news

$12M Lost to Phishing in August Marks Sharp Rise in Crypto Scams

Nahid
Published: September 8, 2025
4 min read
$12M Lost to Phishing in August Marks Sharp Rise in Crypto Scams

STAY UPDATED WITH COTI

Follow COTI across social media platforms to get the latest news, updates and community discussions.

Facebook
Instagram
LinkedIn
YouTube

TL;DR

  • Investors lost $12.17 million to phishing attacks in August, up 72% from July's $7.09 million.
  • 15,230 victims were affected, a 67% increase in cases.
  • Crypto whales bore the brunt: three incidents drained $5.62 million (46% of total losses).
  • A new wave of scams linked to Ethereum's EIP-7702 upgrade has made phishing harder to detect.
  • Experts warn retail users and institutions alike to stay vigilant as phishing tactics evolve.

Phishing isn't new in crypto, but August 2025 saw a steep rise that has alarmed industry watchers. According to a report from blockchain security firm Scam Sniffer, crypto users lost a combined $12.17 million to phishing scams last month. That figure marks a 72% increase from July's $7.09 million in reported losses.

In terms of victims, Scam Sniffer counted 15,230 unique addresses impacted in August, up from 9,143 in July - a 67% month-over-month increase. The firm shared its findings in an X post on September 6, warning that the trend signals more sophisticated phishing campaigns taking root.

What Exactly is Phishing in Crypto?

For readers outside the security trenches, phishing in crypto often works like this:

  1. Hackers set up fake websites or malicious contracts that look identical to legitimate platforms.
  2. Users are tricked into entering their wallet details, signing malicious approvals, or clicking deceptive prompts.
  3. Once approved, funds are immediately drained to attacker-controlled wallets.

Unlike traditional finance, these transfers are irreversible. The appeal for attackers is obvious: with one well-crafted trick, they can siphon off millions in seconds.

Whales Take the Biggest Hit

While phishing attacks hit retail investors daily, August's data highlights a worrying trend: crypto whales are increasingly being targeted.

Source: ScamSniffer

Scam Sniffer's report shows that the top three single incidents drained:

  • $3.08 million
  • $1.54 million
  • $1.00 million

Together, these cases account for $5.62 million, or 46% of all phishing losses in August. This concentration suggests attackers are designing highly tailored traps for wallets holding large sums. Whether through private negotiations, fake OTC offers, or custom contracts disguised as legitimate tools, whales are in the crosshairs like never before.

The New Threat: EIP-7702 Exploits

Adding to the danger is a new attack vector tied to Ethereum's EIP-7702 upgrade. The proposal temporarily allows externally owned addresses (EOAs) - regular user wallets to function like smart contract wallets. This enables useful features like:

  • batching multiple transactions
  • automated spending limits
  • passkey integration

But hackers have found ways to abuse it. By bundling malicious transactions with legitimate requests, attackers trick users into authorizing batch signatures they don't fully understand. Because the transactions look like standard Ethereum activity, they're much harder to detect compared to classic phishing links. For retail users, this could feel like being robbed in broad daylight - everything looks normal until it's too late.

Lessons for Users

So what can everyday investors do? Security experts recommend a few simple but powerful precautions:

  • Double-check URLs - Never click links from DMs or unknown emails. Always verify you're on the official site.
  • Use hardware wallets - These require physical confirmation before signing, making scams harder to execute.
  • Limit approvals - Revoke unnecessary token allowances using tools like Revoke.cash.
  • Be skeptical of urgency - If a site or contact pressures you to act quickly, it's often a red flag.

As phishing grows more sophisticated, education and vigilance remain the strongest defense.

Final Thought

August's numbers are a stark reminder: phishing isn't fading - it's evolving. The rise of batch-signature exploits, the growing focus on whales, and the sheer scale of losses show attackers are innovating just as fast as the industry.

For Web3 to fulfill its promise, security must become a shared responsibility. That means better tools, smarter defaults, and constant user education. Until then, the $12 million lost in August may be just the start of a much larger trend.

 

About the Project


About the Author

Nahid

Nahid

Based in Bangladesh but far from boxed in, Nahid has been deep in the crypto trenches for over four years. While most around him were still figuring out Web2, he was already writing about Web3, decentralized protocols, and Layer 2s. At CotiNews, Nahid translates bleeding-edge blockchain innovation into stories anyone can understand — proving every day that geography doesn’t define genius.

Disclaimer

The views and opinions expressed in this article are those of the authors and do not necessarily reflect the official stance of CotiNews or the COTI ecosystem. All content published on CotiNews is for informational and educational purposes only and should not be construed as financial, investment, legal, or technological advice. CotiNews is an independent publication and is not affiliated with coti.io, coti.foundation or its team. While we strive for accuracy, we do not guarantee the completeness or reliability of the information presented. Readers are strongly encouraged to do their own research (DYOR) before making any decisions based on the content provided. For corrections, feedback, or content takedown requests, please reach out to us at

contact@coti.news

Stay Ahead of the Chain

Subscribe to the CotiNews newsletter for weekly updates on COTI V2, ecosystem developments, builder insights, and deep dives into privacy tech and industry.
No spam. Just the alpha straight to your inbox.

We care about the protection of your data. Read our Privacy Policy.