Home/ Incident database/walletconnect-drainer-2024-09
Financial loss Credential compromise verified

Wallet-drainer disguised as WalletConnect steals $70K+, hits an Ethereum core dev

Ethereum core developer · Sep 1, 2024 · Trading agent

What happened

A wallet-draining tool disguised as the WalletConnect Protocol stole over $70,000 worth of digital assets from investors, including an Ethereum core developer. The incident highlighted how cheap AI-assisted social engineering lowers the cost of credential theft against crypto users.

$70K
Loss / impact
Sep 1
2024
Credential
Failure mode
Trading
Agent type

Causal vector

Malicious browser extension masquerading as a legitimate wallet protocol

Source

Reported by Cointelegraph. Verified against the primary report.

Read the original report ↗

How a spend firewall would have helped

A transfer to any address not on a pre-approved allowlist returns BLOCKED. The firewall doesn't care how convincing the social engineering was; it only honors the policy.

The six rule types that contain this class of failure

Per-transaction cap

Any single spend above your ceiling is BLOCKED before it moves.

Daily total

Cumulative spend across all agent calls, bounded per day.

Velocity limit

Stops runaway retry loops — the #1 cause of overnight losses.

Merchant allowlist

Only approved destinations can ever receive funds.

Category rules

Flag high-risk classes (crypto, infra, refunds) for review.

Approval threshold

Above a value, the action waits for a human.

Related incidents

Don't be the next entry

Every incident in this database is the result of trusting a prompt, a provider cap, or a human review cycle. sipi.bot replaces all three with one deterministic call. 27 documented failures, one control.