Dissecting Payload-based Transaction Phishing on Ethereum

Zhuo Chen

Network and Distributed System Security (NDSS) Symposium 2025 · Day 3 · Phishing & Fraud 2 · Phishing & Fraud 2

Overview

In a revealing presentation at the NDSS Symposium, Zhuo Chen of Zhejiang University unveiled critical research dissecting payload-based transaction phishing on the Ethereum blockchain. This talk shines a spotlight on a sophisticated and increasingly prevalent attack vector that has contributed to over $3 billion in crypto losses in 2023 alone. Unlike simpler scams, payload-based phishing leverages the very architecture of Ethereum's transaction mechanism, exploiting a fundamental blind spot between user perception and the underlying smart contract interactions.

Watch on YouTube · Slides

Key moments

  1. 0:00 Introduction to payload-based transaction phishing
  2. 2:00 Demonstrating an NFT purchase phishing scam
  3. 3:00 Overview of research methodology and steps
  4. 4:28 Identifying two main payload phishing categories
  5. 8:05 Overview of the role-based detection system
  6. 9:05 Large-scale measurement findings: transactions and losses
  7. 10:00 Community contributions and practical impact

Dissecting Payload-based Transaction Phishing on Ethereum

Speakers: Zhuo Chen, PhD Candidate, Zhejiang University

Conference: NDSS Symposium

YouTube: https://www.youtube.com/watch?v=malawGL3g3I

Overview

In a revealing presentation at the NDSS Symposium, Zhuo Chen of Zhejiang University unveiled critical research dissecting payload-based transaction phishing on the Ethereum blockchain. This talk shines a spotlight on a sophisticated and increasingly prevalent attack vector that has contributed to over $3 billion in crypto losses in 2023 alone. Unlike simpler scams, payload-based phishing leverages the very architecture of Ethereum's transaction mechanism, exploiting a fundamental blind spot between user perception and the underlying smart contract interactions.

The core of the problem lies in the design of decentralized applications (dApps) and the Ethereum Virtual Machine (EVM) transaction flow. While users interact with a seemingly simple graphical interface, clicking "connect" and "sign" buttons, the actual power of a transaction resides in its payload – the encoded instructions dictating how smart contracts interact. Most users, lacking the technical expertise or tools, never inspect this crucial data, creating a dangerous vulnerability that attackers exploit to manipulate contract calls for illicit gain.

Chen's research provides the first systematic analysis of this complex threat. By categorizing the diverse tactics employed by attackers, designing a robust detection system, and performing a large-scale measurement across the Ethereum blockchain, the study offers invaluable insights for both developers and users. The findings underscore the urgent need for enhanced security measures, improved user education, and more transparent transaction signing processes to safeguard assets within the decentralized ecosystem.

Background

▶ Watch: Introduction to payload-based transaction phishing (0:00)

The Ethereum blockchain, like many other smart contract platforms, operates on a principle where user actions trigger smart contract executions. A typical transaction flow involves several steps: a user interacts with a dApp, signs a transaction, the Ethereum network receives the signed transaction, the EVM invokes relevant smart contracts based on the transaction payload, and finally, the blockchain state is updated. The critical vulnerability, as highlighted by Chen, resides in the third step: the payload determines the entire contract interaction, yet remains largely opaque to the average user.

From a user experience perspective, this process is deceptively simple. Users visit a dApp, click "connect" to link their wallet, and then click a button to "sign" a transaction. This streamlined user interface, while convenient, creates a "huge gap between the user and the contract." Attackers weaponize this gap, crafting malicious payloads that, when signed, execute unintended or harmful operations on behalf of the user. The research defines payload-based phishing as "transactions that manipulate smart contracts interactions through the execution of malicious payloads to deceive users."

Existing studies in web3 security have primarily focused on broader scam categories, such as phishing websites, token scams, or NFT frauds, often targeting the user's interaction with the dApp interface or social engineering. However, Chen's work identifies a crucial "critical blind spot" – the systematic analysis of how attackers directly manipulate the underlying transaction payload itself. This study sought to fill that gap by taking a rigorous, three-step approach: first, dissecting and categorizing the various types of payload-based phishing; second, designing a detection system based on these categories; and third, performing a large-scale measurement to quantify the prevalence and impact of these attacks.

To establish a ground truth dataset for their analysis, the researchers collected public reports from prominent security companies like PeckShield, SlowMist, and Scam Sniffer. After manual verification, they expanded this dataset by tracing historical Ethereum transactions associated with identified phishing activities. For comparison and to train their detection models, they also collected transactions from the top five decentralized exchanges (DEXs) and decentralized finance (DeFi) developers, classifying these as benign transactions. This comprehensive data collection, spanning from January 1st to July 30th, 2023, ultimately yielded 5,000 payload-based phishing transactions and over 13,000 benign transactions, forming the foundation for their systematic investigation.

