Worked example · 2024-20
EigenLayer restaking-frontend phishing cohort — Ethereum — 2024–2025
Summary
EigenLayer launched on Ethereum mainnet in 2024-06 with a points program — a pre-token incentive mechanism where users accumulated "restaking points" based on the amount and duration of ETH or liquid-staking-token (LST) deposits into EigenLayer's restaking contracts. The points program created a large, incentivised cohort of users searching for "EigenLayer restake," "restake ETH," "EigenLayer points," and related terms — users who needed to connect their wallets, approve token spends, and execute deposit transactions to EigenLayer's smart contracts.
Phishing operators recognised that the EigenLayer restaking flow was structurally identical to the Lido stETH staking flow (the first T3.005 canonical example): the user connects a wallet to a web interface, approves a deposit transaction to a contract address displayed as the staking/restaking contract, and expects to receive a receipt position (stETH for Lido, a restaking position tracked by EigenLayer's off-chain points system for EigenLayer). The user's mental model is "I am depositing assets to earn yield/points"; the attacker's extraction mechanism is "the deposit-destination address is my wallet, not the protocol's canonical restaking contract."
The EigenLayer restaking flow added a secondary extraction surface that Lido staking did not: liquid-restaking-token (LRT) protocols. After EigenLayer's launch, LRT protocols — Renzo, Ether.fi, Puffer, Kelp DAO — built on top of EigenLayer, issuing their own receipt tokens (ezETH, eETH, pufETH, rsETH) to users who deposited through the LRT protocol's interface. Phishing campaigns targeted LRT-protocol interfaces as well as EigenLayer-native interfaces, exploiting users who searched for "restake ETH Renzo" or "Ether.fi restaking." Each LRT protocol's interface was an independent T3.005 surface, multiplying the phishing attack surface across the restaking ecosystem.
The search-engine-advertisement vector was particularly effective during the EigenLayer points window (2024-06 to 2024-12): users searching for "EigenLayer restake" or "restake ETH" encountered sponsored results leading to typosquat domains (eigenlayer-restake.com, eigenlayer-points.com, eigenlayer-staking.org, restake-eigen.fi) that served cloned EigenLayer restaking interfaces. The fake frontend displayed a competitive restaking yield projection and routed the deposit to an attacker-controlled address. As with the Lido campaigns, the user received no receipt token or points credit, but this was only detectable after the transaction confirmed.
The phishing wave expanded in 2025 to target Symbiotic and Karak — two EigenLayer competitors that launched with their own restaking interfaces and incentive programs. The expansion demonstrated that T3.005 generalises across staking/restaking protocols: the structural primitive (fake interface, deposit-to-attacker routing, post-confirmation detection) is protocol-agnostic, and the phishing operator's marginal cost to create a new fake frontend targeting a new protocol is low.
Timeline (UTC)
| When | Event | OAK ref |
|---|---|---|
| 2024-06 | EigenLayer mainnet launch with points program; restaking TVL surges as users rush to accumulate points | (standing T3.005 surface; restaking creates staking-interface phishing surface) |
| 2024-07 to 2024-09 | First wave: typosquat domains (eigenlayer-restake.com, eigenlayer-points.com, eigenlayer-staking.org) appear; Google Ads campaigns for "EigenLayer restake" keywords | T3.005 (restaking-interface phishing) |
| 2024-10 to 2024-12 | Second wave: campaigns expand to LRT protocols (Renzo, Ether.fi, Puffer, Kelp DAO); domains include renzo-restake.com, etherfi-staking.com; some campaigns add LST approval requests for secondary drain | T3.005 + T4.002 |
| 2025-Q1 to 2025-Q2 | Campaigns expand to Symbiotic and Karak restaking interfaces as those protocols launch with their own incentive programs | T3.005 (protocol-agnostic generalisation) |
| 2025-Q2 onward | Community domain-allowlists (EigenLayer Discord, LRT protocol Discords), Google Safe Browsing flags, and wallet-side domain-verification warnings reduce campaign effectiveness; residual campaigns continue at lower volume | (defender response; ongoing low-level surface) |
Realised extraction
Aggregate mid-seven-figures USD across the cohort. Individual victim losses range from mid-four-figures (small restaking deposits of a few ETH-equivalent) to mid-six-figures (larger LST/LRT position drains where the phishing interface additionally requested an approval for the user's existing staking tokens). The extraction pattern is distributed — many small-to-medium deposits to many attacker-controlled addresses — and victim self-reporting is incomplete. The aggregate figure is a conservative reconstruction from on-chain deposit-to-attacker-address tracing, victim self-reporting in EigenLayer community channels, and domain-reputation-service records for EigenLayer and LRT-protocol typosquat domains. The wide victim-loss range reflects the bifurcation between pure-deposit campaigns (loss bounded by the deposit amount) and deposit-plus-approval campaigns (loss bounded by the user's full LST/LRT balance).
Public references
- EigenLayer official documentation and canonical interface URL guidance (2024-2025)
- Renzo, Ether.fi, Puffer, Kelp DAO canonical interface URLs and security advisories
- Symbiotic and Karak protocol documentation and security advisories (2025)
- Google Safe Browsing and PhishTank domain-reputation records for EigenLayer and LRT typosquat domains
- Community tracking: EigenLayer Discord domain-allowlist threads (2024-2025); LRT protocol Discord/Telegram phishing-warning threads
- C2 infrastructure fingerprinting reports — DPRK-linked phishing-infrastructure overlap analysis (industry reports, 2024-2025)
[eigenlayerphishing2024]— EigenLayer restaking-interface phishing campaigns (2024-2025). Industry reports and community documentation.[symbioticphishing2025]— Symbiotic restaking-interface phishing campaigns (2025). Community documentation.