoSlateCryptoSlate2025/09/12 02:56
By:Oluwapelumi Adejumo

An unidentified crypto investor has lost over $3 million in a highly coordinated phishing attack after unknowingly authorizing a malicious contract.

On Sept. 11, blockchain investigator ZachXBT first flagged the incident, revealing that the victim’s wallet was drained of $3.047 million in USDC.

The attacker quickly swapped the stablecoins for Ethereum and funneled the proceeds into Tornado Cash, a privacy protocol often used to obscure the flow of stolen funds.

How the exploit occurred

SlowMist founder Yu Xian explained that the compromised address was a 2-of-4 Safe multi-signature wallet.

He explained that the breach originated from two consecutive transactions in which the victim approved transfers to an address that mimicked their intended recipient.

The attacker crafted the fraudulent contract so that its first and last characters mirrored the legitimate one, making it difficult to detect.

Xian added that the exploit took advantage of the Safe Multi Send mechanism, disguising the abnormal approval inside what appeared to be a routine authorization.

He wrote:

“This abnormal authorization was hard to detect because it wasn’t a standard approve.”

According to Scam Sniffer, the attacker had prepared the ground well in advance. They deployed a fake but Etherscan-verified contract nearly two weeks earlier, programming it with multiple “batch payment” functions to look legitimate.

On the day of the exploit, the malicious approval was executed through the Request Finance app interface, giving the attacker access to the victim’s funds.

In response, Request Finance acknowledged that a malicious actor had deployed a counterfeit version of its Batch Payment contract. The company noted that only one customer was affected and stressed that the vulnerability has since been patched.

Still, Scam Sniffer highlighted broader concerns about the phishing incident.

The blockchain security firm warned that similar exploits could stem from several vectors, including app vulnerabilities, malware or browser extensions modifying transactions, compromised front-ends, or DNS hijacking.

More importantly, the use of verified contracts and near-identical addresses illustrates how attackers are refining their methods to bypass user scrutiny.

The post New ‘sophisticated’ phishing exploit drains $3M in USDC from multi-sig wallet appeared first on CryptoSlate.

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

Will PayFi be the next narrative for RWA?

Can uncollateralized credit lending protocols work in the DeFi world?

雨中狂睡2025/09/13 18:03
Will PayFi be the next narrative for RWA?

a16z's Latest Insight: Consumer AI Companies Will Redefine the Enterprise Software Market

The boundaries between the consumer market and the enterprise market are gradually becoming blurred to some extent.

BlockBeats2025/09/13 17:54
a16z's Latest Insight: Consumer AI Companies Will Redefine the Enterprise Software Market