Currencies38693
Market Cap$ 2.71T-0.21%
24h Spot Volume$ 37.05B-30.7%
DominanceBTC57.17%+0.41%ETH10.88%+1.03%
ETH Gas0.15 Gwei
Cryptorank
/

Bofur Capital loses $2M in address poisoning attack after Compound withdrawal


Bofur Capital loses $2M in address poisoning attack after Compound withdrawal

Share:

AI Overview

Bofur Capital lost about $2 million after an address poisoning attack that began with a 0.0002 USDC dust transfer following a withdrawal from DeFi lender Compound; the attacker swapped the stolen assets into 2 million DAI which are held at address 0xe2eB…1816a. Security firm PeckShield says this wallet‑targeting scam underscores rising crypto and DeFi security risks, urging use of address books, hardware wallets, multi-signature setups and test transfers since on-chain transactions are irreversible and recovery is unlikely.

Bearish

Predictions Markets

See what traders are focused on

View analytics →
Prediction Banner

BitcoinWorld

Bofur Capital loses $2M in address poisoning attack after Compound withdrawal

A cryptocurrency entity known as Bofur Capital has lost approximately $2 million in an address poisoning attack, according to blockchain security firm PeckShield. The incident occurred shortly after the victim withdrew funds from the decentralized lending protocol Compound, highlighting the growing sophistication of wallet-targeting scams.

How the attack unfolded

PeckShield reported that the attacker initiated the scheme by sending a small ‘dust’ transaction of 0.0002 USDC to the victim’s wallet. This transaction was designed to create a fake address in the victim’s transaction history, which closely resembled a legitimate address the victim had previously used. When the victim later attempted to transfer funds, they copied the fraudulent address from their history and sent the funds to it, resulting in the loss of $2 million.

The stolen assets were subsequently swapped into 2 million DAI and are currently held at the address 0xe2eB…1816a, according to PeckShield. The funds have not yet been moved, but the incident underscores the irreversible nature of blockchain transactions.

Address poisoning: a growing threat in DeFi

Address poisoning, also known as address spoofing, is a type of attack where cybercriminals send tiny amounts of cryptocurrency to a victim’s wallet, hoping to pollute their transaction history. The goal is to trick users into copying a malicious address that looks similar to one they have used before. This technique exploits the common practice of copying addresses from transaction logs rather than verifying them through a trusted source.

This attack vector has become increasingly common in the DeFi space, where users often manage multiple wallets and interact with various protocols. Security experts recommend always verifying the full address before sending funds, using address books, or employing hardware wallets that display the complete address on a separate screen.

Why this matters to crypto users

The Bofur Capital incident serves as a stark reminder that even experienced participants in the crypto ecosystem can fall victim to these scams. The loss of $2 million in a single transaction highlights the need for heightened vigilance, especially when dealing with large transfers. Users should never rely solely on transaction history to confirm addresses, as these can be manipulated.

Blockchain analytics firms and security services are increasingly tracking such attacks and warning the community, but the decentralized nature of crypto means that once funds are sent, recovery is extremely difficult. This case also illustrates the importance of using multi-signature wallets or involving a second party for large transactions.

Protecting against address poisoning

To mitigate the risk of address poisoning, users should adopt several best practices. Always copy addresses from a trusted source, such as a previously saved contact or a wallet’s address book, rather than from transaction history. Double-check the full address, not just the first and last few characters, as attackers often generate addresses with similar prefixes and suffixes. Consider using a hardware wallet that requires physical confirmation of the address. For large transfers, perform a small test transaction first to verify the receiving address.

Conclusion

The attack on Bofur Capital is a clear illustration of the evolving threats in the cryptocurrency space. While the industry continues to innovate, security remains a paramount concern. Users must stay informed and adopt robust verification practices to protect their assets. PeckShield and other security firms continue to monitor the situation, and the stolen funds remain traceable on the blockchain, though recovery is unlikely without the attacker’s cooperation.

FAQs

Q1: What is an address poisoning attack?
An address poisoning attack involves sending a small amount of cryptocurrency to a victim’s wallet to create a fake address in their transaction history. The attacker uses an address that looks similar to one the victim has used before, tricking them into sending funds to the wrong address.

Q2: How can I protect myself from address poisoning?
Always verify the full address before sending funds, use a trusted address book, and consider using a hardware wallet. For large transactions, perform a small test transfer first and double-check the address on multiple devices.

Q3: Can stolen funds be recovered?
In most cases, no. Once a cryptocurrency transaction is confirmed on the blockchain, it is irreversible. However, law enforcement and blockchain analytics firms can sometimes trace funds and freeze them if they end up on a centralized exchange, but recovery is rare.

This post Bofur Capital loses $2M in address poisoning attack after Compound withdrawal first appeared on BitcoinWorld.

Read the article at Bitcoin World

In This News

Coins

$ 0.99993

0%

$ 0.99994

0%

Predictions Markets

See what traders are focused on

View analytics →
Prediction Banner

Share:

In This News

Coins

$ 0.99993

0%

$ 0.99994

0%

Predictions Markets

See what traders are focused on

View analytics →
Prediction Banner

Share:

Read More

Another DeFi Hack: Term Labs Loses $8.5 Million in Governance Exploit

Another DeFi Hack: Term Labs Loses $8.5 Million in Governance Exploit

In Brief Term Labs lost about $8.5 million to a governance exploit on its vaults. At...
The Sandbox Contains Bridge Exploit After Unbacked SAND Minted on Base and BSC

The Sandbox Contains Bridge Exploit After Unbacked SAND Minted on Base and BSC

In Brief The Sandbox says it contained a bridge vulnerability that minted unbacked S...