Gunjo · Business Intelligence for the AI Era
← Sticker Wall SCAM · DETAIL

Fake Cross-Chain Bridge Security Audit Test Scam: Inducing Wallet Approvals via Part-Time Testing to Steal Tens of Millions of Dollars

The primary victims include cryptocurrency holders with technical backgrounds, Web3 developers, and security auditors looking for part-time opportunities. While typically knowledgeable about smart contracts and cross-chain technology, they are susceptible to psychological desires for high-paying freelance work and proof of technical capability, making them vulnerable to security testing and audit task pitches in fake job offers. Eager to secure audit contracts or career opportunities with prominent Web3 projects, victims let down their guard when asked to test a new cross-chain bridge's security features, actively connecting their wallets and granting approvals, ultimately leading to massive asset theft that is difficult to recover.

SCAM

Key Fields

FIELD STAMPS
IndustryFintech
RegionGlobal
ScaleGray Market
ChannelOther
⚠️ This entry compiles scam tactics and public reporting; it is not investment or legal advice. Content is organized from public reporting and third-party complaint platforms; this site does not make any finding of illegality against the parties involved, who may contact us for correction if they object. If you encounter fraud, report it to the police immediately (110 / anti-fraud hotline 96110 in mainland China; local police overseas).

Who Gets Targeted

The primary victims include cryptocurrency holders with technical backgrounds, Web3 developers, and security auditors looking for part-time opportunities. While typically knowledgeable about smart contracts and cross-chain technology, they are susceptible to psychological desires for high-paying freelance work and proof of technical capability, making them vulnerable to security testing and audit task pitches in fake job offers. Eager to secure audit contracts or career opportunities with prominent Web3 projects, victims let down their guard when asked to test a new cross-chain bridge's security features, actively connecting their wallets and granting approvals, ultimately leading to massive asset theft that is difficult to recover.

骗局怎么运作

  • Hackers first pose as human resources or technical recruiters for well-known Web3 projects in crypto communities such as Discord and Telegram, or job platforms like Telegram, posting high-paying positions for security audit engineers or cross-chain bridge testers to hook job seekers and build initial trust.
  • After filtering targets, attackers send a seemingly professional cross-chain bridge security audit task document, instructing victims to interact with a designated testnet or frontend. This frontend is typically a phishing site that completely mimics a genuine cross-chain bridge interface, with a domain name differing from the official site by only the subtlest letter variations.
  • During the testing process, victims are guided to connect their crypto wallets and requested to grant approvals to a so-called security testing smart contract. In reality, this contract contains concealed unlimited approval or malicious transfer logic, allowing users to unconsciously cede asset control to the attackers while falling under silent backdoor monitoring.
  • Once the user signs the approval transaction, the attackers immediately trigger the contract's permission calls via the backend, instantly draining stablecoins or other high-value tokens from the user's wallet and rapidly laundering them through cross-chain bridges to mixers or decentralized exchanges, completely severing the on-chain tracking chain.
  • Some advanced attackers also leverage victim wallet permissions as a springboard to forge cross-chain messages, stealing additional funds and even shifting risks to mainstream lending protocols like Aave, expanding the attack surface and triggering cascading liquidations, delivering a devastating blow to victims and the entire crypto ecosystem.
  • Upon success, hackers immediately delete all chat logs, dissolve fake recruitment groups, and shut down the phishing frontend, leaving victims with zero leads while continuing to use acquired credentials or approvals to hunt for the next target, forming a sustainable, high-tech cybercrime closed loop.

红旗信号(看到这些快跑)

  • 🚩 Recruiters proactively send high-paying Web3 security audit or cross-chain bridge testing invitations through unofficial channels (such as private Discord channels or non-corporate domain emails), while the entire interview and communication process is extremely rudimentary, lacking proper corporate background checks.
  • 🚩 Requests to connect a personal primary wallet during security testing—rather than using an independent test wallet with project-provided test tokens—with testing tasks involving obviously unreasonable steps such as smart contract approvals for large asset amounts.
  • 🚩 The provided test link or frontend domain closely resembles a legitimate cross-chain bridge project, but close inspection of the browser address bar reveals spelling errors or the use of uncommon top-level domain suffixes designed to mislead job seekers.
  • 🚩 The authorization request text popped up by the wallet when signing transactions contains incomprehensible hexadecimal data, with a clear demand to transfer or approve token amounts far exceeding normal testing logic.
  • 🚩 The so-called security audit tasks lack any formal project background endorsement, and searching for the hiring company or project name yields no relevant records or financing history on mainstream crypto media or blockchain security leaderboards.

