Crypto Phishing Campaigns in 2026: Inside the Drainer Economy
Phishing, not code exploits, drove crypto's biggest 2026 losses, from a $284 million fake support scam to state-sponsored fake job offers. Here is how the schemes work and how to stop them.
When Thieves Stopped Breaking Code and Started Breaking Trust
Crypto lost more money to smart contract exploits than to phishing for most of the last decade. That balance has flipped. Data from CertiK’s Hack3D security unit, the same research group behind the auditor profiled here on HOGE Wire, shows total crypto losses reached roughly $1.3 billion through mid-2026, and while the raw number of phishing incidents actually fell in one recent comparison, from 132 down to 63, the money stolen barely moved. Just four social engineering operations accounted for about $310 million, or 85 percent of all phishing losses, including a single January victim who lost $284.8 million in one sitting, a case examined in detail below. Researchers describe the pattern as attacks that are fewer but far more surgical, and the numbers back that framing up: read the full breakdown here.
Chainalysis, the blockchain analytics firm regulators and prosecutors rely on to trace stolen funds, put total 2025 scam and fraud losses at roughly $17 billion in its 2026 Crypto Crime Report, with impersonation scams growing 1,400 percent year over year and the average scam payment rising 253 percent to $2,764. Coverage of the report also captured how personal the impersonation problem has become for people who work in the industry. “Across the crypto industry, impersonation scams are increasing and becoming more sophisticated,” said Lior Aizik, co-founder and chief operating officer of the crypto exchange XBO. “Scammers have impersonated me by name, using fake profiles to contact people in the industry and request money while pretending to represent XBO.”
Attackers are not writing better Solidity. They are writing more convincing support tickets, more believable job offers, and increasingly, AI-generated everything. This piece maps the phishing campaigns actually draining crypto wallets in 2026: how approval phishing and wallet drainers work, why address poisoning keeps succeeding despite viral warnings, how a nation state uses fake job interviews as an attack vector, and what regulators and platforms are doing about it. It closes with a checklist, because in phishing, unlike a reentrancy bug, the fix is mostly behavioral rather than technical.
| Vector | How It Works | Notable Case | Reported Loss |
|---|---|---|---|
| Seed phrase or fake support impersonation | A fake “support agent” or hardware wallet notice talks the victim into typing or reading out a recovery phrase | Trezor impersonation heist, January 2026 | about $284.8 million from one victim |
| Address poisoning | A look-alike address “dusts” a wallet so the victim later copies it from transaction history | USDT transfer, December 2025 | about $50 million |
| Approval and signature phishing | Victim signs a token approval or Permit message that hands spending rights to a drainer contract | Signature drains tracked by Scam Sniffer, January 2026 | $6.27 million from 4,741 victims |
| EIP-7702 delegation phishing | Victim signs a wallet delegation message that hands control of the account to a sweeper contract | Post-Pectra “CrimeEnjoyor” sweeper contracts | 48 percent of tracked delegations flagged as crime linked |
| Malvertising | Paid search and social ads impersonate wallets and DeFi front ends | Fake Uniswap Google Ads campaign, May 2026 | over $400,000 |
| State-sponsored recruiting lures | Fake recruiters and take-home coding “tests” deliver malware to developers | DPRK-linked hiring campaigns, ongoing | over $2 billion a year across all DPRK vectors combined |
| Romance and investment scams | Long-con relationship building leads victims to fake trading platforms | “Pig butchering” pattern, FBI IC3 2025 data | over $7.2 billion reported in the United States |
Inside the $284 Million Heist That Defined January
The single largest phishing loss of 2026 so far did not involve a compromised smart contract, a bridge, or an oracle. On January 16, an attacker impersonating Trezor customer support convinced one victim to hand over a hardware wallet recovery seed. The attacker moved 1,459 BTC and roughly 2.05 million LTC, worth $284,785,689 at the time, then converted the proceeds into Monero within hours, a laundering choice that briefly pushed up the privacy coin’s price and underlined why regulators keep flagging privacy coins as a money laundering chokepoint.
