Ethereum hacked to steal millions from users across the world

ethereum on a chipset
(Image credit: Pexels)

Hackers have been observed abusing a feature in the Ethereum blockchain to trick victims into sending money. 

In the last six months, the criminals were able to trick almost 100,000 people into giving away a total of $60 million, according to a new report from Scam Sniffer. 

As per the report, the hackers used a function called Create2, an opcode that allows users to predict the address of a contract before it is deployed on the Ethereum network. In other words, hackers can create temporary addresses for each individual transaction - addresses that greatly resemble the ones where the victims intended to send the funds. The scheme is dubbed “address poisoning”.


Reader Offer: $50 Amazon gift card with demo

Reader Offer: $50 Amazon gift card with demo
Perimeter 81's Malware Protection intercepts threats at the delivery stage to prevent known malware, polymorphic attacks, zero-day exploits, and more. Let your people use the web freely without risking data and network security.

Preferred partner (What does this mean?

Bypassing security

Most users, before sending any funds, do two things: 1) they double-check the recipient’s address to make sure they’re sending the money to the right place; 2) they send a small transaction first to make sure everything works, before sending the remaining funds. However, as the addresses are a long string of seemingly random characters, most users just cross-check the first and last few characters, instead of comparing the entire strings. 

By creating an address that differs in just a few characters, the attackers can trick people into thinking the address is valid, before sending the funds. That, however, still leaves the second failsafe - the test transaction. Criminals are working around this by forwarding the test transaction to the actual address. 

The lookalike addresses don’t belong directly to a wallet controlled by the attackers, but are rather a smart contract that then transfers the funds to the final destination. The researchers said they observed multiple cases of fraud leveraging Create2, with one victim losing up to $1.6 million.

Users are advised to thoroughly check the entire address before sending the funds, and not just first and last characters.

Via BleepingComputer

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Ethereum
Hackers steal over $1bn in one of the biggest crypto thefts ever
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
Smartphone with new logo X twitter app background. Application twitter old blue bird change X black and white new.
Phishing campaign targets prominent X users, accounts at risk
An abstract image of digital security.
Hundreds of GitHub repositories hijacked to trick users into downloading malware
Android phone malware
Screen reading malware found in iOS app stores for first time - and it might steal your cryptocurrency
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Microsoft 365 accounts are under attack from new malware spoofing popular work apps
Latest in Security
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
Google Chrome
Google Chrome security flaw could have let hackers spy on all your online habits
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Latest in News
A young woman is working on a laptop in a relaxed office space.
I’ll admit, Microsoft’s new Windows 11 update surprised me with its usefulness, providing accessibility fixes, a gamepad keyboard layout, and PC spec cards
inZOI promotional material.
inZOI has become the most wishlisted game on Steam, but I wouldn't get too caught up in the hype
Xbox Series X and Xbox wireless controller set to a green background
Xbox Insiders are currently testing a new Game Hub feature that looks useful, but I've got mixed feelings about it
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Nespresso Vertuo Pop machine in Candy Pink with coffee drinks and capsules
My favorite Nespresso coffee maker just got a fresh new makeover, and now I love it even more
Microsoft Surface Laptop and Surface Pro devices on a table.
Hate Windows 11’s search? Microsoft is fixing it with AI, and that almost makes me want to buy a Copilot+ PC