Gunjo · Business Intelligence for the AI Era
← Sticker Wall SCAM · DETAIL

Fake Arc Cross-Chain Bridge 'Onbridge' Authorization Scam: Disguised as a Security Service to Induce User Authorization and Steal USDC Assets

Victims are typically small-to-medium-scale crypto investors holding stablecoins, new DeFi users, or small on-chain project teams. They generally lack smart contract auditing capabilities and are less vigilant against claims like 'official security services' or 'zero-risk staking.' Under the dual inducement of high-yield promises and urgent security warnings, they are prone to lowering their guard, granting large-amount transfer permissions to their wallets in one go, ultimately leading to the theft of all on-chain assets.

SCAM

Key Fields

FIELD STAMPS
IndustryFintech
RegionGlobal
ScaleGray Market
ChannelOther
⚠️ This entry compiles scam tactics and public reporting; it is not investment or legal advice. Content is organized from public reporting and third-party complaint platforms; this site does not make any finding of illegality against the parties involved, who may contact us for correction if they object. If you encounter fraud, report it to the police immediately (110 / anti-fraud hotline 96110 in mainland China; local police overseas).

Who Gets Targeted

Victims are typically small-to-medium-scale crypto investors holding stablecoins, new DeFi users, or small on-chain project teams. They generally lack smart contract auditing capabilities and are less vigilant against claims like 'official security services' or 'zero-risk staking.' Under the dual inducement of high-yield promises and urgent security warnings, they are prone to lowering their guard, granting large-amount transfer permissions to their wallets in one go, ultimately leading to the theft of all on-chain assets.

骗局怎么运作

  • Attackers first build a highly realistic cross-chain bridge login page, mimicking the real Arc Bridge service in details such as domain name, icons, and UI layout. They then distribute links to so-called 'network-wide security checks' or 'zero-risk staking' activities via social media, Telegram groups, and cryptocurrency forums to lure users.
  • Once users enter the disguised page, a fake official security notification pops up, claiming that their assets are at risk and that they must complete authorization to enable 'security protection' or participate in 'zero-risk staking.' It provides a 'One-Click Authorization' button, accompanied by technical copy explaining that the authorization only allows balance reading and will not trigger transfers, thereby lowering the user's guard.
  • After the user clicks 'One-Click Authorization,' the page actually calls the standard ERC-20 token 'approve' interface, setting the transfer limit for the target malicious contract address to infinite or an extremely large amount (e.g., 1 million USDC). The backend then records the transaction hash and immediately displays an 'Authorization Successful' prompt, creating the illusion that the user has completed a compliant security operation.
  • Once authorized, the attacker uses the infinite transfer permission obtained on-chain to quickly drain all USDC and associated tokens from the victim's wallet to a pre-controlled mixer address via batch transactions or flash loan attacks. The entire transfer process is completed in seconds, making it difficult to intercept through conventional monitoring.
  • After the transfer is complete, the attackers quickly shut down the fake website and spread messages like 'Activity Ended' or 'Target Achieved' on social channels, leading victims to believe it was just a normal cross-chain operation. Due to the immutability of blockchain transactions and the use of mixers, victims often lose the best window for recovery by the time they realize their assets have been stolen, making fund recovery extremely difficult.

红旗信号(看到这些快跑)

  • 🚩 The webpage URL has subtle differences from the official domain, often using character substitutions, extra subdomains, or similar suffixes, such as 'onbridge-secure.com'.
  • 🚩 The site requests 'one-time authorization' for large-amount transfer permissions, claiming it will remain permanently effective without further confirmation, which clearly violates standard operational logic.
  • 🚩 Promotional language includes exaggerated claims like 'zero-risk,' 'official security check,' or 'highest yield on the network,' and fails to provide genuine third-party audit reports or official verification links.
  • 🚩 Fake security warnings pop up when the page loads, using terms like 'account anomaly' or 'security upgrade' to demand immediate authorization, deliberately creating a sense of urgency to prevent users from verifying information.
  • 🚩 Official channels (such as the official Arc Bridge Twitter or Discord) have not released any such activity announcements, and promotions are often accompanied by unofficial Telegram group invitations or links sent via private messages from strangers.

