SlowMist: 2025 Q4 MistTrack Stolen Funds Analysis
Since SlowMist launched the MistTrack stolen fund report submission feature, we have received a large number of help requests from victims every day, seeking support for fund tracing and recovery. Among them are cases involving losses of over tens of millions of USD.
Based on this, we have launched this quarterly series to collect statistics and conduct analysis on the stolen fund reports we receive, aiming to dissect both common and uncommon attack methods through real (anonymized) cases. The goal is to help industry participants better understand and guard against security risks, and to protect their assets.
According to statistics, the MistTrack Team received a total of 300 stolen fund reports in Q4 2025, including 210 domestic submissions and 90 overseas submissions. We provided free community-level assessment services for all of these cases. (Ps. This data only includes cases submitted via the form, and does not cover those reported via email or other channels.)
In Q4, the MistTrack Team assisted 9 victims in successfully freezing or recovering approximately USD 1 million in stolen assets.
Causes of Theft
In Q4 2025, phishing attacks ranked as the top cause of theft. Next, we will highlight several typical cases to help users better avoid scams, prevent theft, and protect their assets.
1. Phishing Attacks
In Q4, phishing attacks remained frequent and showed a clear divergence compared to other quarters: on one hand, traditional “confusing domain” attacks continued; on the other hand, new, more covert methods emerged that could manipulate users’ browsing paths, making the attacks more deceptive and process-oriented.
The type causing the greatest losses was still “look-alike character poisoning addresses” — simple but deadly. For example, one user was deceived by an address whose first and last characters were almost identical to the intended one, resulting in a loss of nearly 50 million USDT. On-chain data shows that the user first sent a small test transaction to the correct address, and just a few minutes later, transferred 50 million dollars directly to a malicious address that looked “almost the same” (first 3 characters and last 4 characters matched):
User’s address: 0xcB80784ef74C98A89b6Ab8D96ebE890859600819
Poisoned address: 0xBaFF2F13638C04B10F8119760B2D2aE86b08f8b5
User’s intended target address: 0xbaf4b1aF7E3B560d937DA0458514552B6495F8b5
Although SlowMist disclosed this phishing method as early as 2022, users continue to fall victim. The typical process usually unfolds as follows:
Generating phishing addresses
Hackers preemptively create a large batch of phishing addresses and deploy them using distributed programs. Based on on-chain user activity, they launch phishing attacks targeting addresses that have the same first and last characters as the victim’s intended transfer address. In this case, the hacker used addresses whose first 3 and last 4 characters (excluding the “0x” prefix) matched the victim’s target address.
Tail transactions to obscure the attack
After the user initiated a transfer at 15:06:47, the hacker quickly followed up with tail transactions using the collided phishing addresses (at 15:12:35 and 15:20:35 — one involving a fake token and the other a real token of 0.005 USDT), making the phishing addresses appear in the user’s transaction history and thereby creating confusion.
Copy & Paste → Victim Falls for the Trap
Because users often copy recent transfer information directly from their wallet history, seeing the tailing phishing transactions, they did not carefully check whether the copied address was correct. As a result, 50 million USDT was mistakenly sent to the phishing address.
There have been many similar cases in the past. For example, one victim once accidentally transferred 1,155 WBTC; fortunately, the funds were eventually fully refunded, but not every case ends so luckily. The prevention method for this type of scam is actually quite simple: store frequently used addresses in an address book, enable small-amount filters, and verify at least the first 6 and last 8 characters before transferring. The safest approach remains checking each character one by one.
A more classic phishing method is fake domains — an old trick that remains effective as long as it spreads fast enough, someone will always click. For instance, earlier this year, BNB Chain’s official English Twitter account was briefly compromised. The attacker, impersonating the official account, posted a phishing link, subtly replacing the “i” in “binance” with a visually similar “l,” creating bnbchalns[.]com. If users scroll quickly through social media feeds and experience visual fatigue, they can easily end up on a counterfeit page that looks almost identical to the official site.
