Phantom Chat Feature Linked to $264K Address Poisoning Scam, Security Experts Warn

4 hour ago 7 sources negative

Key takeaways:

  • Phantom's security incident may temporarily deter adoption despite its UX innovation, highlighting the Web3 security trade-off.
  • The $264k loss underscores immediate need for wallets to implement pre-transaction address validation features industry-wide.
  • Investors should monitor SOL's price reaction as Phantom's issues could negatively impact sentiment toward the broader Solana ecosystem.

Phantom Wallet has launched "Phantom Chat," an integrated messaging feature designed to transform the wallet into a comprehensive Web3 engagement platform. The feature allows users to communicate, share wallet addresses, and discuss transactions directly within the wallet interface, aiming to streamline coordination for DeFi, NFT trading, and on-chain interactions. Phantom emphasizes the feature is encrypted and requires user opt-in, with messaging kept separate from transaction authorization.

However, the launch has been marred by a significant security incident. Blockchain investigator ZachXBT revealed that an investor lost approximately $264,000 worth of Wrapped Bitcoin (wBTC) in a phishing attack enabled through Phantom Chat. The scam utilized address poisoning, where attackers send small transactions to a victim's wallet, hoping the victim will later copy the attacker's address from their transaction history when making a legitimate payment.

ZachXBT criticized Phantom's user interface, calling the messenger a "new method for people to get drained" and urging the wallet to filter out spam transactions to prevent such scams. Another user, Kill4h, reported losing $237 in two separate address poisoning attacks via the feature.

The incident has sparked broader calls for enhanced wallet security. Binance co-founder Changpeng Zhao previously advocated for wallets to automatically check if a receiving address is a known "poison address" and block the transaction, as well as filter out displaying low-value spam transactions. Security firms like Hacken and Cyvers emphasize the need for pre-transaction risk checks, address similarity detection, and clear warnings.

This event highlights the critical challenge for Web3 developers: balancing innovative product features that enhance user experience with rigorous security standards. As wallets evolve into multi-functional financial applications, their expanded capabilities must be accompanied by robust safeguards to maintain user trust in an ecosystem where phishing and social engineering remain prevalent threats.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.