OAK — OnChain Attack Knowledge

Worked example · 2024-20

Rocket Pool fake-staking-frontend phishing campaigns — Ethereum — 2024–2025

Loss
aggregate mid-six-figures to low-seven-figures USD across the Rocket Pool staking-interface phishing cohort. Individual victim losses range from low-four-figures (single 16-ETH minipool deposits routed to attacker-controlled addresses) to mid-six-figures (multiple minipool deposits or existing rETH position drains where the phishing interface additionally requested ERC-20 approve() for the user's rETH balance to an attacker-controlled spender). The aggregate extraction is a conservative reconstruction from on-chain deposit-to-attacker-address tracing, Rocket Pool community self-reporting, and domain-reputation-service records for Rocket Pool typosquat domains.
OAK Techniques observed
OAK-T3.005 (Fake-Validator Staking-Frontend Phishing — primary; the Rocket Pool staking interface is a staking-frontend phishing surface structurally identical to the Lido stETH and EigenLayer restaking-interface phishing campaigns that are the first and second T3.005 canonical examples). OAK-T4.002 (Spoofed Token Approval — co-occurring in campaigns where the fake staking interface requested an ERC-20 approve() for rETH or RPL to an attacker-controlled spender address, enabling a drain of the user's existing Rocket Pool positions beyond the new staking deposit). OAK-T4.008 (Fake-DEX Clone-Frontend Phishing — structurally adjacent; some campaigns combined staking-interface phishing with fake DEX interfaces that offered "better swap rates" for ETH-to-rETH conversions, directing the swap output to attacker-controlled addresses).
Attribution
pseudonymous Multiple phishing-campaign operators — pseudonymous at the domain-registration and wallet-address layer — ran parallel Rocket Pool staking-interface phishing operations. Domain-registration records used privacy-shielded WHOIS; campaign infrastructure showed patterns consistent with previously-documented liquid-staking phishing operations (shared hosting provider IP ranges, common TLS-certificate issuance patterns). The attribution confidence interval is moderate (pseudonymous campaign operators, domain-registration pattern matching) with no confirmed state-actor linkage.
Key teaching point
Rocket Pool's node-operator / minipool architecture creates a distinctive T3.005 sub-shape: the phishing interface targets the node-operator flow (16 ETH + 2.4 RPL deposit to create a minipool) in addition to the liquid-staker flow (rETH minting deposit). The node-operator phishing sub-shape is higher-value per victim (16 ETH minimum deposit vs. typically <1 ETH for rETH minting) because the minipool creation deposit is structurally larger than a liquid-staking deposit. The dual-flow architecture makes Rocket Pool's T3.005 surface wider than the single-flow staking protocols (Lido), creating two distinct victim cohorts with different deposit-value distributions.

Summary

Rocket Pool is a decentralised Ethereum liquid-staking protocol with a distinctive dual-flow architecture: users can either (a) deposit ETH to mint rETH (liquid-staking token — the "liquid staker" flow, analogous to Lido stETH), or (b) deposit 16 ETH + a minimum of 2.4 ETH-worth of RPL (Rocket Pool's governance token) to create a minipool and become a node operator (the "node operator" flow, which earns additional RPL rewards and commission on the staked ETH). Both flows require users to interact with the Rocket Pool staking interface, connect their wallets, and execute deposit transactions to the Rocket Pool smart contracts.

During 2024–2025, phishing operators deployed typosquat domains impersonating Rocket Pool's staking interface: rocket-pool.org, rocketpool-stake.com, rpl-staking.net, rocketpool-minipool.com. The fake frontends mirrored the legitimate Rocket Pool staking interface, displaying competitive APR projections and the node-operator commission rate. The campaigns targeted both the liquid-staker and node-operator flows, but the node-operator phishing sub-shape — where the attacker's fake interface prompted the user to deposit 16 ETH + 2.4 RPL-equivalent to "create a minipool" — was particularly high-value per victim because the minipool creation deposit is structurally larger (16 ETH minimum) than a typical liquid-staking deposit.

The phishing extraction worked through the same structural primitive as Lido stETH and EigenLayer campaigns: the fake interface routed the deposit transaction to an attacker-controlled address rather than to Rocket Pool's canonical staking contract. The user received no rETH and no minipool NFT (the receipt token for Rocket Pool node operators) — the deposit was an outright transfer to the attacker.

