Site navigation

How Much Was Lost to Crypto Phishing Scams in 2024?

Tom Quinn

,

wallet drainer attacks
Crypto phishing scams saw soaring losses in 2024, with increasingly sophisticated attacks, according to the latest report from Scam Sniffer.

Victims of cryptocurrency phishing attacks lost almost $500 million (£401 million) last year, according to new research from web3 anti-scam platform Scam Sniffer.

The security provider’s latest annual Crypto Phishing Report for 2024 saw a 67% increase in the number of ‘wallet drainer’ malware attacks, which the firm said are used on phishing websites to steal crypto assets by getting users to consent to malicious transactions.

These phishing attacks are designed to lure victims into making transactions that allow cyber-criminals to quickly siphon crypto assets, and make it difficult for the fraudulent transactions to be followed by law enforcement. 

Scam Sniffer said that among the most common ways phishing websites acquire traffic for these attacks is through hacking, including of Discord and Twitter accounts, organic traffic manipulation, through NFT or token airdrops and expired Discord links being compromised, and even paid traffic, including via Google Search ads, as well as Twitter and Telegram ads. 

The report, which focuses on Ethereum Virtual Machine (EVM) compatible chains, found that although the number of victims increased by only 3.7%, reaching 332,000 addresses, the loss per attack increased significantly, with the largest single theft amounting to $55.48m (£44.5m).

According to the research, 2024 saw a 56% increase in the number of large loss cases, with thirty high value thefts over $1 million (£801k) being recorded. 

The first half last year saw frequent, smaller-scale incidents, followed by a peak period between July and September, with thefts of $55.48m (£44.5m) in August, and $32.51m (£26m) in September, accounting for 52% of the year’s total large-scale losses.     

Looking across the year, Scam Sniffer said that the first quarter of 2024 saw the heaviest overall losses, amounting to $187.2 million (£150 million) coming from 175,000 victims, with March recording the highest losses in the year, with $75.2 million (£60.3 million) lost to crypto phishing.

The report also highlights the evolving threat landscape as new security bypass methods are continuously being developed by threat actors.


Recommended reading


Among those observed last year were the use of legitimate contracts with added Cloudflare or fake CAPTCHA pages to prevent detection, attempts to bypass wallet blacklists through XSS vulnerabilities, and the exploitation of wallet normalisation processes to initiate signatures that wallets can process but security detection layers might miss.   

“As crucial entry points to the Web3 world, wallets play a key role in protecting user assets,” Scam Sniffer said.

“By establishing comprehensive security strategies, continuously upgrading protection capabilities, and actively adopting industry-leading security solutions, wallets can provide users with a more secure and reliable service environment.

“This is not just a responsibility but also a necessary condition for maintaining advantages in a highly competitive market.”

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data