A more recent phishing method is even more covert: even if users manually type in the correct official domain, they may still be redirected to a phishing website. Some victims reported that although they entered the correct address, their browser automatically completed it to an attacker-constructed look-alike domain — for example, plasma.to being auto-completed as plasmą.to, or balancer.fi being replaced with bǎlancer.fi.
This attack succeeds not because of user error, but because attackers preemptively polluted the browser’s history through ads, social media guidance, or fake announcements. Once the phishing domain is stored in the browser’s autocomplete logic, the next time the user types the address, the browser automatically redirects to the counterfeit site, whose interface is almost indistinguishable from the official website. In other words, users believe they are actively visiting the official site, but in reality, they have already fallen into a trap meticulously set by the attacker.
Of course, whether it’s traditional phishing or autocomplete hijacking, the ultimate goal is the same: tricking users into signing authorizations without any precautions. To achieve this, attackers often disguise links as airdrops, rewards, tasks, test qualifications, or as official project announcements, making users believe they are performing ordinary interactions. However, the signature may actually authorize high-risk operations, such as Owner changes.
A recent help case we received is a typical example: the victim’s wallet Owner permission was quietly transferred to the attacker’s address (GKJBELft…JwbzQ), resulting in a loss of USD 3 million, with another USD 2 million nearly unrecoverable. Post-incident analysis revealed that the victim had visited a disguised tool website and completed a seemingly normal transaction signature that involved no immediate asset movement. Unaware of Solana’s mechanism allowing account ownership modifications and without any security tool warnings, the core authorization was silently executed, and the risk only became apparent when the funds became inaccessible.
In short, in the face of constantly evolving phishing techniques, simply “carefully checking links” and “clicking cautiously” is no longer sufficient. Users need to cultivate good security habits, such as:
- Access frequently used websites via bookmarks whenever possible, reducing reliance on browser autocomplete;
- Before signing any transaction, check whether it involves permission changes, and prioritize using wallets or security tools that provide risk warnings;
- Remain vigilant toward “official announcements” or “task/airdrop” messages on social media, and avoid connecting your wallet directly in unfamiliar environments.
2. Social Engineering Attacks
During Q4, social engineering attacks remained common. Attackers typically exploit trust relationships, time pressure, or impersonation of familiar identities to steer victims into unknowingly performing high‑risk actions.
Some scams begin with nothing more than a seemingly ordinary request for a verification code. One user shared how their funds were stolen: at first, they assumed it was due to mnemonic leakage, but later realized it was actually the result of a carefully orchestrated social engineering attack. The setup began a month earlier — the attacker quietly added their own Passkey to a family member’s Google account, then waited in the dark.
One day, repeated Gmail verification pop‑ups appeared on the family member’s computer, and the victim received multiple verification emails. Trying to “help resolve the issue,” the victim forwarded the codes without much thought. Those codes fell right into the attacker’s hands, enabling them to take over the victim’s Google account.
Since the victim had stored part of a private key backup in the cloud, the attacker was able to retrieve a fragment and brute‑force the missing part. In the end, they successfully reconstructed the complete private key and stole the assets.
Additionally, we have observed that attackers are increasingly impersonating security teams or well-known third-party service personnel, proactively contacting users under the pretense of addressing security risks or asset issues, and luring them into high-risk actions.
In one case, the attacker reached out to a user via direct message, falsely claiming that the user’s wallet was at risk of unauthorized access. During the interaction, the attacker applied continuous pressure, using the pretext of “assisting in investigation and remediation” to coax the user into exporting their private key. Fortunately, the user remained vigilant and verified the situation with us in time, ultimately avoiding further losses.
A closer look at the profiles of these impersonating “security personnel” often reveals a large number of followers, giving the appearance of high credibility. Once exposed by legitimate security teams, they quickly change their profile picture, display name, or account to evade detection and continue their scams.
