$1.8M Lost to Fake MetaMask Token Honeypot Scam
analysis

$1.8M Lost to Fake MetaMask Token Honeypot Scam

THELOGICALINDIAN - It appears that about 400 bodies accept collapsed victim to the scam

A affected MetaMask badge has bamboozled traders out of over $1.8 million. Hackers injected cipher into the DEXTools application’s advanced end, acceptable traders that the badge was verified.

The MetaMask Token Scam

A affected MetaMask badge has larboard abstract traders reeling. 

Hundreds of traders fell victim to a MetaMask badge honeypot betray Monday evening, with grifters authoritative off with over $1.8 million.

The scam, which played on traders’ apprehension of a MetaMask wallet token, acclimated a blemish in the accepted DeFi trading app DEXTools to argue users of the token’s legitimacy. A bluff was able to inject cipher into the DEXTools app advanced end for the Uniswap WETH/MASK pair, which, back viewed, would barrage a pop-up cogent users that the MASK badge was verified.

After affairs the affected MASK token, biting users begin that they were clumsy to advertise it. This appearance of betray is generally referred to as a “honeypot,” acceptance users to enter, alone to acquisition that the acute arrangement administering the token’s interactions prevents them from selling.

In the case of the affected MetaMask token, the bluff appears to accept programmed the acute arrangement to delay until advancement of $1 actor account of clamminess was traded into it, again to anticipate holders from selling. The bluff pulled out 475 ETH from the token’s Uniswap clamminess pool, according to transaction abstracts from Etherscan, account $1.79 actor at columnist time. The adulterous assets were sent to Tornado Cash, a accepted bread bond application, and were apple-pie to an alone wallet. 

Reports of the betray aboriginal emerged on Twitter Monday evening, with several accounts admonishing that the MASK badge was a betray admitting the pop-up on DEXTools cogent traders it was legitimate. Since then, Twitter user @cobynft has provided a breakdown of how the betray occurred, answer how it was a “serious fault” of the DEXTools app developers that accustomed the betray to argue so abounding bodies to buy the tokens. 

An added acumen that the MetaMask badge betray was so able is the accepted apprehension for a accepted MetaMask token. The MetaMask aggregation accept again hinted at decentralizing the accepted EVM wallet by arising a token, with abounding apperception it could be done through an airdrop. 

The affected MetaMask badge is the third above betray to hit the crypto amplitude over the anniversary season. On Sunday, Binance Smart Chain activity MetaSwapMGAS blanket 1,100 BNB from users in an credible rug pull. Just bygone addition Ethereum activity alleged MetaDAO appears to accept accomplished a rug pull on its investors, authoritative off with 800 ETH, account over $3.2 million.

Crypto Briefing contacted DEXTools for animadversion on the advance on its application’s advanced end but did not accept a acknowledgment by columnist time.

Disclosure: At the time of autograph this feature, the columnist endemic ETH and several added cryptocurrencies.