CYFIRMA Research

CYFIRMA Research: Silent Crypto Wallet Takeover- Unlimited USDT Approval Exploitation via Trust Wallet QR Code Phishing

CYFIRMA

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 4:57

CYFIRMA Research has identified an active crypto drainer campaign targeting Trust Wallet users through QR code phishing distributed via Telegram channels. The attack leverages deep link abuse and deceptive transaction flows to gain persistent access to victim funds.

This campaign highlights a shift toward user-authorized exploitation, where no wallet vulnerability is required. By abusing standard Web3 workflows, attackers gain persistent and unrestricted access to victim wallets, enabling delayed or automated fund exfiltration. This activity underscores the rapid evolution of Drainer-as-a-Service ecosystems, combining social engineering, automation, and low-cost blockchain operations to scale financial theft.

Link to the Research Report: https://www.cyfirma.com/research/silent-crypto-wallet-takeover-unlimited-usdt-approval-exploitation-via-trust-wallet-qr-code-phishing/

#ThreatIntelligence #CryptoSecurity #Web3 #Phishing  #BlockchainSecurity
#CyberSecurity #MalwareAnalysis #CYFIRMA #CyfirmaResearch

https://www.cyfirma.com/