Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert
Zero fees, no slippage
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
Inferno Drainer Steals $150,000 in Crypto Phishing Attack

Inferno Drainer Steals $150,000 in Crypto Phishing Attack

BeInCryptoBeInCrypto2025/05/25 08:00
By:Oluwapelumi Adejumo

This marks a shift in crypto phishing tactics, with scammers now integrating Ethereum upgrades to bypass user defenses.

A notorious phishing group known as Inferno Drainer has begun exploiting a new Ethereum feature to launch wallet-draining attacks

The group is taking advantage of Ethereum Improvement Proposal (EIP) 7702, a key part of the Pectra upgrade, which allows Externally Owned Accounts (EOAs) to temporarily act like smart contract wallets during transactions.

Sophisticated Crypto Phishing Scam Exploits Ethereum’s Smart Wallet Flexibility

On May 24, Scam Sniffer, a web3 anti-scam platform, flagged a case where a wallet recently upgraded to EIP-7702 lost nearly $150,000.

According to Yu Xian, founder of blockchain security firm SlowMist, Inferno Drainer carried out the theft using a more sophisticated version of traditional phishing.

Unlike previous scams that hijack user wallets directly, Xian explained that Inferno Drainer used a delegated MetaMask wallet—one already authorized under EIP-7702.

He said this allowed the hackers to approve token transfers silently through a batch authorization process.

Xian furthered that the victim unknowingly triggered an “execute” command within MetaMask, which processed the malicious batch data in the background. The result was a silent but effective token drain.

“The phishing gang uses this mechanism to complete batch authorization operations on tokens related to the victim’s address,” Xian said.

Inferno Drainer Steals $150,000 in Crypto Phishing Attack image 0Crypto Phishing Attack. Source: Scam Sniffer

The security expert emphasized that this incident marks a shift in scam tactics.

According to him, it shows that attackers are no longer relying solely on old tricks as they’re actively integrating new Ethereum updates into their operations to stay ahead.

“As we predicted, the phishing gangs have caught up… Everyone should be vigilant, be careful that the assets in your wallet will be taken away,” Xian said.

Considering this, he urged users to review token authorizations regularly and check whether their wallet addresses have been delegated to phishing accounts via EIP-7702.

Meanwhile, this case is part of a broader trend in the crypto industry. Last month, malicious actors stole over $5 million from 7,565 individuals through phishing attacks.

Due to this, security experts have emphasized that crypto users must remain proactive to stay safe from these attack vectors.

Scam Sniffer advised industry players to verify websites before logging in or approving any transactions. They also urge community members to audit their token permissions routinely and avoid clicking on unverified links.

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Locked for new tokens.
APR up to 10%. Always on, always get airdrop.
Lock now!