Chainalysis and crypto fraud: the explosive growth of phishing approval

Related

Digital Reserve成为2026香港Web3嘉年华二级展位赞助商

Digital Reserve已确认加入2026香港Web3嘉年华,将作为二级展位赞助商为大会提供支持 Digital Reserve 是一家澳洲持牌的加密货币出入金与交易平台,深耕行业多年、穿越多轮牛熊周期,凭借对华人市场的深刻理解、完善的银行通道与高质量服务,持续为专业客户提供稳定、顺畅的数字资产流动解决方案。更多信息: https://digitalreserve.net/ 香港Web3嘉年华是由万向区块链实验室与HashKey Group联合推出的Web3活动品牌,由W3ME承办,自2023年起于每年4月在香港会议展览中心举办,聚焦行业热点话题与政策趋势,是亚洲规模最大、最受关注的Web3行业盛会之一。 2026香港Web3嘉年华将于4月20日-23日在香港会议展览中心盛大举行。自2023年首届举办以来,香港Web3嘉年华已飞速成长为全球最具影响力的加密峰会之一,为全球东西方交流构建了一个高规格、高质量、高纵深的平台。过往三届盛会累计吸引超10万名现场参会者,汇聚超350个前沿项目参加,邀请超1200位演讲嘉宾分享,并衍生超400场周边活动,成功构建了一个以大会为核心、辐射全港的活力生态圈。 目前,香港特别行政区财政司司长陈茂波,香港证监会中介机构部执行董事叶志衡,万向区块链董事长、Hashkey Group董事长兼CEO肖风,香港特别行政区立法会议员(科技创新界)邱达根,Solana Foundation总裁Lily Liu,MatrixPort创始合伙人及首席商务官Cynthia Wu,Animoca...

卓锐证券成为2026香港Web3嘉年华白金赞助商

Hong Kong, 5th March 2026, 卓锐证券已确认加入2026香港Web3嘉年华,将作为白金赞助商为大会提供支持。 卓锐证券(香港)有限公司(中央编号:BRE865)是香港证监会认可持牌法团,持有第1、2、4、5、9类牌照。作为全港增速TOP1的持牌虚拟资产券商*,卓锐证券专注构建合规安全的交易生态,实现传统资产与加密货币的无缝流动。通过自主研发的一站式交易平台“ZR”,投资者只需一个账户,即可借助AI赋能的机构级视野,灵活配置股票、ETF及加密货币。了解更多:https://www.zr.hk/ 香港Web3嘉年华是由万向区块链实验室与HashKey Group联合推出的Web3活动品牌,由W3ME承办,自2023年起于每年4月在香港会议展览中心举办,聚焦行业热点话题与政策趋势,是亚洲规模最大、最受关注的Web3行业盛会之一。 2026香港Web3嘉年华将于4月20日-23日在香港会议展览中心盛大举行。自2023年首届举办以来,香港Web3嘉年华已飞速成长为全球最具影响力的加密峰会之一,为全球东西方交流构建了一个高规格、高质量、高纵深的平台。过往三届盛会累计吸引超10万名现场参会者,汇聚超350个前沿项目参加,邀请超1200位演讲嘉宾分享,并衍生超400场周边活动,成功构建了一个以大会为核心、辐射全港的活力生态圈。 目前,香港特别行政区财政司司长陈茂波,香港证监会中介机构部执行董事叶志衡,万向区块链董事长、Hashkey Group董事长兼CEO肖风,香港特别行政区立法会议员(科技创新界)邱达根,Solana Foundation总裁Lily Liu,MatrixPort创始合伙人及首席商务官Cynthia...

Sui stablecoin USDsui debuts as new backbone for on-chain payments and DeFi

Backed by institutional-grade infrastructure and strong demand for digital...

Share

Chainalysis has released a preview of its report on crypto frauds in 2024, with particular attention to the explosive growth of Approval Phishing. In fact, in 2023 alone, 374.6 million dollars were stolen. 

But what is targeted approval phishing?

Chainalysis and crypto fraud: the report on the strong growth of approval phishing in the last two years

In a preview of its new 2024 Crypto Crime Report“, focusing on crypto fraud, Chainalysis discussed the strong growth that approval phishing has experienced in the last two years.

“Phishing scams targeting approvals are on the rise, with many scammers using romantic scam tactics to trick victims into signing harmful TX. We estimate that victims have lost over $374 million in 2023. To learn more, check out our first preview of the Crypto Crime Report 2024.”

In practice, unlike other crypto scams, with targeted approval phishing, scammers induce the user to sign a harmful blockchain transaction. 

Specifically, the user’s signature gives the scammer’s address approval to spend specific tokens within their wallet, allowing them to empty the victim’s address of those tokens at their discretion. 

Usually, this technique involves three wallet addresses

  1. that of the victim who signs the transaction with approval to the second address to spend their funds;
  2. the second address which belongs to the phisher who will execute the transactions and transfer the funds to a third destination address;
  3. the third address will be the one that contains the stolen funds. 

This technique of crypto fraud has seen an explosive growth in the last two years, with at least 374 million dollars suspected to have been stolen in 2023. 

Chainalysis and crypto fraud: the development of dApps is behind the growth of approval phishing

Chainalysis continues to describe the growing technique of approval phishing associating it with romance scams to convince victims to sign approval transactions.

And indeed, behind this strong growth of the last two years of this type of crypto fraud, there is the increase of decentralized applications (or dApps) that require approval signatures to authorize smart contracts. 

Specifically, dApps that use smart contracts, such as Ethereum, require users to sign approval transactions that authorize the dApp’s smart contracts to move funds held by the user’s address.

With this new habit introduced to the user, phishers insert themselves to forward their signature requests for approval of their transactions which are, instead, harmful. 

In the investigations conducted by Chainalysis, it seems that the peak of income for suspected approval phishing scammers occurred in May 2022. In numerical terms, the estimated amount of stolen funds through this crypto fraud for the entire year 2022 should be $516.8 million. 

Not only that, the study highlights that the most successful approval phishing address has likely stolen $44.3 million from thousands of victim addresses. 

Chainalysis and crypto fraud: tips to avoid falling into the approval phishing trap

Chainalysis, the blockchain data platform that provides software, services, and research, has also explored how to address the problem of crypto fraud resulting from approval phishing. 

Through its analysis scheme of the addresses involved in this technique, Chainlysis invites crypto-exchange compliance teams to monitor the blockchain

The goal is to identify phishing suspects with a strong exposure to associated destination addresses.

Not only that, more generally, the blockchain platform invites the entire industry to work to educate users not to sign suspicious approval transactions, or to have more awareness of what they are granting.

Phishing attacks and crypto crime

The phishing technique for crypto crime attacks is seeing its evolution. In fact, this romantic phishing scam with approval is added to other phishing techniques such as email campaigns. 

In this regard, last November, email phishing campaigns targeted OpenSea’s NFT marketplace and were aimed at both platform customers and developers.

In this case, while OpenSea has not been hacked in any way, users have received emails from a “fake OpenSea” containing harmful links. Users have reported everything on social media, showing evidence of it. 

On the contrary, however, the phishing attack that occurred in early September targeted Vitalik Buterin’s X account, the co-founder of Ethereum, and resulted in the theft of $700,000 from users.

And indeed, Buterin’s compromised X account was used to promote a fake commemorative NFT coin. Users were invited to mint these NFTs with a limited-time offer. 

Obviously, the provided link led to a phishing website that posed a significant threat to unsuspecting victims, using the “Pink drainer software” tool. 

Among the stolen goods, there was also the theft of a precious Crypto Punk NFT valued at 153 ETH, equivalent to $250,000 at that time.