Uniswap V3 Liquidity Pool Affected by Phishing Attack with 7,500 Ether Theft

The hackers stole around 7,500 Ether, valued at over $8.1 million (approximately Rs 64.45 crore), from decentralized exchange Uniswap through a phishing attack. Spotted by several users, including Binance’s Dangerous Intelligence Department, the hacker managed to impersonate Uniswap’s website and trick a liquidity pool provider into signing malicious transactions. On its third iteration, Uniswap’s liquidity position is represented in the form of a non-fungible token (NFT), which enables users to use it as collateral to receive paid-up loans in stablecoins and blue-chip assets. makes.

Binance CEO Changpeng Zhao aka CZ initially tweeted that the platform’s threat intelligence team initially found a potential exploit on Uniswap v3 on the ETH blockchain.

In his tweet, Zhao said that the hackers have stolen 4,295 ETH so far, and that they are “laundered through Tornado Cash.” According to crypto tracking and compliance platform Mysttrack, the number of stolen ETH is currently at $7,500, which is worth around $8.1 million (approximately Rs 64.45 crore).

The Binance CEO later had to correct himself after communicating with the Uniswap team that this was not an exploit on Uniswap, but a phishing attack.

“A phishing attack resulting in some liquidity pool NFTs being taken from individuals who approved malicious transactions,” uniswap Founder Hayden Adams later confirmed in a follow-up tweet. “Totally different from protocol. A good reminder to protect yourself from phishing and not to click on malicious links.”

Before Zhao alerted users via his tweet, MetaMask security analyst Harry Denly reported that a malicious token was sent to 73,399 addresses targeting his assets.

event data blockchain This was changed by scammers to make it appear that the Uniswap platform was airdropping tokens to liquidity providers.

When users linked their wallets to the contract’s website, which resembles Uniswap, their wallets were stripped of native tokens (ETH), ERC20 tokens, and NFTs (ie Uniswap LP status).