Coordinated Phishing Attack Drains Hundreds of EVM Wallets
An automated phishing campaign has siphoned funds from hundreds of ethereum Virtual Machine (EVM)-compatible wallets, with losses exceeding $107,000. The attacker employed a calculated approach—draining typically under $2,000 per wallet to avoid detection, while targeting multiple blockchain networks simultaneously.
Security analysts trace the attack to spoofed MetaMask branding in phishing emails, tricking users into granting malicious token approvals. The incident bears hallmarks of supply-chain vulnerabilities, echoing a separate Christmas Day exploit that compromised 2,596 Trust Wallet users for $7 million.
Blockchain investigator ZachXBT flagged the wallet-draining spree, noting the attacker’s address remains active. December’s crypto exploit losses plummeted 60% to $76 million—a silver lining overshadowed by this persistent threat vector.