Cointime

Download App
iOS & Android

How to Avoid Getting Hooked by Crypto ‘Ice Phishing’ Scammers: CertiK

Validated Project

Introduction

__Phishing is one of the popular methods scammers employ to steal victims assets. However, a type of phishing unique to the Web3 space, known as ice phishing, is a significant threat to the community. The practice was first outlined earlier this year by Microsoft in this blog. Instead of acquiring users' private keys and seed phrases, scammers instead trick victims into approving the transfer of assets to the scammers wallet. This method has been used to steal users tokens and NFTs worth millions of dollars. __

What is Ice Phishing?

Ice phishing is a type of attack that is exclusive to the Web3 world whereby a user is tricked into signing permissions allowing for a malicious actor to spend a user's tokens. This differs from traditional phishing attacks which aim to access confidential information such as private keys or passwords via social engineering. This makes ice phishing a considerable threat to Web3 investors since interacting with DeFi protocols requires you to grant permissions to interact.

The hacker just needs to make a user believe that the malicious address that they are granting approval to is legitimate. Once a user has approved permissions for the scammer to spend tokens, then the assets are at risk of being drained.

Ice Phishing On-chain

The first stage of an ice phishing attack occurs when the victim is tricked into approving an EOA or a malicious contract to spend tokens from the victim's wallet. We can see an example of this in the below transaction:

 Approval transaction. Source: Etherescan

The next phase occurs when the ice phishing address initiates a TransferFrom transaction which transfers tokens from the victim to an address that the ice phisher chooses. In the below example, USDT is transferred to 0x9ca3b…

 Transferfrom transaction. Source: Etherscan

We can see that the ice phisher (0x4632) initiates the transaction between the victim and the recipient. What is important to emphasize here is that the recipient address is not always the wallet that has ice phished you, it's the wallet that initiated the transaction. The ice phisher often sends users' funds to a second EOA that they control. You can see a transaction flow below:

 Ice Phishing Attack Flow. Source: CertiK

If you see a suspicious transaction in your wallet you need to check to see if the initiating EOA has been granted permissions to spend your tokens. You can check this for yourself on scan sites such as Etherscan or Debank.

 Wallet contract approvals as found on Etherscan. Source: Etherscan

If you see an address that you don’t recognize, or one that has initiated transactions without your approval then you should revoke permissions. You can do this by visiting sites like revoke.cash or connecting your wallet to the scan site to revoke.

  1. Here is how you revoke permissions on scan sites such as Etherscan.
  2. Visit https://etherscan.io/tokenapprovalchecker and search for your wallet
  3. Connect your wallet
  4. Hit the ERC-20, ERC-721 or ERC-1155 tabs and find the address you wish to revoke.
  5. Click the revoke button.

Could This Address be an Ice Phish?

The first indicators that a user is at risk of becoming a victim of ice phishing will be apparent in the URL or dApp that they are viewing. Malicious sites will either mimic a legitimate project's page, or display fake partnerships with legitimate companies. We often see scam sites using the CertiK logo showing a fake audit or fake partnership. Below is an example of one of the many fake mining pools that uses CertiK’s logo and other legitimate companies to create a sense of trustworthiness.

 Fake mining URL. Source: CertiK Investigations.

When signing approvals on this site, you are allowing a malicious EOA to spend an unlimited amount of USDT from your wallet. This essentially means that all USDT that you own is at risk.

 MetaMask Approval Prompt: Source MetaMask

In this instance, by checking certik.com you’d discover that the above site is not a partner of CertiK. If you wanted to double check, you can reach out to CertiK’s incident response team by clicking on “Report an Incident” on our website.

 Users can file a report on malicious contracts on certik.com

There are some on-chain checks that you can do yourself as part of your own research. You can take the address presented to you on the dApp or URL that you’re interacting with and search for it on scan sites such as Etherscan for suspicious activity. For example, we detected suspicious ice phishing activity on EOA 0x13a…5dE49 which we found was funded by Tornado Cash withdrawals.

 Tornado Cash Withdrawals. Source: Etherescan

Upon further investigation, we see that 0x13a…5dE49 targeted the Pulse community with a key community member warning users of the dangers of ice phishing.

 Warning members of Pulse community. Source: Twitter

By investigating some of the victim wallets and the complaints on social media, we found a fake Maximus DAO Twitter page which was likely related to the ice phishing wallets.

How to Protect Yourself

The easiest way to prevent yourself from becoming a victim of ice phishing is by going to trusted sites such as Coinmarketcap.com, coingecko.com, and certik.com to verify official sites. Many ice phishing scams can be found on social media such as Twitter, where fake profiles are disguising themselves as legitimate projects and promoting fake airdrops as an example. To gain attention, Twitter accounts are often tagged by bots in these fake accounts posts.

In the below example, we can see a fake Optimism Twitter account promoting a phishing URL. A simple check on CoinMarketCap or Coingecko would display the legitimate site.

 Fake Optimism Twitter account. Source: @CertikAlert

Always take a moment to verify if the URL or dApp that you are interacting with is legitimate. If you are not sure, double check by visiting trusted sources.

Conclusion

Ice phishing is one of the most common types of scams that we see in the Web3 space with users sometimes unaware that they are compromised since they haven’t given away any confidential information. It is always worth taking that extra minute to double check the URL that you’re interacting with is verified by a trusted source, in addition to on-chain checks you can do as part of your own research. CertiK’s incident response team is available 24/7 to help you spot these types of scams. You can can reach out to us via Telegram, Discord, or by submitting a report via certik.com.