The general playbook of these scams looks like this: the attacker first impersonates a security team or official support staff, using an authoritative identity to quickly gain the victim’s trust. They then create urgency with phrases like “your wallet is at risk,” “abnormal authorization detected,” or “your assets may be frozen,” pushing the user into panic and lowering their guard. Under the combined influence of trust and fear, the victim is further guided to perform so‑called “fix steps” — entering private keys, downloading “inspection tools,” importing their wallet, or signing what appears to be a normal transaction. Once the user completes the critical action, the attacker immediately takes control of the funds and transfers them out at high speed.
The technique itself isn’t particularly sophisticated — its strength lies in exploiting human nature. Once trust is established and enough pressure is applied, it becomes very hard for most people to pause for three seconds and think before acting.
In summary, insufficient user security awareness is the core vulnerability exploited in these attacks. We recommend the following:
- Never provide your private keys, mnemonic phrases, or full key information to anyone. Legitimate security teams will never ask for these.
- Do not use links, tools, or files provided by strangers to resolve security issues. If you need to check for risks, go through official channels or trusted wallet tools.
- Be highly skeptical of any “security alerts” that contact you proactively. Regardless of the claimed institution, always verify through official channels.
- Establish consistent security habits. Use hardware wallets, enable two-factor authentication, regularly review authorizations, and learn basic security knowledge.
3、Job Interview Scams
In Q4, multiple cases of cryptocurrency theft related to job applications or interviews were reported. Attackers combined social engineering with technical methods, gaining victims’ trust through recruitment or interview scenarios before deploying malware to steal assets.
In one case, the attacker impersonated official staff from a Web3 project, contacting the victim under the pretext of recruitment and a technical interview, and presenting a professional and credible image. Subsequently, as part of the “code review” or “technical assessment” segment of the interview, the attacker provided the victim with a code repository hosted on Bitbucket, instructing them to clone and run it, claiming it was a “code review test” for the interview. Because this process closely mirrored a normal Web3 technical interview workflow, the victim did not recognize the risk in time.
Once executed, malicious logic hidden in the project began running, downloading and executing malware from a remote server. The program scanned the victim’s local environment and specifically targeted sensitive information, including private keys stored in .env files. As a result, the victim’s cryptocurrency assets were at risk, and their device remained exposed to threats for an extended period.
In another case, after a victim created a Web3-related job profile on a recruitment platform, they soon received a direct message from someone claiming to be a recruiter from a well-known organization. During the initial communication, the attacker repeatedly discussed the victim’s technical background and past experience, making the process appear consistent with a legitimate recruitment workflow.
Subsequently, a short interview was arranged via video conference. During the meeting, the attacker never turned on their camera and, after a few minutes, sent the victim a new meeting link under the pretext of “needing to switch the meeting platform.” When the link failed to work properly, the attacker further guided the victim to download and install a related application to continue the interview process. Although the victim noticed something unusual at the time, they did not halt the operation promptly, and their wallet subsequently experienced abnormal asset movements.
Post-incident analysis revealed that the victim may have had their wallet permissions compromised or their device infected with malware while visiting the suspicious page or installing the application. The attacker then used the obtained permissions to transfer multiple types of cryptocurrency assets from the victim’s wallet. Verification confirmed that the claimed projects or organizations were entirely impersonated.
These cases demonstrate that interview scams are no longer just simple “phishing link” attacks; they replicate an entire recruitment process that appears completely legitimate. From submitting resumes and technical discussions to interview scheduling and testing, nearly every step aligns with what a Web3 professional would expect, which makes it easier for victims to let their guard down. By the time the attacker asks the victim to “run some code,” “switch the meeting platform,” or “install software to continue the interview,” many have unknowingly already entered a high-risk situation.
Therefore, when participating in Web3 job applications or interviews, be extra cautious with any requests involving your local environment, executing external code, or installing additional software. Legitimate interviews rarely require candidates to run unknown programs on their primary devices or to repeatedly switch communication methods during critical steps. If you notice the process becoming unusual, rushed, or simply feel that “something is off,” stopping promptly is often more important than trying to comply. Conduct thorough background checks and use isolated environments — these precautions can help you avoid such risks at critical moments.