Some campaigns combined the staking-interface phishing with a secondary drain: after the user deposited ETH for a minipool, the fake interface requested an ERC-20 approve() for the user's existing RPL or rETH balance to an attacker-controlled spender, draining the user's existing Rocket Pool positions. The secondary drain could extract the user's full Rocket Pool balance — including rETH accumulated from prior liquid-staking deposits and RPL staked in existing minipools — beyond the new minipool deposit.

The search-engine-advertisement vector was active: users searching for "Rocket Pool node operator," "create Rocket Pool minipool," or "Rocket Pool stake ETH" encountered sponsored results leading to typosquat domains. The Rocket Pool community maintained informal domain allowlists in their Discord and Reddit channels, and the Rocket Pool team published canonical interface URLs in their documentation, but the domain-reputation infrastructure lagged behind the campaign deployment cadence.

The cohort generalises the T3.005 surface from single-flow liquid-staking protocols (Lido, Marinade) to a dual-flow protocol (Rocket Pool), demonstrating that the phishing surface width expands with the number of distinct staking flows the protocol offers — each flow is an independent T3.005 surface that the attacker can target with a flow-specific fake interface.

Timeline (UTC)

When Event OAK ref
2024-Q1 to 2024-Q2 Rocket Pool minipool creation activity increases as ETH staking yields attract node operators; typosquat domains (rocket-pool.org, rocketpool-stake.com) begin appearing (standing T3.005 surface; Rocket Pool's dual-flow architecture creates two victim cohorts)
2024-Q3 to 2024-Q4 First major wave: node-operator-targeted campaigns (rocketpool-minipool.com, rpl-staking.net) serve cloned Rocket Pool interface; deposit routed to attacker-controlled address; minipool creation deposit (16 ETH minimum) yields higher per-victim extraction T3.005 (node-operator-flow phishing sub-shape)
2024-Q4 to 2025-Q1 Campaigns expand to liquid-staker flow (rETH minting) and add secondary-approval drain for existing rETH/RPL balances; typosquat domains include rpl-minipool-staking.com, rocketpool-eth.com T3.005 + T4.002 (secondary-approval drain)
2025-Q1 to 2025-Q2 Search-engine advertisement campaigns for "Rocket Pool stake ETH" and "Rocket Pool node operator" keywords; sponsored results lead to typosquat domains T3.005 (search-engine-advertisement interception)
2025-Q2 onward Rocket Pool community domain allowlists updated; Google Safe Browsing flags and PhishTank entries reduce campaign effectiveness; residual campaigns continue at lower volume (defender response; ongoing low-level surface)
Continuing Rocket Pool's dual-flow architecture (liquid staker + node operator) means two distinct T3.005 surfaces exist per user; the node-operator flow's higher deposit minimum (16 ETH) makes it a structurally higher-value phishing target T3.005 (ongoing surface; dual-flow architecture)

Realised extraction

Aggregate mid-six-figures to low-seven-figures USD across the cohort. Per-victim extraction is bifurcated: liquid-staker-flow victims typically lost smaller amounts (mid-four-figures for rETH minting deposits of a few ETH), while node-operator-flow victims lost larger amounts (low-to-mid-five-figures for 16 ETH minipool deposits, or higher if the secondary-approval drain captured the user's existing rETH and RPL balances). The node-operator sub-shape's structurally higher deposit minimum (16 ETH) makes it the load-bearing extraction driver for the cohort's aggregate loss figure. Recovery has not been publicly confirmed.

Public references

  • Rocket Pool official documentation — canonical interface URLs, staking contract addresses, and minipool creation flow
  • Rocket Pool community channels (Discord, Reddit r/rocketpool) — informal domain allowlists and phishing-warning threads (2024–2025)
  • Google Safe Browsing and PhishTank domain-reputation records for Rocket Pool typosquat domains
  • Cross-reference: T3.005 at techniques/T3.005-fake-validator-staking-frontend-phishing.md
  • Cross-reference: examples/2022-2023-lido-steth-staking-phishing-cohort.md — Lido stETH staking-interface phishing campaigns (2022–2023)
  • Cross-reference: examples/2024-2025-eigenlayer-airdrop-staking-frontend-phishing-cohort.md — EigenLayer restaking-frontend phishing cohort (2024–2025)
  • [rocketpoolphishing2022] — Rocket Pool fake-staking-portal incidents (2022–2023); community reports and domain-reputation service records

Techniques demonstrated (3)