Wallet-drainer disguised as WalletConnect steals $70K+, hits an Ethereum core dev
Ethereum core developer · Sep 1, 2024 · Trading agent
What happened
A wallet-draining tool disguised as the WalletConnect Protocol stole over $70,000 worth of digital assets from investors, including an Ethereum core developer. The incident highlighted how cheap AI-assisted social engineering lowers the cost of credential theft against crypto users.
Causal vector
Malicious browser extension masquerading as a legitimate wallet protocol
Source
Reported by Cointelegraph. Verified against the primary report.
A transfer to any address not on a pre-approved allowlist returns BLOCKED. The firewall doesn't care how convincing the social engineering was; it only honors the policy.
The six rule types that contain this class of failure
Per-transaction cap
Any single spend above your ceiling is BLOCKED before it moves.
Daily total
Cumulative spend across all agent calls, bounded per day.
Velocity limit
Stops runaway retry loops — the #1 cause of overnight losses.
Merchant allowlist
Only approved destinations can ever receive funds.
Category rules
Flag high-risk classes (crypto, infra, refunds) for review.
Approval threshold
Above a value, the action waits for a human.
Related incidents
Step Finance treasury drained in $27–40M exploit
Step Finance · Jan 31, 2026
TRM Labs: $2.87 billion stolen across ~150 crypto hacks in 2025
TRM Labs · Jan 1, 2026
Don't be the next entry
Every incident in this database is the result of trusting a prompt, a provider cap, or a human review cycle. sipi.bot replaces all three with one deterministic call. 27 documented failures, one control.