The victim’s identity and the exact script the attacker used were never made public, which is itself telling. Unlike a DeFi exploit, where the transaction sequence is on chain for anyone to reconstruct, a seed phrase phishing attack usually leaves no public trace beyond the resulting transfer. Researchers know the outcome, not the conversation that produced it.
The case is a useful anchor for this entire piece because it shows the pattern behind nearly every large crypto loss category in 2026: not broken contract logic, but a person talked into doing something irreversible. That is also why hardware wallet brands like Trezor and Ledger have become impersonation targets in their own right, a trend covered in more detail further down, including scammers who have moved into physical mail.
How Approval Phishing Actually Works
Most 2026 phishing losses do not involve a victim reading out 24 words. They involve a victim clicking “Connect Wallet,” then signing something they did not fully understand. This is approval phishing, and the U.S. Secret Service considered it significant enough to build an entire international operation around disrupting it (more on that further down). The agency defines it plainly as a scam designed to trick victims into unknowingly granting full access to their cryptocurrency wallets.
Three signature types get abused most often. ERC-20 approve calls let a spender contract move up to a specified amount of a token on the holder’s behalf, a mechanism originally built so a decentralized exchange router can execute a swap. EIP-2612 Permit messages and Uniswap’s Permit2 authorize spending through an off-chain signature rather than an on-chain transaction, which is cheaper to abuse at scale because the attacker, not the victim, pays the gas to execute the drain. And EIP-7702 delegation, live on Ethereum since the Pectra upgrade activated on mainnet in May 2025, lets a regular wallet temporarily hand its execution rights to a smart contract.
That last mechanism turned into an attack vector almost immediately. Wintermute’s research team found that of roughly 1.58 million EIP-7702 delegations activated in the weeks after launch, 48 percent, or 768,275, were tagged as crime related, and more than 97 percent of the malicious ones pointed to the exact same “sweeper” bytecode, a contract researchers nicknamed CrimeEnjoyor, built to automatically drain any funds that land in a compromised wallet. Wintermute’s analysis reads like a warning label for a feature that shipped for convenience, not malice.
None of these mechanisms are bugs. They are legitimate features that make wallets easier to use, which is exactly why drainer kits target them instead of hunting for a new smart contract vulnerability. A phishing site cloning a familiar mint page or claims page only needs the victim to sign one message. There is no bridge to exploit and no audit to bypass, only a signature prompt that most wallets still render as a wall of unreadable hexadecimal data.
The Drainer-as-a-Service Economy
The infrastructure behind most approval phishing is rented, not built from scratch. “Drainer-as-a-service” kits package the phishing site template, the malicious signature request, and the fund-forwarding logic into a product anyone can license. The kit operator typically keeps the largest cut of whatever gets stolen, and pays the remainder to the affiliate who built or promoted that specific phishing site.
Names like Inferno Drainer and Angel Drainer dominated this market in 2023 and 2024 before law enforcement pressure and internal disputes pushed operators to rebrand or fragment into smaller crews. New kits keep surfacing to fill the gap. Security researchers monitoring underground forums have flagged newer entrants advertising affiliate programs throughout 2026, with operators claiming their toolkits can bypass wallet warnings from MetaMask, Phantom, and Scam Sniffer itself; those profit claims come from the criminals running the kits and should be read as marketing rather than verified fact.
