The bad actor targeted over 70,000 ETH wallets, spending over 8 ETH in gas fees.
How the phishing attack was carried out, including the technical side and defensive measures.
Hackers are becoming more sophisticated and employ different tactics to deceive investors. A method that is becoming increasingly popular is a malicious airdrop.
Initially, it was believed Uniswap's protocols were exploited. It was later determined that a phishing attack drained approximately $8 million out of Uniswap's liquidity providers.
Uniswap is a popular decentralized exchange (DEX) for Ethereum including tokens on the ETH mainnet.
How the Phishing Attack Starts?
In the first stage, the bad actor hits the explorers index so the 'From' address appears legitimate, 'Uniswap V3: Positions NFT'. This is called an event pollution attack.
Tokens are sent from the bad actor to numerous addresses. Investors that receive the tokens are curious why 'Uniswap' send them tokens. When checking the token's name the investors are led to the following website: uniswaplp.com (do not visit).
Upon visiting the website, the following message is displayed:
"Liquidity provider rewards At 14:00 UTC, July 11, 2022, Uniswap distributed the UniswapLP tokens, based on the provided liquidity, to the existing UNI-V3 liquidity providers.
"If you have received the UniswapLP tokens, then you are eligible to claim the UNI tokens from this page by clicking on the below button."
As the investors already have received tokens from 'Uniswap' and that only 10k UNI will be airdropped, if claiming is not done immediately there is a risk of the investors missing a portion from the 10,000 UNI.
Employing fear of missing out (FOMO) plays a major role in luring investors into the trap. Upon clicking on the document, a call is made to ethall().
The user's browser info and wallet address are sent to /66312712367123.com.
It may then ask the user to send the tokens to their ETH address. Upon doing so, the bad actor gains full access to the victim's address and drains the account.
The bad actor sent the 'uniswap' tokens to over 70,000 addresses, spending a substantial amount (over 8 ethers) on gas fees. Among the targeted addresses were large ETH holders.
The vast majority of crypto investors are aware of these scams. However, many are caught off guard if they do not pay full attention to the information in from of them.
The bad actor already commenced laundering the stolen ethers via Tornado Cash, sending 100 ETH per transaction to the mixer.
How to Defend against Similar Attacks?
There are several methods that can be adopted that may reduce the odds of becoming a phishing attack victim in the crypto space. Airdrops must be verified through the project's social media channels.
It may be Twitter, Telegram or Discord etc. If we take a scenario where the project's social media accounts are compromised, which has occurred in the past, paying attention to the permissions that are given upon interacting with the contract including the web address may help.
Another method, which is fairly new is using Forta, which offers real-time security. Forta's threat detection kit may be used for threat detections in NFTs, stablecoins, bridges and more.
ZenGo wallet has a feature called ClearSign that verifies interactions with contracts. As attacks are becoming more sophisticated, it is essential to take the required time to investigate the legitimacy of what you receive including in emails.
Hackers are becoming more sophisticated and employ different tactics to deceive investors. A method that is becoming increasingly popular is a malicious airdrop.
Initially, it was believed Uniswap's protocols were exploited. It was later determined that a phishing attack drained approximately $8 million out of Uniswap's liquidity providers.
Uniswap is a popular decentralized exchange (DEX) for Ethereum including tokens on the ETH mainnet.
How the Phishing Attack Starts?
In the first stage, the bad actor hits the explorers index so the 'From' address appears legitimate, 'Uniswap V3: Positions NFT'. This is called an event pollution attack.
Tokens are sent from the bad actor to numerous addresses. Investors that receive the tokens are curious why 'Uniswap' send them tokens. When checking the token's name the investors are led to the following website: uniswaplp.com (do not visit).
Upon visiting the website, the following message is displayed:
"Liquidity provider rewards At 14:00 UTC, July 11, 2022, Uniswap distributed the UniswapLP tokens, based on the provided liquidity, to the existing UNI-V3 liquidity providers.
"If you have received the UniswapLP tokens, then you are eligible to claim the UNI tokens from this page by clicking on the below button."
As the investors already have received tokens from 'Uniswap' and that only 10k UNI will be airdropped, if claiming is not done immediately there is a risk of the investors missing a portion from the 10,000 UNI.
Employing fear of missing out (FOMO) plays a major role in luring investors into the trap. Upon clicking on the document, a call is made to ethall().
The user's browser info and wallet address are sent to /66312712367123.com.
It may then ask the user to send the tokens to their ETH address. Upon doing so, the bad actor gains full access to the victim's address and drains the account.
The bad actor sent the 'uniswap' tokens to over 70,000 addresses, spending a substantial amount (over 8 ethers) on gas fees. Among the targeted addresses were large ETH holders.
The vast majority of crypto investors are aware of these scams. However, many are caught off guard if they do not pay full attention to the information in from of them.
The bad actor already commenced laundering the stolen ethers via Tornado Cash, sending 100 ETH per transaction to the mixer.
