Ice Phishing Scams: What Are They and How Can Web3 Users Stay Clear of These Cyber Attacks

In its latest advisory report to the global Web3 sector, cyber research firm CertiK has sounded an alert against the rising cases of ice phishing scams.

Advertisement
Written by Radhika Parashar, Edited by Siddharth Suvarna | Updated: 21 December 2022 14:06 IST
Highlights
  • Crypto community is under constant threat from scammers
  • Ice phishing scams trick users into signing-off their funds to be used
  • Traditional phishing scammers try and steal private keys to drain account

Microsoft first highlighted the rise in ice-phishing scams in February this year

Photo Credit: Pexels/ Tima Miroshnichenko

The boom in the global fintech industry, has ushered in an era of scammers, armed with high-end tech tools to dupe you out of your hard-earned money. One such advanced scamming technique, especially targeted at the crypto community, is called ‘ice phishing'. In its latest advisory report to the global Web3 sector, cyber research firm CertiK has sounded an alert against the rising cases of ice phishing scams while also outlining preventative measures to keep finances safeguarded.

Ice phishing scams are cyber-attacks that manoeuvre Web3 users into manually signing and approving permissions that allow notorious actors to spend their tokens.

These permissions usually have to be signed on decentralised finance (DeFi) protocols, that could easily be mock-ups.

Advertisement

“The hacker just needs to make a user believe that the malicious address that they are granting approval to is legitimate. Once a user has approved permissions for the scammer to spend tokens, then the assets are at risk of being drained,” CertiK wrote in its report.

Once the scammers get this permission, they can transfer the funds from the victim's accounts into any other wallet address.

Advertisement

This is not quite the case in traditional phishing scams, where hackers manage to steal private keys or passwords by luring in unsuspecting people into clicking on malicious links or having them visit infected fake websites.

As a security-focussed suggestion, CertiK has asked Web3 investors to steer clear against granting permissions to unknown addresses, especially while browsing blockchain explorer sites like Etherscan.

Advertisement

People have been advised to look up for suspicious addresses asking for random permissions on blockchain explorer sites.

The concept of ice phishing was first highlighted by Microsoft in a blog post published in February this year.

“Web3 is the decentralised world that is built on top of cryptographic security that lays the foundation of the blockchain. Now, imagine if an attacker can – single-handedly – grab a big chunk [of market funds] and do so with almost complete anonymity. This changes the dynamics of the game,” the software giant had said at the time.

Advertisement

Earlier last week, 14 NFTs of the expensive and famous Bored Apes Yacht Club (BAYC) collection, were stolen in an ice-phishing attack. The scam unfolded after an investor was duped into signing a transaction request, that looked like a contract to feature these NFTs in a film. Once the scammer bagged the permission, the NFTs were purchased by the actor for a next-to-nothing amount, Cointelegraph had revealed in a report.

“Many ice phishing scams can be found on social media such as Twitter, where fake profiles are disguising themselves as legitimate projects and promoting fake airdrops as an example. The easiest way to prevent yourself from becoming a victim of ice phishing is by going to trusted sites such as Coinmarketcap.com, coingecko.com, and certik.com to verify official sites,” the CertiK report noted.


Is the Realme Pad X the budget ‘iPad' you're looking for? We discuss this on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts. 
Affiliate links may be automatically generated - see our ethics statement for details.
 

Catch the latest from the Consumer Electronics Show on Gadgets 360, at our CES 2026 hub.

Advertisement

Related Stories

Popular Mobile Brands
  1. Here's When the Motorola Signature Will Launch in India
  2. iQOO Z11 Turbo With 200-Megapixel Camera Arrives in China at This Price
  3. Realme P4 Power 5G Will be Launched in India Soon: See Expected Specs
  4. Amazon Sale: Best Deals on Galaxy S25 Ultra and More Samsung Phones
  5. Oppo A6c Launched With 6,500mAh Battery, Snapdragon 685 SoC
  6. YouTube Now Lets Parents Put a Time Limit on Kids' YouTube Shorts Scrolling
  7. Amazon Great Republic Day Sale 2026: Best Deals on iQOO, Vivo Phones
  8. Android 17 May Redesign Notifications, Quick Settings With Split Layout
  1. Civilization VII Coming to iPhone, iPad as Part of Apple Arcade in February
  2. OpenAI’s Hardware Pivot: Rejecting Apple to Focus on Jony Ive-Designed AI Wearables
  3. iQOO Z11 Turbo Launched With 7,600mAh Battery, 200-Megapixel Camera: Price, Specifications
  4. Google Photos App Could Soon Bring New Battery Saving Feature, Suggests APK Teardown
  5. OpenAI Takes on Google Translate With Its New AI-Powered Translation Feature
  6. Nothing Confirms Bengaluru as Location for India’s First Flagship Store; Set to be Second in the World
  7. Resident Evil Village, Like a Dragon: Infinite Wealth and More Join PS Plus Game Catalogue in January
  8. Lava Blaze Duo 3 Confirmed to Launch in India Soon; Key Specifications Revealed via Amazon Listing
  9. Lumio Vision 7, Vision 9 Smart TVs Go on Sale on Flipkart With Republic Day Offers
  10. God of War TV Series OTT Release: Know When, Where to Watch the Live Adaptation of Kratos' Adventures
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.