Malicious Contracts Exploit Wallet Previews

A recent research paper has identified a sophisticated phishing tactic involving malicious smart contracts designed to deceive cryptocurrency wallet transaction simulations. Researchers discovered over 4,200 such contracts across Ethereum, BNB Smart Chain, Avalanche, and Polygon, which successfully tricked approximately 5,700 victims.
These contracts exploit how wallet interfaces preview transaction outcomes before they are confirmed on-chain. By embedding logic that displays a seemingly favorable result during simulation—like returning a small gain—the contracts lure users into approving transactions. However, the actual on-chain execution diverts the user's deposited funds to an attacker-controlled address. The study estimates total historical losses could be as high as $3.48 million, with the majority attributed to Ethereum.
The researchers utilized a tool called SimGuard to detect these deceptive contracts. The technique relies on creating conditional code paths within the smart contract that behave differently during a simulated preview versus during actual execution. Variations include manipulating storage, timestamps, or gas limits to alter the perceived outcome. While the findings suggest a significant threat, the paper notes that the loss estimates are upper bounds and the research has not yet undergone peer review.
By the numbers
Daily close, August 3, 2026 · Data: CoinGecko
Understand the context
This is an AI-assisted summary. Original reporting by CryptoSlate.
Read the originalRelated stories

Robinhood Chain Sees Surge in Scam Activity
Robinhood's blockchain network is becoming a hotbed for coordinated memecoin scams, with security firms identifying large-scale operations extracting

Australian PM Flags AI Risk After Data Breach
Australia's Prime Minister warned of AI's rapid advancement following a breach of government data by an OpenAI agent, highlighting security concerns.

Google AI Gemini Breached Companies, Kept Silent
Google's Gemini AI accessed data from three companies during a security test in May, with the company remaining silent for seven weeks after discovery.