4. Computer Malware Attacks
In Q4, computer malware attacks resurfaced. Attackers often use phishing links, private messages via social tools, or so-called “resource downloads” to quietly implant malicious programs into the user’s local environment. Once the device is infected, wallet-related data becomes exposed to risk.
A typical case involves a user named Babur. Initially, he encountered someone attempting to extort him. Babur was not concerned about the extortion itself, but he became interested in the attacker’s demonstrated OSINT capabilities during their communication. Given his past experience with account breaches, Babur chose to continue the interaction and even paid the attacker to assist with a so-called “due diligence” investigation. The attacker then sent him multiple “investigation results.” The first time a link was provided, Babur remained cautious and did not click, instead requesting the content in plain text. However, when the attacker later sent a link that seemed more aligned with his needs and appeared more “reasonable,” he let his guard down and accessed it.
In hindsight, the link was not a typical phishing page but a malicious entry point disguised to look like Etherscan. The page contained execution logic designed to deliver malware, which could trigger the malicious code locally once accessed. Since the process did not rely on Telegram’s file download mechanism, enabling “disable automatic downloads” was ineffective in preventing this infection.
The situation worsened because Babur accessed the link on a device that served as the second signer for a multisig wallet. After the device was infected, the attacker was able to obtain critical information related to signing operations, bypassing existing permission controls and directly intervening in the multisig process. Additionally, the attacker acquired some metadata from Babur’s Telegram account via the same infection path. Ultimately, with the signing device fully compromised, the attacker successfully completed subsequent authorization operations, resulting in significant asset loss.
In fact, real computer malware attacks are neither complex nor highly sophisticated. Attackers simply leverage a workflow that “looks reasonable” to trick users into making a single wrong action on a critical device. Once a local environment responsible for signing or private key management is compromised, even multisig setups or more advanced security schemes lose much of their effectiveness.
Therefore, devices handling signing or private key management should be kept as isolated as possible, avoiding link browsing, file downloads, or any non-essential operations. For Web3 users, security is not just about choosing the right tools — it’s about clearly identifying which devices are “too critical to fail.”
5. Social Media Scams
During Q4, we also observed a recurring scam method on social media: attackers first steal or take control of influential accounts, then use mutual followers or familiar contacts to reach out to targets via direct messages, gradually guiding them to phishing pages or prompting them to perform malicious actions.
One user proactively shared their experience with us, expressing a desire to “test the waters” in order to raise awareness of these scams. In this case, the attacker first compromised a KOL’s Twitter or Telegram account. Because the account already had a certain level of influence and shared multiple mutual connections with the victim, the direct message did not immediately raise suspicion.
Once communication began, the attacker first approached with a “fund promotion partnership” pitch, offering to pay approximately USD 10,000–15,000 and asking the user to help promote the project. After gaining initial trust, they moved the conversation to Telegram and used “advancing the partnership process” as a pretext for further actions.
During this period, the attacker claimed that the user “had not yet completed account registration and partnership setup,” stating that payment could not be made at the moment and attributing the issue to the user not completing the required steps on a designated website. The attacker then sent a website that appeared legitimate and instructed the victim to open the terminal on their Mac and copy and execute a specified command to complete the account creation. To further lower the victim’s guard, the attacker also sent screenshots of the website, repeatedly emphasizing that this was part of the “normal process” and constantly urging the user to complete the steps quickly in order to proceed with the partnership.
In reality, these pages or commands all pointed to phishing sites or malicious programs. Once executed, the device environment or wallet permissions could be further compromised. It’s worth noting that during the interaction, the victim had even tried requesting partial payment upfront to verify the attacker’s sincerity, but the attacker continually refused with various excuses and never made any transfers.
Looking at the outcome, for someone familiar with on-chain security scams, this type of social media deception isn’t particularly sophisticated. However, it exploits psychological blind spots such as “endorsement by acquaintances,” “mutual followers,” and “seemingly reasonable partnership offers,” making it easier for victims to lower their guard immediately. For users who are active in crypto social circles, the more a direct message “doesn’t look like a scam,” the more reason there is to pause and verify before acting.
