forta-network / starter-kits

MIT License
62 stars 37 forks source link

'Claim' phishing - FN #622

Open Ivan1905 opened 4 months ago

Ivan1905 commented 4 months ago

Hi there,

Do we know why we haven't detected the following attack? tx: https://etherscan.io/tx/0x54dfe8e6161bb0c4d7341290694a0f10ba3bc546702f72adcbb88fc0275cf65b

I have not seen a label for 0xa4b1FBcf5A4423ae1653a2540588d7227175EA7B which is the contract that is invoking when loosing the funds.

Thanks!

Ivan1905 commented 4 months ago

here's another one odd from pink drainer.

Here the approval: https://etherscan.io/tx/0xf5d6c94e733c2ac71366e6fbc448415cb94523f13219052394fbbdbb193953b2

Right after there was a steal here: https://etherscan.io/tx/0xb1b0878c968171fd6b61c3fd281c8bb1f3f43bfb066ccf472af21459b9d7afc6

A few hours later a drain for 10 wbtc here: https://etherscan.io/tx/0x2eaa1a9643bf3505aa757c9f225431286cb1647257bb9548f1f22d2dd246e28d

Do you believe this was because of the unlimited approval of the victim? and then the victim decided to withdraw from maker tx here and that was the chance for the drainer to drain again? In any case I am not seeing a TP for the approved EOA

Ivan1905 commented 4 months ago

Here another one from a drainer:

https://etherscan.io/address/0x47003d6009cb10947d36064376114c457dc78329

I believe we have a FN for the contract.