Cyber Attack on EigenLayer’s X Account Results in Huge Loss

posted  2 hr ago
The EigenLayer team, creators of the largest restaking protocol, has confirmed that their X account was compromised. Hackers began their activity on Friday, October 18, posting suspicious messages related to a fake airdrop.

A series of scam posts were aimed at promoting a phishing link disguised as an EIGEN token airdrop. Hackers lured social media users to visit a fake website impersonating the Eigen Foundation, encouraging them to link their crypto wallets to "receive" rewards.

Eigen Labs, the research branch of the Eigen ecosystem, was the first to confirm the hack of the company’s X account at around 11:00 UTC. In their post, they warned users to stay away from phishing links and to ensure they were visiting the correct domain for EigenLayer’s website.
Well-known blockchain sleuth ZachXBT also addressed the hack on EigenLayer’s X account. Around an hour after the scam activity started, he urged his TG followers to avoid interacting with any links shared by EigenLayer’s account.

Even though the posts from EigenLayer’s X account were deleted, the scammers managed to swindle their victims. According to data from the analytics platform Scam Sniffer, a blockchain user lost $800,000 by signing a phishing transaction.
The transaction verified the transfer of $800,000 to the scammers

The transaction verified the transfer of $800,000 to the scammers' account. Source: x.com

This attack follows a similar incident earlier in the month. On October 4, the EigenLayer team revealed they were investigating the theft of $5.7 million in EIGEN tokens, later admitting hackers were behind the breach.

EigenLayer Draws in Scammers

Scammers often go after the most buzzworthy projects. EigenLayer, for instance, was mentioned in a case tied to the crypto blogger Mister.Biznes.

In May 2024, Mister.Biznes sold his Telegram channel, which had more than 200,000 followers, to a buyer named André. André used the channel to promote a fraudulent EIGEN token, falsely claiming it was part of a private token sale.

Sidebar ad banner