How to Defend against Similar Attacks?
There are several methods that can be adopted that may reduce the odds of becoming a phishing attack victim in the crypto space. Airdrops must be verified through the project's social media channels.
It may be Twitter, Telegram or Discord etc. If we take a scenario where the project's social media accounts are compromised, which has occurred in the past, paying attention to the permissions that are given upon interacting with the contract including the web address may help.
Another method, which is fairly new is using Forta, which offers real-time security. Forta's threat detection kit may be used for threat detections in NFTs, stablecoins, bridges and more.
ZenGo wallet has a feature called ClearSign that verifies interactions with contracts. As attacks are becoming more sophisticated, it is essential to take the required time to investigate the legitimacy of what you receive including in emails.
Scammers Target Hong Kong Stablecoin Licences Before First Tokens Go Live
Featured Videos
FM Daily Brief - 1 May 2026
FM Daily Brief - 1 May 2026
FM Daily Brief - 1 May 2026
FM Daily Brief - 1 May 2026
iForex's CEO tells Finance Magnates the cost of their IPO delay. Also ahead: the US prediction markets legal battle splits in two, and the FCA greenlights onchain funds. It's Friday, the first of May 2026. You're listening to the Finance Magnates Daily Brief.
iForex's CEO tells Finance Magnates the cost of their IPO delay. Also ahead: the US prediction markets legal battle splits in two, and the FCA greenlights onchain funds. It's Friday, the first of May 2026. You're listening to the Finance Magnates Daily Brief.
iForex's CEO tells Finance Magnates the cost of their IPO delay. Also ahead: the US prediction markets legal battle splits in two, and the FCA greenlights onchain funds. It's Friday, the first of May 2026. You're listening to the Finance Magnates Daily Brief.
iForex's CEO tells Finance Magnates the cost of their IPO delay. Also ahead: the US prediction markets legal battle splits in two, and the FCA greenlights onchain funds. It's Friday, the first of May 2026. You're listening to the Finance Magnates Daily Brief.
Not All Video Reviews Are Created Equal | Finance Magnates
Not All Video Reviews Are Created Equal | Finance Magnates
Not All Video Reviews Are Created Equal | Finance Magnates
Not All Video Reviews Are Created Equal | Finance Magnates
Not All Video Reviews Are Created Equal | Finance Magnates
Not All Video Reviews Are Created Equal | Finance Magnates
We deliver fast, structured, neutral reviews covering regulation, platforms, leverage, payouts, and risk across brokers, prop firms, and fintech platforms.
Book your Finance Magnates video review: https://lnkd.in/dDubZJ2S
#FinanceMagnates #BrokerReview #PropTrading #Fintech #Forex #Crypto #CFD #TradingPlatforms #DigitalAssets
We deliver fast, structured, neutral reviews covering regulation, platforms, leverage, payouts, and risk across brokers, prop firms, and fintech platforms.
Book your Finance Magnates video review: https://lnkd.in/dDubZJ2S
#FinanceMagnates #BrokerReview #PropTrading #Fintech #Forex #Crypto #CFD #TradingPlatforms #DigitalAssets
We deliver fast, structured, neutral reviews covering regulation, platforms, leverage, payouts, and risk across brokers, prop firms, and fintech platforms.
Book your Finance Magnates video review: https://lnkd.in/dDubZJ2S
#FinanceMagnates #BrokerReview #PropTrading #Fintech #Forex #Crypto #CFD #TradingPlatforms #DigitalAssets
We deliver fast, structured, neutral reviews covering regulation, platforms, leverage, payouts, and risk across brokers, prop firms, and fintech platforms.
Book your Finance Magnates video review: https://lnkd.in/dDubZJ2S
#FinanceMagnates #BrokerReview #PropTrading #Fintech #Forex #Crypto #CFD #TradingPlatforms #DigitalAssets
We deliver fast, structured, neutral reviews covering regulation, platforms, leverage, payouts, and risk across brokers, prop firms, and fintech platforms.
Book your Finance Magnates video review: https://lnkd.in/dDubZJ2S
#FinanceMagnates #BrokerReview #PropTrading #Fintech #Forex #Crypto #CFD #TradingPlatforms #DigitalAssets
We deliver fast, structured, neutral reviews covering regulation, platforms, leverage, payouts, and risk across brokers, prop firms, and fintech platforms.