The aggregate numbers independent researchers can verify are still large on their own. Scam Sniffer, a Web3 anti-scam firm whose data regularly turns up in law enforcement and press reporting, estimated wallet drainers stole close to $494 million in 2024 alone from more than 332,000 addresses, and more than $800 million since 2023. Its more recent tracking shows the tactic shifting rather than disappearing: January 2026 signature phishing losses jumped 207 percent month over month to $6.27 million even as the number of distinct victims fell 11 percent to 4,741, because just two victims accounted for 65 percent of that month’s losses. Researchers have started calling this shift “whale hunting,” fewer targets, much bigger checks.
| Kit or Category | Model | Scale as Reported | Status |
|---|---|---|---|
| Inferno Drainer and Angel Drainer | Affiliate commission kits rented to phishing site operators | Widely cited as responsible for hundreds of millions of dollars in losses across 2023 and 2024 | Rebranded or fragmented under law enforcement pressure |
| Newer entrants surfacing in 2026 | Same affiliate model, advertised on underground forums | Operators claim to bypass wallet warnings from MetaMask, Phantom, and Scam Sniffer | Profit claims are self-reported by threat actors, not independently verified |
| All tracked wallet drainers, aggregate | Various kits and affiliates | About $494 million stolen in 2024 alone; over $800 million since 2023 | Ongoing, per Scam Sniffer |
| Signature and approval phishing subset | Permit and token approval abuse specifically | $6.27 million from 4,741 victims in January 2026 alone, up 207 percent month over month | Shifting toward fewer, wealthier targets |
Address Poisoning: When Your Own Transaction History Lies
Address poisoning does not need a signature at all. It exploits a much older habit: copying an address from transaction history instead of typing or scanning it fresh. An attacker studies a target’s on-chain activity, generates a new address sharing the same first few and last few characters as one the target regularly pays (most wallet interfaces truncate the middle), and sends a tiny or zero-value transaction from that look-alike address so it lands in the victim’s history. Sooner or later, the victim copies the wrong address for a real payment.
Academic researchers at Carnegie Mellon University’s CyLab, presenting at the 34th USENIX Security Symposium, analyzed more than two years of Ethereum and BNB Smart Chain transaction data and found roughly 270 million attack attempts targeting 17 million potential victims between July 2022 and June 2024, with confirmed losses of at least $83.8 million in that window alone. Chainalysis has documented the extreme tail of the same pattern: in one campaign it dissected, a single victim lost nearly $68 million in wrapped bitcoin after an operation quietly built 82,031 look-alike addresses, about 1 percent of all new Ethereum addresses created during the campaign’s active period.
The most expensive recent case happened on December 20, 2025, when a trader sent a routine $50 test transaction to confirm a destination address, unaware that an attacker had already generated a poisoned address matching its first and last characters and dusted the trader’s wallet history with it. The trader then copied what looked like the verified address from that history and sent $49,999,950 in USDT to the attacker, who swapped it for DAI, converted the proceeds into roughly 16,680 ETH, and moved everything into Tornado Cash. The victim publicly offered a $1 million bounty for the return of 98 percent of the funds within 48 hours; there is no confirmed report that the money came back. That the largest recent case was denominated in USDT is not a coincidence: stablecoins move at the speed of whichever blockchain rail they settle on, and the rulebook for those dollar rails is still catching up to the volume already moving through them.
The theft prompted a public response from Binance co-founder Changpeng Zhao, who argued the entire attack class is preventable at the wallet level. “All wallets should simply check if a receiving address is a poison address, and block the user. This is a blockchain query,” Zhao wrote, adding that wallets “should not even display these spam transactions anywhere” when the transferred value is negligible. “Our industry should be able to completely eradicate this type of poison attacks, and protect our users.”
Some wallets and block explorers have since added poisoned-address warnings, but adoption is uneven, and the underlying habit, trusting transaction history as a source of truth, is hard to fully engineer around.
Malvertising and Malicious Extensions: Crypto’s New Delivery Rails
Search ads and browser extensions have become two of the most reliable ways to put a phishing site in front of someone who is already looking for a legitimate wallet or DeFi front end. Attackers buy sponsored placements on Google and X that impersonate Coinbase Wallet, Uniswap, PancakeSwap, Morpho, Hyperliquid, CoW Swap, and hardware wallet brands, then route the ad’s landing page through trusted domains like sites.google.com or docs.google.com before redirecting to the actual clone, a layered setup built specifically to pass automated ad review. A fake Uniswap campaign on Google Ads alone netted attackers more than $400,000 in May 2026, part of a broader pattern of weekly fake-ad rotations that researchers say peaked in March 2026.
