New Web3 attack exploits transaction simulations to steal crypto
ID: 1558a9a8-a16b-548b-b7a2-62fe1fb0205e
STIX ID: report--1558a9a8-a16b-548b-b7a2-62fe1fb0205e
Feed Name: Bleeping Computer
Threat actors are exploiting a flaw in Web3 wallet transaction simulation — known as "transaction simulation spoofing" — to deceive users into signing transactions that are altered after simulation and before execution, allowing attackers to drain wallets; ScamSniffer reported a case that resulted in the loss of 143.45 ETH (~$460k). The report explains the attack flow, includes examples and visuals, and recommends mitigations such as aligning simulation refresh rates with block times, forcing simulation refreshes before critical operations, and adding expiration warnings.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
