Phishing Airdrop Tricked Users into Malicious Token Approval Theft
Malicious airdrop claims weaponized token approvals, bypassing private key security to execute authorized asset draining across multiple chains.
Malicious Chrome Extension Skims Solana User Swaps via Hidden Transaction Instruction
Browser extension supply chain risk is high; hidden transaction instructions execute perpetual, low-volume asset skimming from user trades.
Malicious Signature Phishing Drains User Wallets across Web3 Ecosystem
The systemic risk is shifting from smart contract flaws to user-signed malicious approvals, enabling rapid, irreversible wallet-draining attacks.
Mobile Wallets Exposed to Zero-Click Attacks via Operating System Flaws
Zero-click mobile exploits bypass OS security, enabling silent, full-device compromise to exfiltrate wallet seed phrases and private keys.
New Delegation Flaw Exploited by Wallet Drainers to Steal User Assets
EIP-7702-style delegation is weaponized to bypass traditional `approve` checks, granting malicious contracts persistent, batch execution authority over user assets.
AI-Generated Wallet Drainer Infiltrates Open-Source Ecosystem via Malicious NPM Package
An AI-crafted supply chain attack exploited developer trust in the NPM registry to deploy stealthy wallet-draining malware, compromising end-user funds.
Web3 Users Compromised by AI-Aided Phishing Network Stealing Seed Phrases
The FreeDrain campaign leverages AI-generated content and search engine spamdexing to steal mnemonic phrases, bypassing traditional security controls at scale.
Web3 Users Compromised by New Eleven Drainer Phishing-as-a-Service
Eleven Drainer is the latest DaaS threat, leveraging social engineering to trick users into signing malicious token approvals, bypassing smart contract security.
Chromium V8 Zero-Day Flaw Enables Private Key Theft and Wallet Draining
A critical V8 engine zero-day (CVE-2025-10585) permitted remote code execution, exposing user private keys and draining hot wallets.