Browser extensions add a second delivery channel, one that does not even require the victim to visit a fake site. In February 2026, a previously legitimate Chrome extension called QuickLens changed ownership and pushed a malicious update that turned it into a credential and wallet-data harvester, targeting MetaMask and Phantom activity data and attempting to extract seed phrases. That pattern, buying or compromising an extension with an existing user base rather than trying to get a new malicious one approved, keeps recurring because Chrome Web Store review catches obviously malicious new submissions far more often than it catches a trusted extension going bad after the fact. Once installed, modern info-stealer malware can harvest saved browser passwords, session cookies, and wallet extension data for MetaMask, Phantom, Trust Wallet, and Coinbase Wallet within thirty to sixty seconds of execution.
The defense here is almost entirely habit rather than tooling: never reach a wallet’s download page through a search ad, a sponsored social post, or a link in a message, and treat any extension update as worth a second look rather than an automatic install.
Analog Phishing: The Ledger Letters in Your Mailbox
Not every phishing campaign lives online. Ledger’s own status page for active phishing campaigns lists physical letters as an ongoing threat: scammers mail official-looking notices, complete with Ledger branding and a reference number, that direct recipients to scan a QR code or visit a website and ultimately enter their 24-word recovery phrase, sometimes under the pretext of a new “vault address” requiring a transfer, or an urgent security update. Some letters that have circulated cite deadlines running from October 2025 into early 2026 and invoke quantum computing risk to manufacture urgency, and the localized, personal nature of the mailings has fueled suspicion that attackers had access to customer shipping data, possibly connected to a breach at Global-e, Ledger’s e-commerce fulfillment partner, disclosed in January 2026.
Ledger’s guidance is unambiguous on the point that matters most: the company states plainly that it does not send emails asking customers to update firmware, enable two-factor authentication, or take similar account actions, and that there is no legitimate reason to type a recovery phrase into a computer, website, or form, ever. The same status page flags a phone-based variant too, where callers impersonate Ledger support or CoinCover (Ledger Recover’s partner) and claim to be resolving an unauthorized recovery attempt from a foreign country, working toward the same goal by a different route: getting the victim to read out or type in the seed.
The lesson generalizes past Ledger. Any hardware wallet or exchange brand can be impersonated by mail, phone, or email, because none of those channels are authenticated the way a signed software update is. If a message about a wallet arrives through a channel the owner did not initiate, the recovery phrase does not leave the device, full stop.
North Korea’s Fake Recruiters: Phishing as State Policy
Some of the most patient phishing campaigns in crypto are not run by opportunists but by a government. North Korea’s Lazarus Group and its sub-clusters have spent years posing as recruiters, hiring managers, and even entire companies to reach developers who hold deploy keys, treasury multisig access, or production credentials. Fireblocks documented a campaign that closely mirrored its own hiring process, with fake recruiters conducting real-seeming video interviews and sending take-home coding assignments through GitHub; running the assignment’s setup script installed malware capable of exposing wallets, keys, and production systems, with targets often selected based on LinkedIn profiles showing privileged access. Separately, investigators traced three shell companies, BlockNovas, Angeloper Agency, and SoftGlide, registered as ordinary US businesses specifically to run fake job postings and distribute malware through the application process, frequently via a staged “error message” that told the applicant to copy, paste, and run a command to fix it.
Chainalysis attributes roughly $2.02 billion in 2025 crypto theft to DPRK-linked actors overall, up 51 percent year over year, a figure that spans this recruiting vector alongside more direct infrastructure attacks, including some of the multisig and bridge compromises covered in depth elsewhere on HOGE Wire.
