Victims of cryptocurrency phishing attacks lost almost $500 million (£401 million) last year, according to new research from web3 anti-scam platform Scam Sniffer.
The security provider’s latest annual Crypto Phishing Report for 2024 saw a 67% increase in the number of ‘wallet drainer’ malware attacks, which the firm said are used on phishing websites to steal crypto assets by getting users to consent to malicious transactions.
These phishing attacks are designed to lure victims into making transactions that allow cyber-criminals to quickly siphon crypto assets, and make it difficult for the fraudulent transactions to be followed by law enforcement.
Scam Sniffer said that among the most common ways phishing websites acquire traffic for these attacks is through hacking, including of Discord and Twitter accounts, organic traffic manipulation, through NFT or token airdrops and expired Discord links being compromised, and even paid traffic, including via Google Search ads, as well as Twitter and Telegram ads.
The report, which focuses on Ethereum Virtual Machine (EVM) compatible chains, found that although the number of victims increased by only 3.7%, reaching 332,000 addresses, the loss per attack increased significantly, with the largest single theft amounting to $55.48m (£44.5m).
According to the research, 2024 saw a 56% increase in the number of large loss cases, with thirty high value thefts over $1 million (£801k) being recorded.
The first half last year saw frequent, smaller-scale incidents, followed by a peak period between July and September, with thefts of $55.48m (£44.5m) in August, and $32.51m (£26m) in September, accounting for 52% of the year’s total large-scale losses.
Looking across the year, Scam Sniffer said that the first quarter of 2024 saw the heaviest overall losses, amounting to $187.2 million (£150 million) coming from 175,000 victims, with March recording the highest losses in the year, with $75.2 million (£60.3 million) lost to crypto phishing.
The report also highlights the evolving threat landscape as new security bypass methods are continuously being developed by threat actors.
Recommended reading
- Ransomware Groups are Adjusting Their Strategies
- Comment | The Rise in QR Code Attacks
- 82% of Phishing Toolkits Use Deepfakes
Among those observed last year were the use of legitimate contracts with added Cloudflare or fake CAPTCHA pages to prevent detection, attempts to bypass wallet blacklists through XSS vulnerabilities, and the exploitation of wallet normalisation processes to initiate signatures that wallets can process but security detection layers might miss.
“As crucial entry points to the Web3 world, wallets play a key role in protecting user assets,” Scam Sniffer said.
“By establishing comprehensive security strategies, continuously upgrading protection capabilities, and actively adopting industry-leading security solutions, wallets can provide users with a more secure and reliable service environment.
“This is not just a responsibility but also a necessary condition for maintaining advantages in a highly competitive market.”