Book your Finance Magnates video review: https://lnkd.in/dDubZJ2S
#FinanceMagnates #BrokerReview #PropTrading #Fintech #Forex #Crypto #CFD #TradingPlatforms #DigitalAssets
FM Daily Brief - 30 April 2026
FM Daily Brief - 30 April 2026
FM Daily Brief - 30 April 2026
FM Daily Brief - 30 April 2026
FM Daily Brief - 30 April 2026
FM Daily Brief - 30 April 2026
iForex posts its first annual results as a listed broker. Also ahead: CFI Financial secures a Brazil license, and prediction markets have a big week, with new ETF launches and fresh Polymarket loss data. It's Thursday, the thirtieth of April 2026. You're listening to the Finance Magnates Daily Brief.
iForex posts its first annual results as a listed broker. Also ahead: CFI Financial secures a Brazil license, and prediction markets have a big week, with new ETF launches and fresh Polymarket loss data. It's Thursday, the thirtieth of April 2026. You're listening to the Finance Magnates Daily Brief.
iForex posts its first annual results as a listed broker. Also ahead: CFI Financial secures a Brazil license, and prediction markets have a big week, with new ETF launches and fresh Polymarket loss data. It's Thursday, the thirtieth of April 2026. You're listening to the Finance Magnates Daily Brief.
iForex posts its first annual results as a listed broker. Also ahead: CFI Financial secures a Brazil license, and prediction markets have a big week, with new ETF launches and fresh Polymarket loss data. It's Thursday, the thirtieth of April 2026. You're listening to the Finance Magnates Daily Brief.
iForex posts its first annual results as a listed broker. Also ahead: CFI Financial secures a Brazil license, and prediction markets have a big week, with new ETF launches and fresh Polymarket loss data. It's Thursday, the thirtieth of April 2026. You're listening to the Finance Magnates Daily Brief.
iForex posts its first annual results as a listed broker. Also ahead: CFI Financial secures a Brazil license, and prediction markets have a big week, with new ETF launches and fresh Polymarket loss data. It's Thursday, the thirtieth of April 2026. You're listening to the Finance Magnates Daily Brief.
FM Daily Brief - 29 April 2026
FM Daily Brief - 29 April 2026
FM Daily Brief - 29 April 2026
FM Daily Brief - 29 April 2026
FM Daily Brief - 29 April 2026
FM Daily Brief - 29 April 2026
XTB and Robinhood both post first-quarter earnings. But the numbers point in very different directions. Also ahead: Capital.com pushes into three new markets and signals a move into payments.
It's Wednesday, the 29th of April 2026. You're listening to the Finance Magnates Daily Brief.
XTB and Robinhood both post first-quarter earnings. But the numbers point in very different directions. Also ahead: Capital.com pushes into three new markets and signals a move into payments.
It's Wednesday, the 29th of April 2026. You're listening to the Finance Magnates Daily Brief.
XTB and Robinhood both post first-quarter earnings. But the numbers point in very different directions. Also ahead: Capital.com pushes into three new markets and signals a move into payments.
It's Wednesday, the 29th of April 2026. You're listening to the Finance Magnates Daily Brief.
XTB and Robinhood both post first-quarter earnings. But the numbers point in very different directions. Also ahead: Capital.com pushes into three new markets and signals a move into payments.
It's Wednesday, the 29th of April 2026. You're listening to the Finance Magnates Daily Brief.
XTB and Robinhood both post first-quarter earnings. But the numbers point in very different directions. Also ahead: Capital.com pushes into three new markets and signals a move into payments.
It's Wednesday, the 29th of April 2026. You're listening to the Finance Magnates Daily Brief.
XTB and Robinhood both post first-quarter earnings. But the numbers point in very different directions. Also ahead: Capital.com pushes into three new markets and signals a move into payments.
It's Wednesday, the 29th of April 2026. You're listening to the Finance Magnates Daily Brief.
FM Daily Brief - 28 April 2026
FM Daily Brief - 28 April 2026
FM Daily Brief - 28 April 2026
FM Daily Brief - 28 April 2026
FM Daily Brief - 28 April 2026
FM Daily Brief - 28 April 2026
Startrader posts three-point-one trillion dollars in first-quarter volume — up three hundred and forty percent from a year ago. Also ahead: Fintokei claims sub-second trader payouts, and eToro opens its premium subscription tier to all investors.
Startrader posts three-point-one trillion dollars in first-quarter volume — up three hundred and forty percent from a year ago. Also ahead: Fintokei claims sub-second trader payouts, and eToro opens its premium subscription tier to all investors.
Startrader posts three-point-one trillion dollars in first-quarter volume — up three hundred and forty percent from a year ago. Also ahead: Fintokei claims sub-second trader payouts, and eToro opens its premium subscription tier to all investors.
Startrader posts three-point-one trillion dollars in first-quarter volume — up three hundred and forty percent from a year ago. Also ahead: Fintokei claims sub-second trader payouts, and eToro opens its premium subscription tier to all investors.
Startrader posts three-point-one trillion dollars in first-quarter volume — up three hundred and forty percent from a year ago. Also ahead: Fintokei claims sub-second trader payouts, and eToro opens its premium subscription tier to all investors.
Startrader posts three-point-one trillion dollars in first-quarter volume — up three hundred and forty percent from a year ago. Also ahead: Fintokei claims sub-second trader payouts, and eToro opens its premium subscription tier to all investors.