Taylor Monahan, the MetaMask security researcher who has tracked Lazarus-linked wallet activity for years, has described the operation’s range as its defining feature rather than any single technical trick. “It’s the diversity and dedication of these attacks that’s mind-boggling,” Monahan said, adding that once the group gets initial access to a target’s device, the specific wallet or product in use stops mattering much: “There’s not a single product out there that will perfectly save you… they’re going to come up with a very customized plan that they’ve tailored to you.” She has also pointed to voice phishing as the next growth area, expecting AI to make convincing “vishing” calls far easier to run at scale, a prediction already playing out in the section below.
Pig Butchering: Romance Scripts Wearing a Trading Terminal
The most financially destructive phishing pattern in crypto rarely looks like phishing at first. Romance-investment scams, widely known as “pig butchering” for the way scammers patiently build trust before soliciting ever-larger transfers, start on dating apps or social media, sometimes even a wrong-number text message that turns into a friendly conversation. Once trust is established, the scammer introduces a trading opportunity, usually a slick but entirely fake exchange or investment platform, and walks the victim through depositing crypto that shows fabricated gains on screen. Small withdrawals work at first, which is precisely what keeps larger deposits coming.
The FBI’s Internet Crime Complaint Center logged 1,008,597 total complaints in 2025 with $20.877 billion in reported losses, a 26 percent increase over 2024. Cryptocurrency-related complaints made up the largest slice by dollar value: 181,565 complaints totaling more than $11 billion. Within that, investment fraud, the category the FBI says crypto now dominates at 72 percent of the total, accounted for $8.65 billion, roughly double the prior year, and the romance-investment hybrid pattern specifically drove reported losses up 24 percent to more than $7.2 billion.
Regulators see the same pattern from a different angle. The SEC’s Office of Investor Education and Advocacy has repeatedly warned that fraudsters build trust through group chats and social platforms before soliciting crypto investments, sometimes impersonating financial professionals or even SEC officials to lend the pitch legitimacy. In one case the agency highlighted, participants impersonated financial industry professionals inside WhatsApp groups to defraud retail investors of more than $14 million through purported crypto trading platforms and investment clubs.
Because the entire scheme depends on a relationship rather than a single clickable link, it survives nearly every technical defense built for approval phishing or malicious extensions. The only reliable circuit breaker is behavioral: a genuine relationship does not require moving crypto to a platform nobody else has heard of, and any platform that only allows withdrawals after another deposit is not a platform at all.
AI Is Rewriting the Phishing Playbook
Generative AI has removed the two biggest constraints on phishing at scale: skill and cost. Chainalysis found AI-enabled scams were 4.5 times more profitable than traditional fraud in 2025, and one widely cited analysis of reported phishing activity found the AI-assisted share of attacks jumped from about 4 percent in November 2025 to 56 percent in December, a fourteen-fold increase in a single month. The FBI’s 2025 report logged more than 22,000 AI-related fraud complaints with losses exceeding $893 million.
Voice and video cloning are the sharpest edge of this shift. Consumer research from Hiya found roughly one in four Americans received a deepfake voice call in the past year, and deepfake-enabled vishing attempts surged more than 1,600 percent in early 2025 compared with the prior quarter. The starkest known case remains a Hong Kong finance employee who authorized transfers totaling roughly $25.6 million after a video conference in which every other participant, including an apparent CFO, was an AI-generated deepfake with synchronized facial movement and a cloned voice; the employee had initially suspected phishing, but the live video call overcame his doubts. Crypto has its own long-running version of the same tactic: deepfaked livestreams of recognizable industry figures promising to double any crypto sent to a displayed address, a scam format that has periodically hijacked verified YouTube channels and pulled tens of thousands of live viewers at a time.
