A fake Uniswap website promoted through Google ads has already drained roughly $400,000 from users. The scam works by pushing phishing links above the real website in Google search results, tricking users into connecting their wallets and signing malicious transactions.
An attacker discovered a flaw in Aztec Connect’s public rollup processing function and exploited it to drain the remaining funds. Before the attack, the wallet was funded through Tornado Cash. Aztec Labs closed Aztec Connect in 2023 and gave users over a year to withdraw their
The exploit drained:
909 ETH
270,000 DAI
167 wstETH
Other assets
Total losses exceeded $2.1 million.
Importantly, no current users were affected. The stolen funds had been left behind in abandoned contracts after the shutdown.
If you’ve been a victim of a crypto scam or exploit, @IRONCLADFORENS can assist with blockchain tracing, forensic analysis, and assistance in getting back your assets.
Stay safe and share this so more people don’t get drained.
x.com/messages/compose?recip…
Unfortunately, this has been happening for years, and people are still getting caught by it every day. These wallets are linked to these scam activity:
0x37925684BA178821b4436E06e67f5dBD6cfA49Bb
0x2fC25F46cC49D226eF92E9A7665f3d2821F3c5E2
Please be careful when accessing DeFi platforms. Always verify links through official X accounts or check protocols with @IRONCLADFORENS before connecting your wallet. Never trust the first sponsored result on Google.
If you were affected by this scam, you can also reach out to @IRONCLADFORENS for forensic tracing and possible recovery assistance related to stolen funds.
Stay safe and share this so more people don’t get drained. x.com/messages/compose?recip…
🚨@ThetanutsFi Legacy Index Vault was exploited for ~$105.5K USDC.
Attacker flashloaned most TN-IDX-USDC-PUT tokens, claimed them, and drained nearly all underlying assets — leaving just 3 wei in totalSupply.
They then used multiple crafted mints to generate large amounts of new IDX-USDC-PUT tokens (without depositing any assets), exploiting the mint math (underlying_amount * shares / totalSupply) due to precision loss at near-zero totalSupply.
💡Reminder: Allowing flash-loans on share/LP tokens carries very high risk.
- attacker: etherscan.io/address/0x30498…
- tx: etherscan.io/tx/0xbba9f138fe……
Our preliminary investigation indicates that this is once again, a deprecated vault that we have migrated from years ago. It has no relation to any of our current contracts or products.
We will release a post-mortem once we get more details.
@kojistrade Your wallet have been compromised by a phishing attempt.A bot triggered a transaction that authorized a malicious smart contract,allowing it to withdraw your assets.
If you still have the transaction hash, kindly send us a text so we can review the transaction, assist you with revoking the approval and recover your funds. This is important @kojistrade
Approximately $500,000 in crypto assets was stolen after 297 wallets were drained across multiple EVM chains.
Blockchain tracing identified the stolen funds being consolidated at:
0x43D49AeF7aAf0Dcf015b20057C5364E092D66615
The assets were transferred directly to FixedFloat.
@degenariooo The compromise on your wallet looks like a phishing attack. An automated sweep bot executed a transaction that granted token approval to a malicious smart contract,enabling it to drain your coins from your wallet.
If you still have the transaction hash id, Kindly share it with us so we can be analyze and guide you through revoking the transaction and recovering your assets @degenariooo
Chirag Tomar allegedly ran a phishing scam targeting users of Coinbase Pro under Coinbase. He registered a lookalike domain (CoinbasePro.com) and used SEO tricks so it ranked high in Google. Victims landed on a fake login page, entered email/password 2FA,
A fake Uniswap website promoted through Google ads has already drained roughly $400,000 from users. The scam works by pushing phishing links above the real website in Google search results, tricking users into connecting their wallets and signing malicious transactions.
Users should avoid clicking crypto ads on Google and instead visit trusted websites directly through manually typing URLs. They should always verify website addresses carefully, enable multi-factor authentication, and never share wallet seed phrases or private keys.
@IRONCLADFORENS can help detect, analyze, and investigate phishing attacks and suspicious crypto activity, improving threat visibility and enabling faster response to fraudulent schemes.