真实案例

  • In 2026, the North Korean hacker group Lazarus was accused of attacking AFX Bridge through fake job offers. Posing as recruiters, the attackers induced victim developers to perform purported security testing on the frontend and sign malicious cross-chain messages, ultimately stealing 24 million USD worth of USDC assets and shocking the entire crypto industry. (Source: [https://cn.cryptonomist.ch/2026/07/31/afx%E6%A1%A5%E6%94%BB%E5%87%BB%E8%BF%BD%E5%9B%9E%EF%BC%9A%E6%9C%9D%E9%B2%9C%E9%80%9A%E8%BF%87%E8%99%9A%E5%81%87%E5%B7%A5%E4%BD%9C%E9%82%80%E7%BA%A6%E7%9B%97%E5%8F%962400%E4%B8%87%E7%BE%8E%E5%85%83/](https://cn.cryptonomist.ch/2026/07/31/afx%E6%A1%A5%E6%94%BB%E5%87%BB%E8%BF%BD%E5%9B%9E%EF%BC%9A%E6%9C%9D%E9%B2%9C%E9%80%9A%E8%BF%87%E8%99%9A%E5%81%87%E5%B7%A5%E4%BD%9C%E9%82%80%E7%BA%A6%E7%9B%97%E5%8F%962400%E4%B8%87%E7%BE%8E%E5%85%83/))
  • A blockchain developer received a part-time job invitation for a high-paying cross-chain bridge security auditor on social media. After executing contract approvals on a testing frontend provided by the other party, approximately 800 million KRW worth of USDT in their hot wallet was instantly transferred. This case was later reported by media as the 800 million KRW USDT phishing case.
  • In another variant case involving zero-risk staking yield farming, victims were lured into transferring assets to a purported secure cross-chain staking protocol and signing unlimited approvals for security verification, ultimately resulting in over 3 million RMB in assets being drained, with official warning articles explicitly pointing out that wallet approvals became the key entry point.
  • In March 2026, the Gangbuk Police Station in Seoul, South Korea, in cooperation with Vietnamese police, cracked a major cyberphishing case. The criminal syndicate stole Tether from victims by building fake high-yield financial platforms and exploiting smart contract approval mechanisms, with involved amounts reaching up to 800 million KRW (approximately 4.3 million RMB). (Source: [https://developer.cloud.tencent.com/article/2634581](https://developer.cloud.tencent.com/article/2634581))
  • In July 2026, an attacker disguised as an OddiumLab recruiter induced an AFX developer to clone a code repository hiding malicious Git configurations, gradually compromising internal development systems and validator nodes, and ultimately forging cross-chain transactions on July 22 to steal approximately 24.15 million USD in USDC. Forensics attributed this to the North Korean-backed group UNC4899. (Source: [https://cn.cryptonomist.ch/2026/07/31/afx%E6%A1%A5%E6%94%BB%E5%87%BB%E8%BF%BD%E5%9B%9E%EF%BC%9A%E6%9C%9D%E9%B2%9C%E9%80%9A%E8%BF%87%E8%99%9A%E5%81%87%E5%B7%A5%E4%BD%9C%E9%82%80%E7%BA%A6%E7%9B%97%E5%8F%962400%E4%B8%87%E7%BE%8E%E5%85%83/](https://cn.cryptonomist.ch/2026/07/31/afx%E6%A1%A5%E6%94%BB%E5%87%BB%E8%BF%BD%E5%9B%9E%EF%BC%9A%E6%9C%9D%E9%B2%9C%E9%80%9A%E8%BF%87%E8%99%9A%E5%81%87%E5%B7%A5%E4%BD%9C%E9%82%80%E7%BA%A6%E7%9B%97%E5%8F%962400%E4%B8%87%E7%BE%8E%E5%85%83/))

Official Stance

  • Tencent Cloud Developer Community published Smart Contract Permission Hijacking Under High-Yield Bait: On-Chain Security Mechanism Reconstruction and Defense Strategies Based on the 800 Million KRW USDT Phishing Case, detailing the full-link mechanism of technical attacks inducing smart contract approvals through fake tests.
  • ChainUP published a warning article Zero-Risk Staking Yield Farming Scam Drains Over 3 Million RMB: Why Did Wallet Approvals Become the Key Entry Point?, clearly pointing out that authorization scams under the guise of security verification or high-yield staking are currently erupting on a large scale and causing massive losses.
  • CertiK, in its Verus incident analysis report, reconstructed the technical path of cross-chain authorization hijacking using on-chain data, warning the entire industry against such phishing-style asset theft disguised under security testing.

How to Protect Yourself

  • ✅ For any Web3 job offers or security audit tasks that require connecting wallets and interacting with contracts, always cross-verify the authenticity of the recruitment through official emails and channels like Telegram published on the project's official website.
  • ✅ When conducting so-called security testing, absolutely never use primary wallets containing personal real assets; instead, create brand new empty wallets or use official testnet isolated environment wallets for operation verification.
  • ✅ Before signing any transaction, carefully read the authorization details popped up by the wallet interface, or use plugins such as blind-signing interception tools to reject unlimited authorization requests with unknown hexadecimal data.
  • ✅ Regularly check historical wallet approval records using token approval tools on blockchain explorers like Etherscan, and promptly revoke unlimited authorization permissions granted to unknown or suspicious smart contracts.
  • ✅ Organizations must strengthen anti-social engineering training for employees and third-party auditors, strictly prohibiting the opening of cross-chain transfer test links from unknown sources outside internal networks or on unisolated devices.