The trend points toward autonomous systems next, not just better fakes. As wallets and DeFi protocols increasingly hand routine transactions to autonomous AI agents acting on a user’s behalf, the attack surface shifts again, from tricking a human into signing something, to tricking or manipulating the agent itself into approving it. Security researchers already treat prompt injection against these agents as a phishing variant in its own right, since the actual goal, an unauthorized transfer approved by whoever is holding the keys, has not changed at all.
Regulators and Platforms Fight Back
Law enforcement’s response to approval phishing specifically has started to look coordinated rather than reactive. In March and April 2026, the US Secret Service ran Operation Atlantic alongside the UK’s National Crime Agency and Canadian authorities, targeting approval phishing directly. The operation tracked more than 20,000 victim wallet addresses across more than 30 countries in real time, disrupted more than 120 scam domains, froze $12 million in stolen crypto for potential return to victims, and identified a further $33 million in funds linked to related investment fraud for continued investigation, out of more than $45 million in disrupted losses overall.
Google has taken a similar fight to civil court. On June 12, 2026, the company filed a civil RICO and Lanham Act lawsuit in Manhattan federal court against 25 unnamed defendants it calls the “Outsider Enterprise,” accusing them of running a phishing-as-a-service platform, sold through a Telegram bot for as little as $88 a week, that gave subscribers more than 290 ready-made templates impersonating banks, toll agencies, and delivery services, complete with tutorials for prompting AI coding tools to generate the underlying scam sites. The FBI ties the platform to an estimated $1.9 billion in losses and 3.87 million stolen payment cards since mid-2023, and separately seized the group’s core domains, a storefront, and roughly $100,000 in USDT as part of a parallel action the bureau dubbed Operation Ghost Hook. It is not a crypto-native case; most of the underlying scam messages impersonated banks and toll agencies. But the fact that seized proceeds were denominated in a stablecoin, and that a phishing kit business modeled its pricing and support tiers on legitimate software subscriptions, says a great deal about how industrialized the supply side of phishing has become.
The SEC keeps its own role narrower but consistent: its Office of Investor Education and Advocacy publishes recurring alerts on crypto-specific lures and on fraudsters impersonating the agency itself, while its enforcement division continues bringing cases against the platforms and organizers running crypto-linked investment fraud rather than pursuing individual phishing operators directly. That division of labor leaves the FBI, the Secret Service, and international partners as the primary responders to phishing as a crime, while the SEC targets the securities-law violations that sit downstream of it.
A Practical Defense Checklist for 2026
Most of the defenses against 2026’s phishing campaigns are not products. They are habits, the same handful of checks applied consistently no matter how convincing the specific lure looks. Solo stakers and validator operators face an especially acute version of this problem, since a blind-signed delegation or a compromised withdrawal credential can be just as final as a drained hot wallet, which makes the discipline below non-negotiable for anyone holding keys to real value, not only active traders.
- Bookmark official wallet, exchange, and hardware wallet URLs; never reach them through a search ad, sponsored post, or link in a message.
- Treat any request to view, type, or photograph a recovery phrase as an automatic scam, no matter who appears to be asking.
- Read what a hardware wallet displays before approving anything; if the device cannot show the real function and amount in plain language, do not sign it.
- Send a small test transaction before moving a large balance, and copy destination addresses from a saved contact rather than transaction history.
- Periodically review and revoke stale token approvals using a wallet’s built-in tool or a block explorer’s approval manager.
- Run unfamiliar code from a job application, mint page, or “verification” step in an isolated environment, never on the device holding real keys.
