📈 Get daily crypto insights that make you smarter about your money

CREATE2 Phishing Drains $2.34 Million in SUPER Tokens as Wallet Drainers Escalate

A cryptocurrency investor lost $2.34 million worth of SUPER tokens on January 27, 2024, in a phishing attack that leveraged the Ethereum CREATE2 opcode to bypass wallet security mechanisms. The incident, flagged by Scam Sniffer, represents one of the largest single-wallet thefts of the month and underscores the growing sophistication of Wallet Drainer toolkits targeting the crypto ecosystem.

The Threat Landscape

The January 2024 phishing landscape reached alarming proportions, with more than $58 million stolen through Twitter-based phishing schemes alone during the month. Wallet Drainer malware — malicious software deployed on fraudulent websites that tricks users into authorizing harmful transactions — has evolved from rudimentary social engineering into a highly technical operation exploiting Ethereum’s underlying architecture.

According to Scam Sniffer’s annual report, Wallet Drainers stole $295 million from approximately 324,000 victims throughout 2023. The SUPER token heist on January 27 demonstrates that this trend is accelerating rather than abating. The victim, operating from wallet address ending in d6a29cd83c, unknowingly authorized an “increaseAllowance” transaction that granted the scammer full access to their SUPER token holdings.

Core Principles

Understanding how the CREATE2 opcode enables these attacks is essential for every crypto user. CREATE2 is an Ethereum opcode that allows smart contracts to pre-determine the address of a yet-to-be-deployed contract. Legitimate uses include deterministic contract addresses for DeFi protocols and layer-2 infrastructure. However, scammers weaponize CREATE2 to generate fresh, seemingly legitimate contract addresses for each phishing attempt.

The attack typically follows a pattern: a user encounters a fraudulent website, often promoted through compromised social media accounts or fake airdrop announcements. The site prompts the user to connect their wallet and approve a transaction. Because the scammer’s contract address is freshly generated using CREATE2, it has no history of malicious activity and may not be flagged by wallet security extensions. Once the user signs the transaction, the scammer gains approval to transfer tokens from the victim’s wallet.

Tooling and Setup

Protecting against CREATE2-based phishing requires a multi-layered security approach. First, install a reputable wallet security extension such as Scam Sniffer, which maintains databases of known malicious addresses and can detect suspicious transaction patterns in real time. These extensions analyze transaction calldata and flag potentially dangerous approvals before you sign them.

Hardware wallets provide an additional layer of protection by requiring physical confirmation of transaction details. Even if a phishing site tricks you into initiating a malicious transaction, the hardware wallet display shows the actual contract interaction, giving you a chance to abort before confirming. Ledger and Trezor devices remain the industry standard for this purpose.

Token allowance management tools like Revoke.cash or Unrekt allow you to review and revoke existing token approvals. Regularly auditing your approved contracts reduces the attack surface even if a phishing attempt initially succeeds. Make it a habit to revoke approvals after each DeFi interaction.

Ongoing Vigilance

The SUPER token theft coincided with a 20% price drop in the token, demonstrating how phishing incidents can amplify market impact. With Bitcoin holding near $42,120 and Ethereum around $2,267 in late January 2024, the crypto market’s recovery attracted new users who may lack experience identifying phishing attempts. Attackers exploit this knowledge gap by timing campaigns around market rallies and major protocol events.

Phishing campaigns frequently coincide with airdrops and exchange listings, when users expect legitimate token-related communications and are more likely to click links without verifying. The Arbitrum Discord breach on March 24, 2023, and the fraudulent Circle websites that exploited USDC exchange rate volatility are prime examples of event-driven phishing campaigns.

Final Takeaway

The $2.34 million SUPER token theft is not an isolated incident — it is part of a systemic escalation in crypto phishing operations. Wallet Drainer toolkits are now available as services, lowering the barrier to entry for would-be scammers. Every transaction you sign is a potential point of failure. Verify the contract address, understand what you are approving, use hardware wallets for significant holdings, and maintain a healthy skepticism toward unsolicited links and airdrop offers. The few seconds spent verifying a transaction can save you millions.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Always conduct your own research and use appropriate security measures when interacting with cryptocurrency platforms.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

23 thoughts on “CREATE2 Phishing Drains $2.34 Million in SUPER Tokens as Wallet Drainers Escalate”

