
A recent incident has highlighted the growing sophistication of phishing attacks in the cryptocurrency space. An investor lost a total of $2.6 million in stablecoins after falling victim to two separate zero-value transfer phishing scams within a mere three-hour window. This method, which exploits token transfer functions to trick users into sending real funds to attackers, is an advanced form of address poisoning. In this case, the victim sent 843,000 USDT initially and another 1.75 million USDT shortly thereafter, both to addresses that appeared legitimate due to prior zero-value transfers.
🚨ALERT🚨Our system has detected~2.6M $USDT loss from a targeted address poisoning scam involving zero-value transfers. A single victim was repeatedly scammed by the same attacker address.
First, the victim lost 843K $USDT.
⏳ About 3 hours later, the same victim sent 1.75M… pic.twitter.com/WWVlrZvavK— 🚨 Cyvers Alerts 🚨 (@CyversAlerts) May 26, 2025
Zero-value transfers are particularly deceptive because they do not require the victim’s private key to execute. Instead, they involve transferring zero tokens to a spoofed address, which then appears in the victim’s transaction history. Users often mistakenly trust these addresses and inadvertently send real funds to them in future transactions. This tactic has been responsible for significant losses in the past, including a notable incident where $20 million worth of USDT was stolen before the address was blacklisted.
The rise of such phishing schemes underscores the importance of vigilance and caution in the crypto community. Users are advised to double-check recipient addresses, avoid relying solely on transaction histories, and be wary of unsolicited communications that prompt them to send funds. As the methods employed by scammers become more sophisticated, staying informed and cautious is crucial to safeguarding digital assets.
Get the weekly commit
New blockchain deep dives every week.

