|

Gas tokens, wallet security warns against interacting with strange tokens amid Multichain exploit delirium

  • Wallet security Revoke.cash urges investors to ignore tokens they don’t recognize.
  • The caution comes amid a new discovery that scammers use gas tokens to steal money when victims revoke the fake approvals.
  • The alert comes amid the infamous Multicahin exploit across Fantom, Moonriver, and Dogecoin bridges.

Gas tokens have become the new loophole that hackers exploit to steal money from unsuspecting token holders. The discovery aligns with the recent attack on cross-chain router Multichain.org which saw the threat actors make away with upwards of $130 million in user-supplied tokens.

Also Read:  Fantom trading volume falls 20% as Multichain hackers leverage FTM tokens in a new attack on Twitter

Gas tokens, a new tactic among scammers

Gas tokens could see you lose money without seeing it coming. The news comes after several reports of token holders noticing strange approval notifications on their transaction history even though they had denied the transactions.

Gas tokens are typically cryptocurrencies designed to pay transaction processing fees. Notably, for every transaction, a nominal fee is paid as a transaction charge. A recent discovery has indicated that scammers now leverage this principle to enrich themselves at the expense of innocent cryptocurrency investors.

The gas tokens concept traces back several years ago to mitigate high Ethereum (ETH) blockchain transaction fees. It works by leveraging an Ethereum Virtual Machine (EVM) feature where users get some form of discount when clearing storage. Specifically, “users could mint gas tokens when fees were low, and burn them when fees were high.” Effectively, they enjoy the reduced fees as an unintended result of storage gas refunds.

Gas tokens leveraged by Multichain hackers

Multichain hackers capitalized on gas tokens to execute their recent attack, creating fake tokens for airdrops and advertising them to the unsuspecting Fantom (FTM) and Dogecoin (DOGE) holders.

Here’s the catch! While the victims (unsuspecting token holders at the time) turned down the notifications to approve the airdrops, they did not know that the bad actors had created fake approvals for these tokens, which victims thought they needed to (and did) revoke.

Revoke.cash, a web3 infrastructure, has cautioned token holders against reacting to such notifications, saying, “If you tried to revoke these fake approvals, you probably paid a very high fee, which went to the scammers.”

The wallet security firm said that the Multichain hackers programmed fake tokens to mint a lot of gas tokens during the victims’ revoke transactions, which were all sent to their own accounts. At this point, therefore, they could sell their exploit tokens. Notably, the transaction is not noticeable as “just a high gas fee.”

According to Revoke, the best way to avoid this exploit is to ignore them because they are innately programmed to charge a high fee when revoked.

Citing Revoke.cash, “The approve/revoke functionality is programmed into the token itself,” which means ignoring it is the only way to avoid falling victim. 

Instances of scams presented as airdrops have increased in the crypto sector, which is why token holders must exercise caution and avoid the temptation to click on links they are not familiar with.


Like this article? Help us with some feedback by answering this survey:

Author

Lockridge Okoth

Lockridge is a believer in the transformative power of crypto and the blockchain industry.

More from Lockridge Okoth
Share:

Editor's Picks

Dash Price Forecast: DASH defies headwinds, paces toward $100

Dash extends its rally, reaching an intraday high of $96.85 despite the broader crypto market correcting. Retail interest in DASH explodes as futures Open Interest soars to $165 million.

XRP slides below 50-day EMA as selling pressure intensifies

Ripple is edging lower toward the pivotal $2.00 level at the time of writing on Friday, marking three consecutive days of declines. The sell-off extends across the crypto market, with Bitcoin falling toward $95,000 and Ethereum pressing down on support at $3,300.

Pi Network consolidates as momentum shift flashes downside risk

Pi Network (PI) is trading near the $0.2000 psychological support level at press time on Friday, extending its nearly month-long consolidation. Large deposits over centralized exchanges accepting PI tokens suggest a sell-side bias among holders.

Crypto Today: Bitcoin, Ethereum, XRP hold support amid waning retail demand

Bitcoin slips but holds above $95,000, weighed down by declining retail demand. Ethereum trades narrowly between the 100-day EMA support and the 200-day EMA resistance.

Orange Juice Newsletter – Smart insights by real people. Every day.

A free newsletter highlighting key market trends to help traders stay a step ahead. Daily insights on the most relevant trading topics, compiled by our experts in an easy-to-read format so you never miss an important move.

Bitcoin: BTC bulls remain strong amid institutional demand, risk-on sentiment improves

Bitcoin (BTC) price holds above $95,500 at the time of writing on Friday after rallying more than so far 5% this week. The rising institutional and corporate demand supports the bullish price action in BTC.