Blockchain Transaction Simulation Phishing
Xiaocan Wang, Shixuan Guan, Tong Yang, Xiapu Luo, Yue Duan, Kai Li
cs.CR
Submitted: 2026-07-30
Comments: 15 pages, 7 figures
Code: https://github.com/blockchain-etl/ethereum-etl
Project page: https://ucsb-seclab.github.io/greed/examples/#1-reachibility-of-a-call-statement
License: http://creativecommons.org/licenses/by-nc-nd/4.0/
The gist: Cryptocurrency users have increasingly become targets of phishing and scam attacks.
Terminology
Abstract
Cryptocurrency users have increasingly become targets of phishing and scam attacks. To mitigate these threats, leading crypto wallets (e.g., MetaMask) have introduced transaction simulation, which previews a transaction's balance changes before on-chain execution. While effective against traditional fund-draining attacks, we show that this defense can itself be exploited by a new phishing technique, which we term transaction simulation phishing. This attack uses carefully crafted smart contracts whose execution depends on dynamic blockchain state, causing simulations to display benign or profitable outcomes while the actual on-chain execution redirects users' funds to attacker-controlled addresses. We present the first comprehensive study of transaction simulation phishing. We first develop a taxonomy of phishing contracts that can be utilized to facilitate this attack. Then, we propose SIMGUARD, a bytecode-level detection system that combines static and dynamic program analysis to identify phishing contracts. Applying SIMGUARD to Ethereum, Binance Smart Chain, Avalanche, and Polygon, we detect over 4,000 phishing contracts deployed between August 2024 and June 2025. Our analysis identifies more than 5,700 victims and approximately 3.48 million USD in losses, 91.5% of which occurred on Ethereum. Moreover, our clustering result reveals that the largest phishing contract cluster alone accounts for about 83% of the total losses. These results expose a critical weakness in current wallet defenses and highlight the urgent need for more robust transaction simulation mechanisms.
Sources
- Forsage: Anatomy of a Smart-Contract Pyramid Scheme
- Insecurity Through Obscurity: Veiled Vulnerabilities in Closed-Source Contracts
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs