• 4 mins read
  • Published

Researchers Find Over 4,200 Malicious Smart Contracts Draining Crypto

Catheryne Nicholson Crypto infrastructure writer EgonCoin

Post by Catheryne Nicholson

Researchers Find Over 4,200 Malicious Smart Contracts Draining Crypto EgonCoin © egoncoin.com
Researchers Find Over 4,200 Malicious Smart Contracts Draining Crypto © egoncoin.com

A new study links thousands of deceptive smart contracts to millions in crypto losses, exposing how wallet simulations can mislead users and reroute funds to attackers across major blockchains

Thousands of crypto users have lost millions of dollars to a sophisticated form of phishing that exploits the way wallet safety tools preview transactions, according to a recent academic study. Researchers identified more than 4,200 malicious smart contracts that tricked users into approving transactions that ultimately sent their funds to attacker-controlled addresses, despite wallet previews showing apparently safe or even profitable outcomes.

How Simulation-Phishing Contracts Work

The attack targets a common feature in many crypto wallets: transaction simulation. Before a user signs a transaction, the wallet often displays a preview estimating the expected result. The malicious contracts identified in the study are designed to behave differently during this simulation than when the transaction is actually executed on-chain. For example, a contract might show a small gain or refund in the preview, but once the transaction is confirmed, it reroutes the user's deposit to the attacker. Some contracts achieve this by altering their internal state between simulation and execution, while others exploit differences in block timestamps or gas limits to trigger the malicious branch only during the real transaction.

Scope of the Losses

According to the July 30 preprint, researchers used a tool called SimGuard to detect 4,224 simulation-phishing contracts across Ethereum, BNB Smart Chain, Avalanche, and Polygon. They linked these contracts to 5,742 victim addresses and estimated up to $3.48 million in historical losses, though they cautioned that some attacker test transactions may have inflated the total. The vast majority of losses-over 91%-occurred on Ethereum, with a single cluster of contracts responsible for most of the cross-chain impact. The study's figures are based on on-chain analysis and have not yet been peer reviewed. The authors also noted inconsistencies in their Avalanche data and observation period, leaving some uncertainty about the precise breakdown by network and time frame.

Wallet Previews and User Risk

The research highlights a critical gap in wallet safety features. While tools like MetaMask warn that simulated balance changes are only predictions, many users may not realize that a positive preview does not guarantee a safe outcome. In controlled tests, the researchers found that some wallet previews showed a net gain or negligible loss, even when the actual transaction sent nearly all funds to the attacker. The study did not specify which wallet versions or simulation backends were used by historical victims, making it difficult to assess which products are most at risk. The authors recommend that wallets re-run simulations whenever contract state or gas parameters change, and that user interfaces display both the gross outgoing amount and the net balance change to help users spot misleading refunds.

Security Implications and Industry Response

The findings add to a growing body of evidence that wallet simulation tools, while helpful, are not foolproof against advanced phishing tactics. The study's detector was evaluated on a limited set of contracts, and the code repository cited by the authors was not publicly accessible at the time of review. As the crypto industry continues to grapple with evolving security threats, the need for more robust transaction previews and user education remains clear. This research follows a series of incidents and market shifts that have exposed new risks for crypto holders, such as the increased volatility seen when derivatives activity outpaces spot trading, as discussed in recent coverage of XRP's liquidity challenges.

On-chain data from the study shows that the largest single phishing contract moved approximately 143.45 ETH in a single transaction, as recorded on Etherscan in January 2025. The total number of victim transactions linked to these contracts reached 6,223, with the majority of losses concentrated in a handful of large clusters. While the $3.48 million loss estimate represents an upper bound, it underscores the scale of the threat posed by simulation-phishing contracts across major blockchains.

Smart-contract phishing attacks like those described in the study exploit the technical complexity of blockchain transactions and the limitations of wallet interfaces. Unlike traditional phishing, which relies on fake websites or emails, these attacks use code-level deception to manipulate what users see before they sign. Because blockchain transactions are irreversible, a single mistaken approval can result in permanent loss of funds. As wallet providers and security researchers work to improve simulation accuracy and user warnings, crypto users should remain cautious and verify transaction details-especially when interacting with unfamiliar contracts or protocols.

Related articles