  1. CREATE2 pre-computing the contract address so metamask shows empty state is genius exploitation. the EVM working as designed and thats the scariest part

  2. $2.34M in SUPER tokens gone because of CREATE2. the scary part is the approval transaction looked completely normal in metamask. no way a casual user catches that

    1. the increase allowance trick is the oldest one in the book. metamask really needs better UI for showing what youre actually approving, not just the gas fee

    2. the CREATE2 trick pre-generates the contract address so metamask shows zero code change. literally invisible unless you check the bytecode manually

      1. audit_trail_ the scary part is CREATE2 is working as designed. you cant patch legitimate EVM functionality without breaking contract deployment entirely

      2. CREATE2 predetermines the contract address before deployment so metamask shows a clean audit on a clone. brilliant exploit of working as designed

      3. calldata_nerd_

        audit_trail_ the bytecode diff thing is the real issue. metamask shows you a clean simulation because CREATE2 deploys to a pre-computed address. your hardware wallet says looks good and your tokens are gone

        1. calldata_nerd_ hardware wallets show the approval target address but not the bytecode being deployed. ledger and trezor need to add contract simulation previews

        2. bytecode_diff_

          calldata_nerd_ metamask simulating a clean transaction because CREATE2 pre-computes the address is the scariest part. your hardware wallet literally cannot detect this. the signing device says all clear

      4. audit_trail_ the scary part is CREATE2 is working as designed. the exploit uses legitimate EVM functionality. you cant patch this without changing the spec itself

        1. opcode_scan is right, you literally cannot patch CREATE2 without breaking contract deployment. the fix is wallet UI showing bytecode diffs not protocol changes

  3. $58M from twitter phishing in one month while verified accounts run scam ads. elon really turned the blue check into a drainer hunting license

  4. 295 million stolen from 324K victims in 2023 via wallet drainers alone. thats almost $1000 per victim on average. these operations are industrial scale now

    1. meta_mask_quitter

      Olga Petrova $295M from 324K victims averages to about $910 per person. these drainer kits are operating at industrial scale and twitter still runs their ads

    2. and those are just reported losses. probably double that when you count people too embarrassed to admit they got phished

  5. $58M stolen through twitter phishing in january 2024 alone. at some point the platform has to take responsibility for verified scam accounts running sponsored posts

    1. rug_sweeper twitter charges for scam ads, profits from them, then charges for verified checkmarks that make the scams look legit. the business model is the problem

      1. bytecode_check_ twitter verified checkmarks cost $8 and add zero security. the platform literally charges scammers for legitimacy

    2. rug_sweeper $58M in a month from twitter phishing and the platform still hasnt implemented basic scam link detection. the ad revenue from verified scammers is apparently worth more than user safety

      1. tweet_watch twitter makes ad revenue from promoted scam posts, blue checks make scams look legit, and reporting does nothing. the incentive structure is perfectly aligned for drainers

      2. etherscan_watcher_

        tweet_watch 58M from twitter phishing in one month and the blue check system makes scams look legitimate. paying for verification then using it to run drainer ads is a broken incentive structure

  6. 2.34M in SUPER tokens. not even a top 100 coin. these drainer operations are scanning every token with liquidity and targeting bag holders specifically

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$63,868.00-2.0%ETH$1,872.77-2.5%SOL$75.80-1.7%BNB$599.93-1.3%XRP$1.02-2.2%ADA$0.1931-2.2%DOGE$0.0697-1.1%DOT$0.8020-0.6%AVAX$6.46-1.4%LINK$8.23-1.0%UNI$3.92-3.2%ATOM$1.41+2.3%LTC$44.99-2.5%ARB$0.0801+2.2%NEAR$1.60-2.1%FIL$0.7021-0.9%SUI$0.6895-1.2%BTC$63,868.00-2.0%ETH$1,872.77-2.5%SOL$75.80-1.7%BNB$599.93-1.3%XRP$1.02-2.2%ADA$0.1931-2.2%DOGE$0.0697-1.1%DOT$0.8020-0.6%AVAX$6.46-1.4%LINK$8.23-1.0%UNI$3.92-3.2%ATOM$1.41+2.3%LTC$44.99-2.5%ARB$0.0801+2.2%NEAR$1.60-2.1%FIL$0.7021-0.9%SUI$0.6895-1.2%
Scroll to Top