Key Findings

▶ Watch: Overview of research methodology and steps (3:00)

The research identified two primary categories of payload-based transaction phishing, each presenting distinct threat models: abusing legitimate contracts and exploiting phishing contracts. These categories encompass a range of sophisticated techniques designed to trick users into signing transactions that result in asset loss.

Within the abusing legitimate contracts category, two significant subcategories were identified:

  1. Ice Fishing Scam: This sophisticated scam leverages the token approval mechanism inherent in ERC-20 tokens. Attackers trick users into signing transactions that grant malicious actors excessive approval over their tokens or allow them to set setApprovalForAll for NFTs, effectively giving the scammer permission to transfer funds or NFTs from the user's wallet. The attacker then uses the transferFrom function to drain the victim's assets. Chen further divided this into specific tricks such as "approval permits" and "set approval for all," highlighting the varied ways these approvals can be obtained.
  2. NFT Order Scam: As illustrated with a compelling example, this scam involves attackers analyzing legitimate NFT marketplace contracts to generate seemingly valid but malicious NFT purchase or sale orders. The user, believing they are interacting with a standard marketplace transaction, signs an order that includes hidden malicious parameters, such as a 100% fee directed back to the scammer's wallet, or other manipulative conditions. Subtypes include "bump transfer," "proxy upgrade," and "free by order," each exploiting specific functionalities of NFT marketplaces to transfer ownership without fair compensation to the victim.

The second primary category, exploiting phishing contracts, focuses on scenarios where attackers deploy their own malicious smart contracts to facilitate the scam:

  1. Address Poison Scam: This is an "interesting and well-known" type of scam where attackers monitor a user's legitimate transaction history. When a user initiates a transfer, the attacker quickly generates a "look-alike" address that closely resembles one of the user's recently interacted-with addresses (e.g., by sharing the same first and last few characters). The attacker then invokes their phishing contract to send a zero-value or dust-value transaction from this look-alike address to the victim. The user, upon reviewing their transaction history for a previous recipient, might inadvertently copy the attacker's look-alike address instead of the legitimate one for a future transfer, sending funds directly to the scammer. This can be further divided into "zero value transfer poison," "dust value transfer poison," and "fake token transfer poison." Etherscan has even begun flagging these abnormal zero-value transfers due to their association with this scam type.
  2. Payable Function Scam: In this scenario, scammers deploy phishing smart contracts with fake interfaces, often designed to mimic legitimate dApps offering airdrops or rewards. They then "airdrop rubbish tokens" to unsuspecting users. If a user, enticed by the fake airdrop or a promise of a reward, interacts with and invokes the malicious smart contract's payable function (e.g., claimAirdrop, claimReward, securityUpdate), they inadvertently trigger a malicious logic that drains their assets.

These categorizations provided crucial insights for the development of a robust detection system. The research identified four key perspectives through which phishing transactions differentiate themselves from benign ones: contract bytecode patterns, input data signatures, transaction-related addresses, and transaction history. These distinctions form the bedrock of an effective defense strategy against payload-based transaction phishing.

Technical Deep Dive

▶ Watch: Identifying two main payload phishing categories (4:28)

The technical sophistication of payload-based transaction phishing lies in its ability to manipulate the low-level execution environment of the EVM. At its core, every transaction on Ethereum contains an input field, which encodes the function call and its parameters for a target smart contract. This encoded data, the payload, is precisely what attackers craft maliciously.

Consider the NFT order scam as a prime example. Attackers don't necessarily create a fake website; instead, they analyze the legitimate smart contracts of established NFT marketplaces. They understand how these contracts handle buyOrder or sellOrder functions and their expected parameters. The scammer then generates a transaction payload that, when signed by the victim, appears to be a standard NFT purchase. However, embedded within the parameters might be a manipulated fee structure, such as a "100% fee" directed to an address controlled by the scammer, effectively ensuring the seller receives no ETH while losing their NFT. The speaker highlighted a "proxy upgrade" example within this category, suggesting that attackers might leverage upgradable contract patterns to introduce malicious logic or redirect funds.