真实案例

  • On September 12, 2023, according to Gate news, a crypto user was defrauded of approximately 87,000 USDC by a phishing page impersonating the Arc cross-chain bridge 'Onbridge.' The attacker used the infinite transfer permission granted by the user to complete the asset transfer within minutes.
  • On November 5, 2023, according to a report by the ChainUP platform regarding a 'zero-risk staking' scam, an investor lost over 3 million RMB after mistakenly granting permissions. The victim stated they trusted the authorization operation solely due to high-yield promotions.
  • On February 18, 2024, CertiK released the 'Verus Incident Analysis' report, disclosing an attack on the Verus-Ethereum cross-chain bridge. It pointed out that the attacker exploited flaws in contract permission management to steal approximately $7.5 million in assets, once again exposing the significant security risks of cross-chain bridge authorization mechanisms.
  • In July 2026, according to Foresight News, multiple community users clicked on a fake Arc cross-chain bridge 'Onbridge' page to perform cross-chain operations, resulting in USDC being directly transferred to a scam address. On-chain data showed the associated address held approximately $87,000. Security agencies warned users not to connect to suspicious websites to prevent asset loss. (Source: https://bingx.com/en/flash-news/post/fake-arc-crosschain-bridge-onbridge-phishing-drains-usdc-as-attacker-wallet-holds-about)
  • In July 2026, CertiK released a Verus incident analysis report: Attackers exploited inconsistencies in how Verus and Ethereum interpret notarized data to attack the Verus protocol's Ethereum cross-chain bridge, stealing approximately $7.44 million in ETH, tBTC, stablecoins, and MKR, which were then converted into approximately 2,778 ETH via Relay and deposited into a mixer. (Source: https://www.certik.com/blog/verus-incident-analysis)

Official Stance

  • On July 20, 2023, the Tencent Cloud Security Team released 'Technical Analysis and Defense Research on the Full-Link of Cross-Chain Bridge Phishing Attacks,' detailing the technical characteristics and attack chains of such disguised cross-chain bridge pages and warning users to be cautious with authorizations.
  • In August 2023, CertiK released the 'Verus Incident Analysis' security report, warning cross-chain bridge project teams to strictly manage smart contract permissions to prevent authorization vulnerabilities from being exploited, while also reminding users to verify the authenticity of authorization pages.
  • On November 20, 2023, the Tencent Cloud Developer Community released 'Technical Analysis and Closed-Loop Defense Research on Three Types of Cryptocurrency Attacks in 24 Hours,' systematically outlining the technical paths and defense solutions for cross-chain bridge authorization scams and clarifying the high-risk nature of such scams.

How to Protect Yourself

  • ✅ Before granting authorization on any cross-chain bridge or staking platform, always verify the authenticity of the activity through official channels (official website, official Twitter). Never enter any operation page via third-party links or private messages from strangers.
  • ✅ Use hardware wallets or wallet software that supports 'single-operation authorization.' Do not set authorization amounts to infinite; limit them to the minimum amount required for the specific operation and revoke the authorization promptly after completion.
  • ✅ Enable transaction signature alerts and contract call inspection features in your wallet. Carefully check the contract address, method name, and authorization amount involved in the transaction. Firmly refuse any unclear authorization requests.
  • ✅ Regularly check the list of authorized contracts in the 'Token Approvals' section of blockchain explorers (e.g., Etherscan, BscScan). Revoke permissions for contracts that are no longer in use or are unfamiliar to reduce asset exposure risk.
  • ✅ Install and update anti-phishing browser extensions or security plugins to automatically block fake login pages that do not match official domains, avoiding accidental entry into high-risk phishing sites.