header-langage
简体中文
繁體中文
English
Tiếng Việt
한국어
日本語
ภาษาไทย
Türkçe
Scan to Download the APP

On-chain trading has recently been fraught with pitfalls, with scam links and malicious pools requiring caution.

Read this article in 5 Minutes
Someone was phished and lost $600,000.

Recently, jumping into dog coins has become noticeably riskier. We're used to the ups and downs, but the main thing is not to get scammed.

For example, clicking on phishing links.


Crypto KOLs @insidecalls and @cladzsol recently exposed that while scanning the chain daily, they opened a meme coin homepage and were greeted with a fake "Cloudflare verification" prompt from hackers, instructing them to press Ctrl+V, which was actually a malicious script. After following the prompt to "complete verification," the victims' on-chain funds were stolen. Among them, @cladzsol lost about $600,000 in assets.



BlockBeats found that on several recently popular meme coin display pages, their homepages all redirect to a "Cloudflare verification" page, which is actually a phishing link. If users follow the instructions, their computer systems will download and execute malicious scripts, leading to asset losses.


This phenomenon is now very common, likely due to delayed audits by mainstream trading aggregator platforms like DexScreener. Currently, the display logic of these platforms is: directly referencing the "official website" or social media links filled in the token metadata. These fields can be updated by the token creator or those later claiming "community takeover." Hackers are exploiting this audit loophole to turn meme coin display pages into new "fishing grounds" for phishing attacks.


Another example is the recently much-discussed Uniswap V4 pool issue.

Trading aggregator 0x released an analysis report titled "Uniswap v4 hooks were a mistake." They pulled 84,163 hooks across 6 chains for a health check, and the results were staggering: over half (54.2%) were malicious contracts, and another 26.4% were suspected malicious.

This maliciousness leads to retail investors losing money; buying $1,000 worth of coins might result in $200 going straight into these hook addresses, akin to MEV attacks.

So how can retail investors protect themselves?


Set Low Slippage


This is probably the best on-chain defense for retail investors. With low slippage, malicious hooks can't take a cut. Some low-market-cap coins might indeed not execute with low slippage, but for those with slightly larger market caps, it's worth paying attention.


Confirm the "Minimum Received Amount"


The estimated received amount is simulated off-chain, and in the face of malicious hooks, it can be an empty promise at any time.


To check the Minimum Received, if this number drops below your personal tolerance limit, it's best to cancel the transaction.


There are also some official suggestions from Uniswap, which are basically useless. They say to use the official Uniswap frontend because it has a hook whitelist, so malicious ones won't pass review, but who would trade using the crappy Uniswap frontend experience?


In short, everyone should pay more attention when trading. When the chain heats up, there will be many opportunities, but the principal is more important.


Welcome to join the official BlockBeats community:

Telegram Subscription Group: https://t.me/theblockbeats

Telegram Discussion Group: https://t.me/BlockBeats_App

Official Twitter Account: https://twitter.com/BlockBeatsAsia

举报 Correction/Report
Choose Library
Add Library
Cancel
Finish
Add Library
Visible to myself only
Public
Save
Correction/Report
Submit