For the Ice Fishing Scam, the technical vector is the ERC-20 approve() function or the ERC-721/ERC-1155 setApprovalForAll() function. When a user interacts with a legitimate dApp, they might be prompted to approve a certain amount of tokens for the dApp's smart contract to spend on their behalf. Attackers craft phishing dApps or social engineering tactics to trick users into signing approve() transactions with an unusually high amount (e.g., MAX_UINT256) or to an unauthorized address. Once approved, the attacker can then call transferFrom() on the token contract to move the approved tokens from the victim's wallet to their own, without requiring any further direct signature from the victim for each transfer. The "approval permits" and "set approval for all" tricks represent variations in how these permissions are initially obtained.

The Address Poison Scam preys on human error and the visual similarity of hexadecimal addresses. The technical mechanism involves the attacker sending a zero-value transfer or a dust-value transfer from a newly created address (the "look-alike" address) to the victim. This seemingly innocuous transaction serves to "poison" the victim's transaction history. When the victim later intends to send funds to a legitimate address they've used before, they might copy the look-alike address from their transaction history instead of the correct one. Etherscan's flagging of these zero-value transfers indicates the on-chain footprint these attacks leave.

Finally, the Payable Function Scam directly exploits the payable keyword in Solidity smart contracts. A payable function can receive Ether directly. Attackers deploy contracts with functions like claimAirdrop() or claimReward() that are marked payable. They then entice users to call these functions, often by airdropping "rubbish tokens" as bait. When a user calls the payable function, the malicious contract's logic is executed, which might include transferring the user's ETH or other tokens to the scammer's address, often under the guise of paying a gas fee or a "service charge."

Based on these technical distinctions, the researchers developed a "role-based detection system." While the detailed detection rules were not fully presented due to time constraints, the speaker indicated that the system leverages four key characteristics:

  1. Contract bytecode patterns: Analyzing the compiled code of smart contracts can reveal suspicious functionalities or known phishing contract structures.
  2. Input data signatures: The function selector (the first four bytes of the payload) and the structure of function arguments can indicate malicious intent, especially when compared against known legitimate contract ABIs.
  3. Transaction-related addresses: Examining the sender, receiver, and any intermediary contract addresses involved in a transaction can flag unusual or blacklisted entities.
  4. Transaction history: Analyzing patterns in a user's or an address's historical transactions can help identify anomalies, such as the sudden appearance of look-alike addresses or unusual approval patterns.

This detection system demonstrated high efficacy, achieving an accuracy of over 99% in their evaluation against both the ground truth dataset and a large-scale Ethereum dataset. Furthermore, its efficiency was impressive, consuming only 319 milliseconds per block on average, making it suitable for real-time monitoring.

Demo / Proof of Concept

▶ Watch: Large-scale measurement findings: transactions and losses (9:05)

While the talk did not feature a live demonstration or a dedicated proof-of-concept walkthrough of the detection system itself, the speaker effectively illustrated the core attack vectors and their mechanisms through detailed examples. These examples served as conceptual demonstrations of how payload-based phishing operates in practice.

One prominent example was the comparison between a legitimate NFT purchase order and a phishing NFT purchase order. The speaker showed how both interfaces might appear identical to the user, prompting them to "execute" what they believe is a standard transaction. However, the malicious version was revealed to contain different parameters, specifically a "100% fees" setting. This critical parameter, hidden within the transaction payload, ensured that while the seller lost their NFT, the funds were rerouted back to the scammer, resulting in no compensation for the victim. This vividly showcased how subtle manipulation of transaction parameters can lead to significant losses.

Another illustrative case was the "proxy upgrade" example within the NFT order scam category, hinting at how attackers might leverage complex contract architectures to introduce malicious logic. Similarly, the explanation of the "address poison scam" detailed how a "zero value transfer" from a "look-alike address" could trick users, with the speaker noting that Etherscan even flags such abnormal transfers, providing a real-world indicator of this attack in action. These concrete scenarios, drawn from actual observed attacks, served as powerful conceptual demonstrations of the technical exploits.

Defensive Implications

▶ Watch: Community contributions and practical impact (10:00)

The findings from Zhuo Chen's research carry significant implications for both individual users and the broader web3 security ecosystem. Addressing payload-based transaction phishing requires a multi-faceted approach, combining user education with technological advancements.