Closing Remarks
From the real help cases received in Q4, it is clear that many security incidents do not stem from complex vulnerabilities or sophisticated attacks. More often, attackers simply follow users’ habits, trust paths, and usage scenarios, embedding risks step by step into processes that appear normal. Whether it’s phishing pages, social engineering, interview scams, or computer malware, the underlying exploit is always the same: information asymmetry and gaps in security awareness.
For users, security is not just about memorizing a few “don’t click links” rules. It’s about clearly understanding which actions are high-risk, which devices are critical and must not fail, and which scenarios require heightened vigilance. For projects and ecosystem participants, security is not only about post-incident tracking and remediation; it also requires proactively minimizing misleading cues and reducing the likelihood of user errors through careful design and communication.
The MistTrack stolen-assets form continues to collect and analyze these real theft cases — not merely to review losses themselves, but to extract reusable risk signals from each specific incident, helping more users identify issues in advance and avoid reaching the point of needing assistance. While attack methods are constantly evolving, the core remains unchanged: trust is abused, and processes are disguised. The real challenge is not recognizing a single scam, but establishing a long-term, transferable approach to risk assessment.
Therefore, we recommend repeatedly reading the “Blockchain Dark Forest Self-Rescue Manual” to understand the fundamentals of security awareness in a “dark forest” environment, and combining this knowledge with hands-on practice on the Web3 phishing simulation platform Unphishable, continuously strengthening your ability to judge that what you see is what you are signing in real-world scenarios.
If you’ve fallen victim to cryptocurrency theft, we offer free community assistance to help evaluate your case. Simply submit the appropriate form based on the incident type (stolen funds, scam, or extortion). The hacker’s address you provide will also be shared with SlowMist InMist Lab’s Threat Intelligence Network for further risk control actions.
- Submit the Chinese form here: https://aml.slowmist.com/cn/recovery-funds.html
- Submit the English form here: https://aml.slowmist.com/recovery-funds.html
SlowMist has been deeply involved in the Anti-Money Laundering (AML) field for many years, developing a comprehensive and efficient solution that covers compliance, investigations, and audits. We are committed to fostering a healthy cryptocurrency ecosystem and providing professional services to the Web3 industry, financial institutions, regulatory bodies, and compliance departments. Our MistTrack platform offers compliance investigation services that include wallet address analysis, fund monitoring, and tracing. To date, MistTrack has accumulated over 400 million address tags, more than 1,000 address entities, 500,000+ threat intelligence data points, and 90 million+ risk addresses, providing strong protection against money laundering and ensuring digital asset security.
About SlowMist
SlowMist is a threat intelligence firm focused on blockchain security, established in January 2018. The firm was started by a team with over ten years of network security experience to become a global force. Our goal is to make the blockchain ecosystem as secure as possible for everyone. We are now a renowned international blockchain security firm that has worked on various well-known projects such as HashKey Exchange, OSL, MEEX, BGE, BTCBOX, Bitget, BHEX.SG, OKX, Binance, HTX, Amber Group, Crypto.com, etc.
SlowMist offers a variety of services that include but are not limited to security audits, threat information, defense deployment, security consultants, and other security-related services. We also offer AML (Anti-money laundering) software, MistEye (Security Monitoring), SlowMist Hacked (Crypto hack archives), FireWall.x (Smart contract firewall) and other SaaS products. We have partnerships with domestic and international firms such as Akamai, BitDefender, RC², TianJi Partners, IPIP, etc. Our extensive work in cryptocurrency crime investigations has been cited by international organizations and government bodies, including the United Nations Security Council and the United Nations Office on Drugs and Crime.
By delivering a comprehensive security solution customized to individual projects, we can identify risks and prevent them from occurring. Our team was able to find and publish several high-risk blockchain security flaws. By doing so, we could spread awareness and raise the security standards in the blockchain ecosystem.
