Home » Uniswap users phished – $8 million in cryptocurrencies gone

Uniswap users phished – $8 million in cryptocurrencies gone

by Tim

An elaborate phishing attack has siphoned $8 million in cryptocurrency from Uniswap users. They thought they were getting an airdrop. What happened?

Phishing: Uniswap users take the bait

The attack was described by Harry Denley, an analyst with Metamask, who explains how the phishing took place, and how Uniswap users were fooled. A “malicious token” was allegedly sent to liquidity providers (LPs), with the promise of an airdrop:

Several techniques were used to make this fake airdrop appear legitimate. First, the attackers managed to get the upload indexed on block browsers such as Etherscan so that it appeared to come from a legitimate contract:

Transactions appearing to come from

The name of this malicious token linked to a /uniswaplp.com domain name, which itself mimicked the appearance of regular Uniswap communications. The funds were then stolen from this secondary site. In total, more than $8 million in ETH was allegedly sent to the Tornado Cash blender to be laundered.

Changpeng Zhao sounds the alarm

Many people have reacted to this massive attack, including Binance Changpeng Zhao. A little too quickly? The CEO of Binance announced that his teams had “detected a potential attack on Uniswap V3, on the ETH blockchain”. Then he corrected himself, saying that it was only a phishing attack – but a very effective one:

The lesson of this case is that one must always be extremely careful, even when the site seems legitimate. It cannot be repeated enough: clicking on unknown links is not a good idea, and using “cold” wallets is the best way to protect your cryptocurrencies.

Related Posts

Leave a Comment