|

Gas tokens, wallet security warns against interacting with strange tokens amid Multichain exploit delirium

  • Wallet security Revoke.cash urges investors to ignore tokens they don’t recognize.
  • The caution comes amid a new discovery that scammers use gas tokens to steal money when victims revoke the fake approvals.
  • The alert comes amid the infamous Multicahin exploit across Fantom, Moonriver, and Dogecoin bridges.

Gas tokens have become the new loophole that hackers exploit to steal money from unsuspecting token holders. The discovery aligns with the recent attack on cross-chain router Multichain.org which saw the threat actors make away with upwards of $130 million in user-supplied tokens.

Also Read:  Fantom trading volume falls 20% as Multichain hackers leverage FTM tokens in a new attack on Twitter

Gas tokens, a new tactic among scammers

Gas tokens could see you lose money without seeing it coming. The news comes after several reports of token holders noticing strange approval notifications on their transaction history even though they had denied the transactions.

Gas tokens are typically cryptocurrencies designed to pay transaction processing fees. Notably, for every transaction, a nominal fee is paid as a transaction charge. A recent discovery has indicated that scammers now leverage this principle to enrich themselves at the expense of innocent cryptocurrency investors.

The gas tokens concept traces back several years ago to mitigate high Ethereum (ETH) blockchain transaction fees. It works by leveraging an Ethereum Virtual Machine (EVM) feature where users get some form of discount when clearing storage. Specifically, “users could mint gas tokens when fees were low, and burn them when fees were high.” Effectively, they enjoy the reduced fees as an unintended result of storage gas refunds.

Gas tokens leveraged by Multichain hackers

Multichain hackers capitalized on gas tokens to execute their recent attack, creating fake tokens for airdrops and advertising them to the unsuspecting Fantom (FTM) and Dogecoin (DOGE) holders.

Here’s the catch! While the victims (unsuspecting token holders at the time) turned down the notifications to approve the airdrops, they did not know that the bad actors had created fake approvals for these tokens, which victims thought they needed to (and did) revoke.

Revoke.cash, a web3 infrastructure, has cautioned token holders against reacting to such notifications, saying, “If you tried to revoke these fake approvals, you probably paid a very high fee, which went to the scammers.”

The wallet security firm said that the Multichain hackers programmed fake tokens to mint a lot of gas tokens during the victims’ revoke transactions, which were all sent to their own accounts. At this point, therefore, they could sell their exploit tokens. Notably, the transaction is not noticeable as “just a high gas fee.”

According to Revoke, the best way to avoid this exploit is to ignore them because they are innately programmed to charge a high fee when revoked.

Citing Revoke.cash, “The approve/revoke functionality is programmed into the token itself,” which means ignoring it is the only way to avoid falling victim. 

Instances of scams presented as airdrops have increased in the crypto sector, which is why token holders must exercise caution and avoid the temptation to click on links they are not familiar with.


Like this article? Help us with some feedback by answering this survey:

Author

Lockridge Okoth

Lockridge is a believer in the transformative power of crypto and the blockchain industry.

More from Lockridge Okoth
Share:

Editor's Picks

Crypto Today: Bitcoin at $60,000, Ethereum at $1,500, and XRP at $1 face a make-or-break test

Bitcoin (BTC), Ethereum (ETH), and Ripple (XRP) are trading in the red on Friday after three consecutive days of losses, testing their respective make-or-break support levels.

Bitcoin Weekly Forecast: BTC hits 20-month low, will the pain continue?

Bitcoin recovers slightly, trading at $66,000 on Friday after reaching a new yearly low of $58,115 earlier this week, its lowest level since October 2024. Institutional selling intensified as spot ETFs recorded $1.35 billion in net outflows through Thursday.

XRP clings to $1 as long liquidations deepen bearish trend

Ripple trades near the key psychological support level of $1 at the time of writing on Friday after losing more than 8% so far this week. CoinGlass liquidation data shows that over 97% XRP long positions were wiped out over the past 24 hours.

Pi Network Price Forecast: Minor recovery amid market crash fuels short-term hope

Pi Network price records a mild 3% recovery at press time on Friday, shaping a rebound from a broken descending trendline. The declining trend in trading volume has stabilized around $10 million this week, supporting the possibility of an extended recovery as selling pressure wanes.

Bitcoin: BTC hits 20-month low, will the pain continue?
Bitcoin (BTC) recovers slightly, trading at $66,000 on Friday after reaching a new yearly low of $58,115 earlier this week, its lowest level since October 2024. Institutional selling intensified as spot Exchange Traded Funds (ETFs) recorded $1.35 billion in net outflows through Thursday.