Signature Phishing (Web3)
O que é Signature Phishing (Web3)?
Signature Phishing (Web3)A Web3 phishing pattern that tricks a user into signing an EIP-712 or `personal_sign` message that authorizes the attacker to move tokens, transfer NFTs, or take wallet actions — without ever asking for a seed phrase.
Signature phishing — sometimes called 'sign-in scam' or 'one-click drainer' — is the dominant Web3 phishing pattern of 2023–2025, displacing traditional seed-phrase phishing. The attacker convinces a user to connect their wallet to a malicious dApp (typically a fake mint, airdrop, claim, or 'verify your wallet for refund' page) and to sign one or more messages. Those messages look benign in older wallets — `personal_sign` shows opaque bytes, `eth_signTypedData` shows generic-looking JSON — but actually encode high-impact authorizations: an unlimited ERC-20 `Permit`, an ERC-20 `Permit2.transfer`, an `setApprovalForAll` on a high-value NFT collection, an OpenSea or Blur order to sell the user's holdings for ~zero, or, increasingly, a `safe.execTransaction` on the user's Safe / smart-contract wallet. The attacker submits the signature on-chain and drains the user. Defenses are unfortunately almost entirely UI-side: wallets that decode EIP-712 typed data into 'You are granting unlimited spend of X to address Y', anti-phishing extensions (Wallet Guard, ScamSniffer, Rabby, Pocket Universe, Stelo), and user education that any signature request is functionally equivalent to a transaction.
● Exemplos
- 01
A user visits a fake 'Arbitrum airdrop claim' site, signs a Permit2 message they think is a login, and the attacker uses the signature to transfer their USDC to a drainer wallet.
- 02
An anti-phishing extension parses the EIP-712 payload, displays 'WARNING: you are about to grant unlimited spend of USDC to 0x… on Ethereum', and the user backs out.
● Perguntas frequentes
O que é Signature Phishing (Web3)?
A Web3 phishing pattern that tricks a user into signing an EIP-712 or `personal_sign` message that authorizes the attacker to move tokens, transfer NFTs, or take wallet actions — without ever asking for a seed phrase. Pertence à categoria Web3 e blockchain da cibersegurança.
O que significa Signature Phishing (Web3)?
A Web3 phishing pattern that tricks a user into signing an EIP-712 or `personal_sign` message that authorizes the attacker to move tokens, transfer NFTs, or take wallet actions — without ever asking for a seed phrase.
Como funciona Signature Phishing (Web3)?
Signature phishing — sometimes called 'sign-in scam' or 'one-click drainer' — is the dominant Web3 phishing pattern of 2023–2025, displacing traditional seed-phrase phishing. The attacker convinces a user to connect their wallet to a malicious dApp (typically a fake mint, airdrop, claim, or 'verify your wallet for refund' page) and to sign one or more messages. Those messages look benign in older wallets — `personal_sign` shows opaque bytes, `eth_signTypedData` shows generic-looking JSON — but actually encode high-impact authorizations: an unlimited ERC-20 `Permit`, an ERC-20 `Permit2.transfer`, an `setApprovalForAll` on a high-value NFT collection, an OpenSea or Blur order to sell the user's holdings for ~zero, or, increasingly, a `safe.execTransaction` on the user's Safe / smart-contract wallet. The attacker submits the signature on-chain and drains the user. Defenses are unfortunately almost entirely UI-side: wallets that decode EIP-712 typed data into 'You are granting unlimited spend of X to address Y', anti-phishing extensions (Wallet Guard, ScamSniffer, Rabby, Pocket Universe, Stelo), and user education that any signature request is functionally equivalent to a transaction.
Como se defender contra Signature Phishing (Web3)?
As defesas contra Signature Phishing (Web3) costumam combinar controles técnicos e práticas operacionais, conforme detalhado na definição acima.
Quais são outros nomes para Signature Phishing (Web3)?
Nomes alternativos comuns: Sign-in scam, One-click drainer.
● Termos relacionados
- web3№ 912
Phishing de Permit2
O phishing de Permit2 induz um usuario Ethereum a assinar uma mensagem off-chain do Uniswap Permit2 que concede a um atacante o direito de transferir seus tokens ERC-20.
- web3№ 1348
Drainer de Carteira
Software malicioso ou kit de phishing que engana utilizadores de carteiras cripto para assinarem transacoes ou aprovacoes que entregam todos os tokens e NFTs valiosos.
- web3№ 590
Inferno Drainer
A 2022–2023 crypto-wallet-drainer-as-a-service that emptied tens of thousands of victims' wallets by phishing them into signing token-approval transactions on fake mint and airdrop sites, before shutting down in November 2023.
- web3№ 413
EIP-712 Signing
An Ethereum standard for typed, structured off-chain message signing that lets wallets display human-readable intent (e.g. 'sell 1 ETH to user X by Friday') and bind the signature to a domain, chain, and contract.
- attacks№ 917
Phishing
Ataque de engenharia social no qual o atacante se faz passar por uma entidade de confiança para enganar a vítima e obter credenciais, transferir dinheiro ou executar malware.
- web3№ 017
Envenenamento de Enderecos
O envenenamento de enderecos planta no historico da vitima enderecos semelhantes controlados pelo atacante, para que ela depois copie e cole o errado e envie fundos ao atacante.