Two separate crypto thefts highlighted how small user actions can open the door to large losses. In one case, a wallet user lost about $305,000 in DAI after sending funds to a deceptive address that closely resembled the intended recipient. In the other, a victim lost $167,342 in LINK after signing a malicious Permit2 approval on Ethereum.

Together, the two incidents account for more than $472,000 in losses. Security researchers cited the cases as examples of two recurring risks in onchain activity: copying wallet addresses from transaction history and approving signatures without fully understanding what access they grant.

Address poisoning led to a $305,000 DAI loss

GoPlus Security reported that the larger of the two losses came from an address poisoning, or address substitution, attack. According to the firm, the attacker first sent a tiny transfer, often described as dust, from an address designed to look almost identical to a legitimate destination.

The intended recipient address was 0x085adc…18f1dd, while the attacker used the lookalike address 0x085ccc…18f1dd. After the dust transfer appeared in the victim’s transaction history, the user reportedly copied the misleading address and sent roughly $305,000 in DAI to the attacker instead of the real recipient.

GoPlus said this kind of campaign can be highly automated. That can include identifying targets, creating cloned tokens with the same names, sending deceptive micro-transfers, and then laundering funds through mixers.

Permit2 signature was later used to drain LINK

A second case involved a different attack path but the same end result: direct access to a user’s assets. Scam Sniffer reported that a victim lost $167,342 in LINK after signing a malicious Permit2 approval on Ethereum.

The approval was signed on August 18, 2025, but the attackers did not move the assets until October 3 of the following year. The delayed transfer underscores a key danger with token approvals and signatures: a harmful permission may remain in place long after the user has forgotten about the transaction that created it.

Analysts cited in the report said the case shows how users can unknowingly authorize malicious access when interacting with Permit2-based requests.

Why these attacks are difficult to spot

Both incidents relied on details that can be easy to miss during routine wallet use. In address poisoning, the trap is visual similarity: the false address shares the same beginning and ending characters as the real one, making it look familiar in a wallet history list. In the Permit2 case, the danger came from signing a message that appeared to be a normal approval but actually granted attackers the ability to move tokens later.

Because the mechanics differ, the warning signs also differ. One risk emerges when a user copies an address from past activity rather than from a trusted source. The other appears when a wallet asks for a signature or token approval and the exact permissions are not clearly understood.

Recommended precautions and the next step

The source report said users should avoid copying destination addresses from transaction history and should verify the full wallet address before sending funds. It also recommended making a small test transaction before transferring a significant amount.

For approval-based threats, analysts said clearer warnings during transactions and message signing could help reduce similar losses. Based on the incidents described, the immediate confirmed takeaway is not a protocol change or recovery action, but a renewed emphasis on address verification and caution around signing requests that can authorize future asset transfers.

Source: incrypted.com