| Red Flag | Why It Matters | What To Do |
|---|---|---|
| Manufactured urgency (“act within 24 hours or lose access”) | Time pressure is designed to short-circuit verification | Pause; verify independently through an official channel before acting |
| A request to type, read aloud, or photograph a seed phrase | No legitimate wallet, exchange, or support agent ever needs it | End the contact immediately and report it |
| A signature request you cannot read in plain language | Blind signing hides the real function being authorized | Use a device with clear signing, or decode the calldata before signing |
| A “test” or take-home coding task from an unsolicited recruiter | A documented lure used by state-sponsored groups targeting developers | Run unfamiliar code only in an isolated sandbox or virtual machine |
| A sponsored ad or DM promoting a wallet or app download | Ad slots and verified accounts are routinely bought or hijacked for this | Navigate only by typing the official URL or using a saved bookmark |
Where Phishing Goes Next
Two trends look set to define the next year of crypto phishing. The first is the whale hunting shift already visible in Scam Sniffer’s data: as wallet security tooling gets better at flagging obviously malicious approvals, attackers are investing more effort in fewer, larger targets rather than spraying thousands of small wallets, which means headline loss figures may stay large even as victim counts keep falling. The second is the AI arms race described above, where the cost of producing a convincing lure, whether a cloned voice, a fake recruiter persona, or a flawless clone of a DeFi front end, keeps falling toward zero.
Neither trend has an easy technical fix, because both exploit the same gap: wallets and interfaces were built to make signing transactions easy, and phishing is what happens when that ease gets turned against the person holding the keys. The clearest defense in either direction is still the oldest one in security: verify out of band, through a channel the other party cannot control, before anything irreversible happens.
Frequently Asked Questions
What is approval phishing in crypto?
Approval phishing tricks a wallet holder into signing a transaction that grants a malicious smart contract ongoing permission to move tokens, rather than stealing funds in that moment. Using mechanisms like the ERC-20 approve function or off-chain Permit signatures, the wallet interface often shows a vague prompt such as “claim” or “verify” instead of the real instruction being authorized. Once signed, the attacker’s contract can drain the approved balance immediately or wait until more funds arrive. The U.S. Secret Service considered the pattern significant enough to build a dedicated international operation, Operation Atlantic, around disrupting it in 2026.
How do crypto wallet drainers work?
Wallet drainers are prebuilt JavaScript kits, often rented out as “drainer-as-a-service,” that phishing site operators plug into cloned fronts for wallets, NFT mints, or DeFi protocols. When a victim connects a wallet and signs what looks like a routine transaction, the kit requests a token approval, a Permit signature, or an EIP-7702 delegation that hands control to the drainer. The kit operator typically keeps the largest share of anything stolen, sometimes as much as 80 percent, and pays the rest to whoever built or promoted the specific phishing site.
What is address poisoning and how can I avoid it?
Address poisoning happens when an attacker generates a wallet address sharing the same first and last characters as one you transact with regularly, then sends a tiny or zero-value transaction from it so it appears in your transaction history. Because most wallet interfaces truncate addresses, victims later copy the look-alike address instead of the real one. The best defenses are copying destination addresses from a saved contact rather than transaction history, checking the full address rather than just the ends, and sending a small test transaction before moving a large balance.
Can a hardware wallet like Ledger or Trezor stop phishing attacks?
A hardware wallet stops attackers from remotely extracting your private keys, but it cannot stop you from approving a malicious transaction if you cannot read what you are actually signing, a problem known as blind signing. Devices that support clear signing can display the real function and parameters of a transaction on their own screen, which helps considerably, but no hardware wallet can override someone who has been socially engineered into typing a 24-word recovery phrase into a fake “verification” website or reading it out to a fake support agent, which is how several of the largest losses in 2025 and 2026 actually happened.
What should I do if I signed a malicious approval or transaction?
Move any remaining funds in that wallet to a newly generated wallet immediately, since the exposure will not resolve on its own. Use a token approval checker, available on most block explorers and several dedicated tools, to review and revoke approvals granted to unfamiliar contracts, keeping in mind revocation only stops future spending and does not recover funds already taken. Report the phishing site or contract address to your wallet provider so it can be blacklisted for other users, and if the loss is significant, file a report with the FBI’s Internet Crime Complaint Center or your national equivalent, since coordinated law enforcement action has successfully frozen and returned funds in some 2026 cases.
Reported by the HOGE Wire security desk.