TY - GEN
T1 - No Wallet for Old Tricks
T2 - 19th European Workshop on Systems Security, EuroSec 2026
AU - Muzammil, Muhammad
AU - Shah, Harsh
AU - Nikiforakis, Nick
N1 - Publisher Copyright: © 2026 Copyright held by the owner/author(s)
PY - 2026/4/26
Y1 - 2026/4/26
N2 - Cryptocurrency users routinely fall victim to social engineering attacks. Attackers trick victims into mistakenly authorizing transactions that transfer funds to attacker-controlled wallets rather than the intended recipient. Existing protections against these attacks largely rely on public blocklists, which attackers can easily evade. Official reports and recent measurement studies indicate that such attacks have led to billions of dollars in financial losses that are irreversible due to the immutable nature of blockchain transactions. In this work, we introduce the idea that cryptocurrency wallets can incorporate an additional context-aware, client-side layer of defense. Using this layer, wallets can better protect users from social engineering attacks by tailoring their defense to user’s specific cryptocurrency activity, instead of exclusively relying on global blocklists. To demonstrate this approach, we design and implement detection mechanisms targeting three prevalent attack vectors in the most widely used Ethereum wallet, MetaMask. We show that these mechanisms can be integrated without substantial engineering complexity and incur negligible runtime overhead. We hope that our work encourages wallet providers to consider incorporating them into their existing security workflows.
AB - Cryptocurrency users routinely fall victim to social engineering attacks. Attackers trick victims into mistakenly authorizing transactions that transfer funds to attacker-controlled wallets rather than the intended recipient. Existing protections against these attacks largely rely on public blocklists, which attackers can easily evade. Official reports and recent measurement studies indicate that such attacks have led to billions of dollars in financial losses that are irreversible due to the immutable nature of blockchain transactions. In this work, we introduce the idea that cryptocurrency wallets can incorporate an additional context-aware, client-side layer of defense. Using this layer, wallets can better protect users from social engineering attacks by tailoring their defense to user’s specific cryptocurrency activity, instead of exclusively relying on global blocklists. To demonstrate this approach, we design and implement detection mechanisms targeting three prevalent attack vectors in the most widely used Ethereum wallet, MetaMask. We show that these mechanisms can be integrated without substantial engineering complexity and incur negligible runtime overhead. We hope that our work encourages wallet providers to consider incorporating them into their existing security workflows.
KW - Address Poisoning
KW - Dropcatching
KW - Ethereum
KW - Typosquatting
UR - https://www.scopus.com/pages/publications/105039315712
U2 - 10.1145/3803525.3804977
DO - 10.1145/3803525.3804977
M3 - Conference contribution
T3 - EuroSec 2026 - Proceedings of the 19th European Workshop on Systems Security, Part of EuroSys 2026
SP - 1
EP - 9
BT - EuroSec 2026 - Proceedings of the 19th European Workshop on Systems Security, Part of EuroSys 2026
PB - Association for Computing Machinery, Inc
Y2 - 27 April 2026 through 30 April 2026
ER -