  1. Enhanced User Education and Awareness: The most critical defensive measure is to educate users about the dangers of blindly signing transactions. Users must be taught to inspect the transaction details presented by their wallets, going beyond the superficial dApp interface. While current wallets often display some transaction parameters, they rarely provide a clear, human-readable summary of the intent of complex smart contract interactions. Users should be wary of unusual approval requests, unexpected function calls, or transactions with excessively high values or fees.
  2. Improved Wallet Interfaces: Wallet providers have a crucial role to play in bridging the "gap between the user and the contract." Wallets should evolve to provide more transparent and understandable transaction previews. This could include:
  • Simulated transaction outcomes: Showing users what will actually happen if they sign a transaction (e.g., "You will send 1 NFT to X, and receive 0 ETH").
  • Highlighting suspicious parameters: Automatically flagging parameters like 100% fees, MAX_UINT256 approvals, or transfers to unknown addresses.
  • Human-readable contract interaction summaries: Translating complex function calls and encoded parameters into plain language, perhaps with warnings for known malicious patterns.
  • Address book functionality with warnings: Allowing users to label trusted addresses and warning them if they are interacting with a similar, but slightly different, address.
  1. Proactive Detection Systems: The research's role-based detection system, which boasts over 99% accuracy and minimal latency (319 milliseconds per block), offers a blueprint for security providers and blockchain infrastructure projects. Such systems, leveraging contract bytecode patterns, input data signatures, transaction-related addresses, and transaction history, can identify and flag malicious transactions in near real-time. This can enable on-chain alerts, as demonstrated by the researchers' contribution to the community.
  2. Collaboration with Security Researchers and Community Reporting: The success of the research in identifying and categorizing these attacks underscores the importance of ongoing collaboration between academia, security firms, and the wider web3 community. The reporting of 1,726 phishing addresses, accounting for 43% of all community reports, directly contributes to blacklisting efforts and protecting users.
  3. Smart Contract Auditing and Best Practices: While some attacks abuse legitimate contracts, developers of dApps and smart contracts should adhere to rigorous security auditing practices. Contracts should be designed with clear, auditable logic, and potentially incorporate circuit breakers or rate limits for critical functions to mitigate the impact of exploited approvals.
  4. Block Explorer Enhancements: Block explorers like Etherscan are already taking steps, such as flagging "abnormal zero-value transfers" associated with address poisoning. Continuing to enhance these platforms with more sophisticated phishing indicators can help users and investigators identify suspicious activity.

By implementing these defensive measures, the web3 community can collectively work towards building a safer and more resilient decentralized ecosystem, mitigating the significant financial losses currently inflicted by payload-based transaction phishing.

Key Takeaways

  • Significant Financial Impact: Payload-based transaction phishing is a highly sophisticated and costly threat, contributing to over $3 billion in crypto losses in 2023, with the research identifying $341 million lost across 130,000 transactions in their measurement period alone.
  • User Blind Spot as Core Vulnerability: The primary vulnerability exploited by attackers is the user's lack of visibility into and understanding of the transaction payload, which dictates smart contract interactions, creating a critical "gap between the user and the contract."
  • Two Main Phishing Categories: The research systematically categorizes payload-based phishing into two distinct types: abusing legitimate contracts (e.g., Ice Fishing Scams, NFT Order Scams) and exploiting phishing contracts (e.g., Address Poison Scams, Payable Function Scams).
  • Diverse Attack Techniques: Specific attack vectors include manipulating token approvals (approve, setApprovalForAll), crafting malicious NFT marketplace orders with hidden fees, "poisoning" transaction history with look-alike addresses, and luring users to interact with fake airdrop contracts.
  • Effective Detection is Possible: A role-based detection system, leveraging contract bytecode patterns, input data signatures, transaction-related addresses, and transaction history, achieved over 99% accuracy with high efficiency (319ms per block on average).
  • Community Contribution and Future Security: The research actively contributed to web3 security by reporting 1,726 phishing addresses (43% of community reports) and sending over 2,500 on-chain alerts to nearly 2,000 victims, highlighting the importance of collaborative defense and proactive threat intelligence.

About the Speaker(s)

Zhuo Chen is a PhD candidate at Zhejiang University, where he conducts research in the field of cybersecurity, particularly focusing on the intricacies of blockchain security. He is advised by Professor Yajin Zhou. His work, as demonstrated in this presentation, delves into the technical specifics of emerging threats within decentralized systems, aiming to dissect sophisticated attack vectors and contribute to building safer web3 environments.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Competent academic taxonomy of Ethereum transaction phishing with a functional detection system and real measurement numbers. The work is thorough and the dataset is credible, but the attack categories themselves aren't novel to anyone who's been tracking web3 security — ice fishing, address poisoning, and malicious approvals have been documented and exploited at scale for years. Solid NDSS paper; not a DEF CON headliner.

Heather Calloway (CISO) — WEAK

Technically rigorous academic work on a real and costly attack class, but it stops at research and never crosses into institutional accountability or operational decision-making. The $3 billion loss figure demands a governance conversation that never happens.

→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025

All talks from Network and Distributed System Security (NDSS) Symposium 2025