Fake Cross-Chain Bridge Phishing Scam Targets Crypto Users
A new phishing campaign is targeting users of cross-chain bridges, according to recent warnings circulating within crypto communities. Scammers have set up counterfeit web pages mimicking the interface of the Arc cross-chain bridge, specifically using the name 'onbridge' to appear legitimate.
How the Attack Works
Users who land on these deceptive sites are prompted to initiate a cross-chain transaction as they normally would. However, instead of facilitating a genuine bridge transfer, the interaction authorizes the direct transfer of the user's USDC stablecoins to an address controlled by the attacker.
On-chain data reveals the scale of the theft. The primary address linked to this phishing operation currently holds approximately $87,000, indicating that multiple victims have already been affected.
Protecting Yourself from Similar Threats
These scams exploit the trust users place in familiar DeFi interfaces. Fraudsters often use sophisticated copies of real websites, deceptive domain names, or promoted links in social channels to lure victims.
- Verify URL Sources: Always access services through links published on a project's official channels. Never click on unsolicited links.
- Double-Check Addresses: Before signing any transaction, use a block explorer to verify the recipient address is correct.
- Review Transaction Details: Modern wallets show transaction previews. Scrutinize the recipient address in this preview, not just the website's interface.
- Follow Official Channels: Stay updated by following a project's official social media accounts for any security announcements.
Cross-chain bridges are critical infrastructure and a prime target for malicious actors. While they offer convenience, users must incorporate security checks as a non-negotiable part of their workflow. If you suspect unauthorized activity, revoke any suspicious approvals immediately and report the incident to relevant security teams.