Security Breach Alert: $4.20 Million Drained in Ethereum Scam Exploiting CREATE2
A recent major phishing attack on the Ethereum blockchain exploited the CREATE2 opcode, leading to a substantial loss of $4.20 million in aEthWETH and aEthUNI. Scam Sniffer's 2023 report highlights the growing threat of crypto phishing scams, with attackers leveraging sophisticated methods, including the manipulation of contract addresses through the CREATE2 exploit.
The victim, identified by the wallet address 0x1749, fell prey to the scam, unknowingly signing multiple ERC20 Permit signatures. These signatures granted unauthorized access to scammers operating under addresses 0x00003 and 0xf6. The incident was promptly reported by Scam Sniffer on January 22, underscoring the urgency of addressing vulnerabilities and enhancing security measures in the crypto space.