Comments

All Comments

Recommended for you

  • U.S. Spot Bitcoin ETF On-Chain Holdings Exceed 2 Million BTC

    As of October 11, data from Dune shows that the on-chain total holdings of the U.S. spot Bitcoin ETF have surpassed 2 million BTC, currently reaching approximately 2.013 million BTC, which accounts for 10.02% of the current BTC supply. The value of the on-chain holdings has reached approximately $227.6 billion.

  • Hedge Fund Net Exposure to US Tech Giants Reaches Record High of 22%

    On October 10, according to data from Goldman Sachs and The Kobeissi Letter, investor sentiment towards large tech stocks has reached an all-time high. Hedge fund net exposure to the 'Big Seven' tech giants in the US has risen to 22%, marking a historic peak; this figure has surged by 7 percentage points since July, representing the largest three-month increase in 2023, and surpassing the previous high of 21% set in June 2024 (compared to only 8% during the bear market low in 2022). During the same period, hedge fund net exposure to semiconductor stocks in the US has increased to 12%, slightly below the peak of 14% in June 2026, while this metric was only 2% at the beginning of 2025.

  • Anthropic Reveals Internal Issues: Out-of-Control AI Attempted to Access Multiple Government Websites, Reported to the White House

    Anthropic stated on Friday that its AI agents acted autonomously, attempting to access various federal, state, and local government websites. The company did not disclose which government agencies were involved but confirmed that it has reported these incidents to the White House. In a blog post, Anthropic mentioned that one of its AI models under testing had taken several unauthorized actions, including exploiting a vulnerability on a university website to download data and submitting a form to a government agency that it had been explicitly instructed not to submit. The company noted that it discovered these incidents after beginning a review of the AI's actions in July. Earlier on Friday, the Philadelphia Police Department stated that Anthropic had notified them that its technology had submitted a false homicide tip to the police website.

  • No Flights Departing or Arriving at Riyadh's King Khalid Airport Following Explosion Sounds

    On October 10, according to CCTV International News, witnesses reported that explosion sounds were heard at Terminal 3 of King Khalid International Airport in Riyadh, the capital of Saudi Arabia, this afternoon, leading to the evacuation of personnel from the airport. Flight tracking website 'FlightRadar24' indicates that there are currently no flights departing or arriving at the airport, and some flights heading to Riyadh have been diverted or returned. King Khalid International Airport has issued a traveler advisory, recommending that passengers contact their airlines to confirm flight status before heading to the airport.

  • BTC Surpasses $83,000

    Market data shows that BTC has surpassed $83,000, currently priced at $83,020.19, with a 24-hour decline of 0.2%. The market is experiencing significant fluctuations, so please ensure proper risk management.

  • ETH Surpasses $2500

    Market data shows that ETH has surpassed $2500, currently priced at $2500.03, with a 24-hour increase of 0.33%. The market is experiencing significant fluctuations, so please ensure proper risk management.

  • Houthi Forces Claim Saudi Airstrikes on Sana'a Airport in Yemen

    On October 10, according to information released by the Houthi forces in Yemen, on the afternoon of the same day local time, the Saudi-led coalition conducted airstrikes on Sana'a International Airport, which is under the control of the Houthi forces, dropping four bombs. Additionally, the Saudi coalition also targeted a communication facility in Hajjah Province, controlled by the Houthi forces, dropping three bombs. There has been no response from the Saudi side regarding these incidents. (Jinshi)

  • French Finance Committee Approves Amendments on Stablecoin Exchange Tax and Crypto Exit Tax

    On October 10, Decrypt reported that the Finance Committee of the French National Assembly approved two amendments related to cryptocurrency taxation this week: starting January 1, 2027, exchanges of stablecoins regulated under MiCA will be considered taxable sales; and an exit tax will be imposed on taxpayers who have been French tax residents for at least six of the past ten years and have moved abroad with crypto assets totaling over 800,000 euros. On October 9, the committee voted 31 to 3 to reject the budget revenue portion, and the full National Assembly will review based on the government's original text. The amendments will not be automatically included; supporters must reintroduce them during the debate starting on October 13, with a formal vote scheduled for October 20. The related measures have not yet become law. The stablecoin amendment was proposed by Nicolas Sansu, a member of the left-wing GDR party group, along with 16 co-signers, and does not set a new tax rate but aims to include the revenue under France's existing 31.4% flat tax system. The committee also passed an amendment allowing crypto asset losses to be carried forward for ten years to offset future gains.

  • Luxshare Precision: Company and Luxshare Technology Involved in 337 Investigation, Currently in Initial Filing Stage

    On October 10, Luxshare Precision announced that the company and its holding subsidiary, Dongguan Luxshare Technology Co., Ltd., have been listed as respondents in a 337 investigation by the U.S. International Trade Commission (ITC), involving U.S. Patent US 10,903,700. The ITC officially launched the investigation on October 9, 2026, with investigation number 337-TA-1526. The case is currently in the initial filing stage, and no substantial determination has been made regarding the relevant infringement claims. The products involved are in the customer verification stage and have not yet entered mass production.

  • South Korea's Financial Commission: Shareholding Restrictions for Exchange Major Shareholders Not Targeting Specific Companies

    On October 10, Lee Ik-yeon, chairman of the Financial Services Commission of South Korea, stated that the provisions regarding shareholding restrictions for major shareholders of virtual asset exchanges in the ongoing 'Basic Law on Digital Assets' are not aimed at specific individuals or companies. Instead, they are designed to ensure that exchanges, once institutionalized, bear a higher level of public responsibility. Currently, South Korean virtual asset exchanges operate under a system that requires updates every three years, but this will transition to a licensing system after the implementation of the 'Basic Law on Digital Assets.' Lee emphasized that exchanges have infrastructure attributes and must possess public accountability and responsibility commensurate with their status.